Skip to main content
EPSS 0.7%top 49%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Critical
Published: 05/09/2026 (05/09/2026, 15:24:33 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: trivy: * trivy-0.69.3-1.2.hum1 (aarch64, x86_64) * trivy-0.69.3-1.2.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64trivy-main@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:31:56 UTC

Technical Analysis

The advisory covers a security update for Red Hat Hardened Images RPMs, specifically including trivy packages version 0.69.3-1.2.hum1. Among the addressed issues is CVE-2026-45287, a vulnerability in OpenTelemetry-Go's schema parsing (before schema package version 0.0.17) where the ParseFile function leaks file descriptors by not closing files after parsing. This can lead to exhaustion of file descriptors in long-running processes, causing denial of service. The exposure is limited to applications that parse schemas from untrusted file paths. The advisory lists multiple CVEs (including CVE-2026-44432) but does not provide detailed descriptions for all. The update is a bug fix and enhancement release, with references to Red Hat's errata and security pages for further details. No explicit patch status is stated for all CVEs, but updated RPMs are provided.

Potential Impact

The primary impact is a potential denial of service due to resource exhaustion (file descriptor leaks) in affected components, notably OpenTelemetry-Go schema parsing. This can cause affected services to crash or stall if an attacker can induce repeated schema parsing from attacker-controlled file paths. Other vulnerabilities referenced involve resource management flaws (CWE-770, CWE-409, CWE-772, CWE-59, CWE-807) that may also lead to denial of service or other stability issues. No data indicates confidentiality or integrity impacts. No known active exploitation has been reported.

Mitigation Recommendations

Red Hat has released updated RPM packages (trivy-0.69.3-1.2.hum1) for affected architectures. Users should apply these updates as per Red Hat's guidance at https://images.redhat.com/. The advisory does not explicitly state that all CVEs are fixed in this update, so users should monitor Red Hat's official errata and security advisories for confirmation. No additional mitigations are specified. Since this is not a cloud service, remediation depends on applying the vendor-provided updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:15862
Cve Count
2
Additional Cves
["CVE-2026-45287"]

Threat ID: 6a340ceff198dc38c10606c8

Added to database: 06/18/2026, 15:21:19 UTC

Last enriched: 08/16/2026, 17:31:56 UTC

Last updated: 09/17/2026, 22:01:35 UTC

Views: 188

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses