Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: trivy: * trivy-0.69.3-1.2.hum1 (aarch64, x86_64) * trivy-0.69.3-1.2.hum1.src (src)
AI Analysis
Technical Summary
The advisory covers a security update for Red Hat Hardened Images RPMs, specifically including trivy packages version 0.69.3-1.2.hum1. Among the addressed issues is CVE-2026-45287, a vulnerability in OpenTelemetry-Go's schema parsing (before schema package version 0.0.17) where the ParseFile function leaks file descriptors by not closing files after parsing. This can lead to exhaustion of file descriptors in long-running processes, causing denial of service. The exposure is limited to applications that parse schemas from untrusted file paths. The advisory lists multiple CVEs (including CVE-2026-44432) but does not provide detailed descriptions for all. The update is a bug fix and enhancement release, with references to Red Hat's errata and security pages for further details. No explicit patch status is stated for all CVEs, but updated RPMs are provided.
Potential Impact
The primary impact is a potential denial of service due to resource exhaustion (file descriptor leaks) in affected components, notably OpenTelemetry-Go schema parsing. This can cause affected services to crash or stall if an attacker can induce repeated schema parsing from attacker-controlled file paths. Other vulnerabilities referenced involve resource management flaws (CWE-770, CWE-409, CWE-772, CWE-59, CWE-807) that may also lead to denial of service or other stability issues. No data indicates confidentiality or integrity impacts. No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (trivy-0.69.3-1.2.hum1) for affected architectures. Users should apply these updates as per Red Hat's guidance at https://images.redhat.com/. The advisory does not explicitly state that all CVEs are fixed in this update, so users should monitor Red Hat's official errata and security advisories for confirmation. No additional mitigations are specified. Since this is not a cloud service, remediation depends on applying the vendor-provided updates.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: trivy: * trivy-0.69.3-1.2.hum1 (aarch64, x86_64) * trivy-0.69.3-1.2.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The advisory covers a security update for Red Hat Hardened Images RPMs, specifically including trivy packages version 0.69.3-1.2.hum1. Among the addressed issues is CVE-2026-45287, a vulnerability in OpenTelemetry-Go's schema parsing (before schema package version 0.0.17) where the ParseFile function leaks file descriptors by not closing files after parsing. This can lead to exhaustion of file descriptors in long-running processes, causing denial of service. The exposure is limited to applications that parse schemas from untrusted file paths. The advisory lists multiple CVEs (including CVE-2026-44432) but does not provide detailed descriptions for all. The update is a bug fix and enhancement release, with references to Red Hat's errata and security pages for further details. No explicit patch status is stated for all CVEs, but updated RPMs are provided.
Potential Impact
The primary impact is a potential denial of service due to resource exhaustion (file descriptor leaks) in affected components, notably OpenTelemetry-Go schema parsing. This can cause affected services to crash or stall if an attacker can induce repeated schema parsing from attacker-controlled file paths. Other vulnerabilities referenced involve resource management flaws (CWE-770, CWE-409, CWE-772, CWE-59, CWE-807) that may also lead to denial of service or other stability issues. No data indicates confidentiality or integrity impacts. No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (trivy-0.69.3-1.2.hum1) for affected architectures. Users should apply these updates as per Red Hat's guidance at https://images.redhat.com/. The advisory does not explicitly state that all CVEs are fixed in this update, so users should monitor Red Hat's official errata and security advisories for confirmation. No additional mitigations are specified. Since this is not a cloud service, remediation depends on applying the vendor-provided updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:15862
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-45287"]
Threat ID: 6a340ceff198dc38c10606c8
Added to database: 06/18/2026, 15:21:19 UTC
Last enriched: 08/16/2026, 17:31:56 UTC
Last updated: 09/17/2026, 22:01:35 UTC
Views: 188
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.