Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: ngtcp2: * ngtcp2-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-gnutls-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-gnutls-devel-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-ossl-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-ossl-devel-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-devel-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-doc-1.22.1-1.hum1 (noarch) * ngtcp2-1.22.1-1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-40170 is a stack buffer overflow vulnerability in the ngtcp2 library, triggered by processing specially crafted large transport parameters during the QUIC handshake when the qlog callback is enabled. This vulnerability can cause denial of service by writing beyond a fixed-size buffer. While the vulnerable code is present in some Red Hat packages, it is not compiled into the NodeJS binaries shipped by Red Hat, thus those are not affected. The vulnerability impacts Samba versions 4.23 and above included in RHEL 9.8+ and RHEL 10.2+, which support SMB over QUIC using ngtcp2. The vulnerability is tracked under CWE-120. Red Hat recommends disabling the qlog callback to mitigate the issue, which may reduce logging capabilities. No known exploits are reported in the wild.
Potential Impact
The vulnerability allows a remote attacker to cause a denial of service by triggering a stack buffer overflow during the QUIC handshake when qlog is enabled. This results in application crashes or restarts, impacting availability. There is no reported impact on confidentiality or integrity. The affected functionality is experimental and disabled by default in NodeJS packages shipped by Red Hat, limiting exposure. Samba on certain RHEL versions that support SMB over QUIC is affected, potentially impacting services relying on this protocol.
Mitigation Recommendations
Red Hat advises disabling the qlog callback in applications using the ngtcp2 library to prevent the vulnerable code path from being exercised. This mitigation may reduce logging and debugging capabilities. Applications linked against ngtcp2 must be restarted after disabling qlog for the change to take effect. NodeJS packages shipped by Red Hat are not affected as QUIC support is disabled by default. For Samba on RHEL 9.8+ and 10.2+, consider disabling SMB over QUIC or applying updates when available. Patch status is not explicitly confirmed in the advisory; check Red Hat's official advisory for updates.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: ngtcp2: * ngtcp2-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-gnutls-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-gnutls-devel-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-ossl-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-crypto-ossl-devel-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-devel-1.22.1-1.hum1 (aarch64, x86_64) * ngtcp2-doc-1.22.1-1.hum1 (noarch) * ngtcp2-1.22.1-1.hum1.src (src)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-40170 is a stack buffer overflow vulnerability in the ngtcp2 library, triggered by processing specially crafted large transport parameters during the QUIC handshake when the qlog callback is enabled. This vulnerability can cause denial of service by writing beyond a fixed-size buffer. While the vulnerable code is present in some Red Hat packages, it is not compiled into the NodeJS binaries shipped by Red Hat, thus those are not affected. The vulnerability impacts Samba versions 4.23 and above included in RHEL 9.8+ and RHEL 10.2+, which support SMB over QUIC using ngtcp2. The vulnerability is tracked under CWE-120. Red Hat recommends disabling the qlog callback to mitigate the issue, which may reduce logging capabilities. No known exploits are reported in the wild.
Potential Impact
The vulnerability allows a remote attacker to cause a denial of service by triggering a stack buffer overflow during the QUIC handshake when qlog is enabled. This results in application crashes or restarts, impacting availability. There is no reported impact on confidentiality or integrity. The affected functionality is experimental and disabled by default in NodeJS packages shipped by Red Hat, limiting exposure. Samba on certain RHEL versions that support SMB over QUIC is affected, potentially impacting services relying on this protocol.
Mitigation Recommendations
Red Hat advises disabling the qlog callback in applications using the ngtcp2 library to prevent the vulnerable code path from being exercised. This mitigation may reduce logging and debugging capabilities. Applications linked against ngtcp2 must be restarted after disabling qlog for the change to take effect. NodeJS packages shipped by Red Hat are not affected as QUIC support is disabled by default. For Samba on RHEL 9.8+ and 10.2+, consider disabling SMB over QUIC or applying updates when available. Patch status is not explicitly confirmed in the advisory; check Red Hat's official advisory for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:9113
- Cve Count
- 1
Threat ID: 6a298f90c9170919df395ea5
Added to database: 06/10/2026, 16:23:44 UTC
Last enriched: 08/16/2026, 17:46:17 UTC
Last updated: 09/14/2026, 15:21:38 UTC
Views: 185
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.