Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 97%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Medium
Published: 08/05/2026 (08/05/2026, 17:29:27 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A heap buffer overflow vulnerability (CVE-2026-44605) was found in the RPM Package Manager (RPM) used in Red Hat Hardened Images. The flaw occurs when processing a specially crafted NDB database file due to incorrect memory allocation calculations. This can lead to a denial of service by crashing the system. The impact is considered low on Red Hat Enterprise Linux and Fedora because NDB is not the default RPM database backend, which reduces the attack surface. A security update is available addressing this issue in multiple RPM packages.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 12:54:33 UTC

Technical Analysis

CVE-2026-44605 is a heap buffer overflow vulnerability in the RPM Package Manager's NDB database backend caused by an integer overflow or wraparound during file parsing. This results in incorrect memory allocation, which can be triggered by processing a maliciously crafted NDB database file. The vulnerability can cause a denial of service by crashing the system. Red Hat notes that the default RPM backend in their distributions is SQLite, not NDB, which significantly limits exposure. The issue affects multiple RPM-related packages in Red Hat Hardened Images and has been addressed in version 6.0.1-6.2.hum1 of these packages.

Potential Impact

The vulnerability can cause a denial of service (system crash or unavailability) when a local user processes a specially crafted NDB database file with RPM. There is no impact on confidentiality or integrity. The attack complexity is low and no privileges are required, but user interaction is needed. The overall impact on Red Hat Enterprise Linux and Fedora is low due to the non-default use of the NDB backend, reducing the attack surface.

Mitigation Recommendations

A security update is available from Red Hat that addresses this vulnerability in multiple RPM packages (version 6.0.1-6.2.hum1). Users of Red Hat Hardened Images should apply this update promptly. Since the vulnerability is in the NDB backend, which is not the default, the risk is reduced. No additional mitigations are specified by Red Hat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:33507
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a44530727e9c79719919ba8

Added to database: 06/30/2026, 23:36:39 UTC

Last enriched: 08/10/2026, 12:54:33 UTC

Last updated: 08/14/2026, 12:41:10 UTC

Views: 124

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses