Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: ruff: * python3-ruff-0.15.11-1.hum1 (noarch) * ruff-0.15.11-1.hum1 (aarch64, x86_64) * ruff-0.15.11-1.hum1.src (src)
AI Analysis
Technical Summary
This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including python3-ruff-0.15.11-1.hum1 and ruff-0.15.11-1.hum1 packages. Among the addressed vulnerabilities is CVE-2026-44029, a directory traversal flaw in Nix's 'nix-prefetch-url --unpack' and 'nix store prefetch-file --unpack' commands, allowing arbitrary file writes. This vulnerability is classified under CWE-36 (Absolute Path Traversal) and can lead to unauthorized code execution, file modification, and denial of service by overwriting critical files. The advisory references multiple CVEs (CVE-2026-41238, CVE-2026-41239, CVE-2026-44028, CVE-2026-44029, CVE-2026-47423) and highlights the high severity of these issues. Red Hat provides updated RPM packages to mitigate these vulnerabilities but does not explicitly list patch availability in the advisory content. The vendor advisory is the authoritative source for remediation.
Potential Impact
The vulnerabilities allow an attacker with local access to perform absolute path traversal during archive unpacking, enabling arbitrary file writes. This can compromise system integrity by overwriting or creating critical files such as programs or libraries, potentially leading to unauthorized code execution or bypass of security mechanisms. Confidentiality may also be impacted if sensitive files are read or overwritten. Additionally, availability can be affected if critical files are corrupted or deleted, potentially causing denial of service. The advisory rates these vulnerabilities as high severity due to their potential to impact integrity and availability significantly.
Mitigation Recommendations
Red Hat has released updated RPM packages (python3-ruff-0.15.11-1.hum1 and ruff-0.15.11-1.hum1) for Red Hat Hardened Images to address these vulnerabilities. Users should apply these updates as soon as possible by following the instructions at https://images.redhat.com/. No additional mitigations or workarounds are specified in the advisory. Patch status is confirmed by the vendor advisory indicating updated packages are available.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: ruff: * python3-ruff-0.15.11-1.hum1 (noarch) * ruff-0.15.11-1.hum1 (aarch64, x86_64) * ruff-0.15.11-1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including python3-ruff-0.15.11-1.hum1 and ruff-0.15.11-1.hum1 packages. Among the addressed vulnerabilities is CVE-2026-44029, a directory traversal flaw in Nix's 'nix-prefetch-url --unpack' and 'nix store prefetch-file --unpack' commands, allowing arbitrary file writes. This vulnerability is classified under CWE-36 (Absolute Path Traversal) and can lead to unauthorized code execution, file modification, and denial of service by overwriting critical files. The advisory references multiple CVEs (CVE-2026-41238, CVE-2026-41239, CVE-2026-44028, CVE-2026-44029, CVE-2026-47423) and highlights the high severity of these issues. Red Hat provides updated RPM packages to mitigate these vulnerabilities but does not explicitly list patch availability in the advisory content. The vendor advisory is the authoritative source for remediation.
Potential Impact
The vulnerabilities allow an attacker with local access to perform absolute path traversal during archive unpacking, enabling arbitrary file writes. This can compromise system integrity by overwriting or creating critical files such as programs or libraries, potentially leading to unauthorized code execution or bypass of security mechanisms. Confidentiality may also be impacted if sensitive files are read or overwritten. Additionally, availability can be affected if critical files are corrupted or deleted, potentially causing denial of service. The advisory rates these vulnerabilities as high severity due to their potential to impact integrity and availability significantly.
Mitigation Recommendations
Red Hat has released updated RPM packages (python3-ruff-0.15.11-1.hum1 and ruff-0.15.11-1.hum1) for Red Hat Hardened Images to address these vulnerabilities. Users should apply these updates as soon as possible by following the instructions at https://images.redhat.com/. No additional mitigations or workarounds are specified in the advisory. Patch status is confirmed by the vendor advisory indicating updated packages are available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:10999
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-41239","CVE-2026-44028","CVE-2026-44029"]
- State
- PUBLISHED
Threat ID: 6a54ae1068715ace438f8d1e
Added to database: 07/13/2026, 09:21:20 UTC
Last enriched: 08/16/2026, 17:53:42 UTC
Last updated: 09/14/2026, 10:01:30 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.