Skip to main content
EPSS 0.3%top 73%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 04/15/2026 (04/15/2026, 10:20:34 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: golang1.26: * golang1.26-1.26.2-1.1.hum1 (aarch64, x86_64) * golang1.26-bin-1.26.2-1.1.hum1 (aarch64, x86_64) * golang1.26-docs-1.26.2-1.1.hum1 (noarch) * golang1.26-misc-1.26.2-1.1.hum1 (noarch) * golang1.26-shared-1.26.2-1.1.hum1 (aarch64, x86_64) * golang1.26-src-1.26.2-1.1.hum1 (noarch) * golang1.26-tests-1.26.2-1.1.hum1 (noarch) * golang1.26-1.26.2-1.1.hum1.src (src)

Affected software

Affected versions
=0.30.11-r1Red HatRed Hat Hardened Imagesaarch64golang1-26-main@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 00:25:20 UTC

Technical Analysis

CVE-2026-33813 is a denial of service vulnerability found in golang.org/x/image, specifically in the WEBP image parsing code. A remote attacker can supply a malformed WEBP image with an invalid, large size that triggers an integer overflow, leading to a panic and crash on 32-bit platforms. This causes the application to terminate unexpectedly, resulting in denial of service. The vulnerability is classified under CWE-190 (Integer Overflow or Wraparound). Red Hat has issued a security advisory (RHSA-2026:8291) and released patched versions of the golang1.26 packages as part of the Red Hat Hardened Images update, which includes the fix in ollama-fips version 0.30.11-r1.

Potential Impact

The vulnerability allows remote attackers to cause a denial of service by crashing applications that parse malicious WEBP images on 32-bit platforms. There is no indication of confidentiality or integrity impact. The primary impact is availability degradation due to application crashes. No known exploits are reported in the wild at this time.

Mitigation Recommendations

An official patch is available in ollama-fips version 0.30.11-r1 and corresponding golang1.26 packages released by Red Hat. Users should apply the update as provided by Red Hat Hardened Images RPMs to remediate this vulnerability. No additional mitigations are specified or required beyond applying the official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:8291
Cve Count
1
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a160988e29bf47b50652f00

Added to database: 05/26/2026, 20:58:48 UTC

Last enriched: 08/15/2026, 00:25:20 UTC

Last updated: 09/14/2026, 22:01:33 UTC

Views: 135

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses