Skip to main content
EPSS 0.4%top 70%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Critical
Published: 08/22/2026 (08/22/2026, 00:58:40 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Multiple security vulnerabilities have been identified and fixed in apr-util, including a timing attack vulnerability in apr_password_validate(), XML stack recursion crash, SQL injection in apr_dbd_oracle, and heap buffer overflows in Redis and memcached clients. The timing attack vulnerability allows potential leakage of password hash content via side-channel timing differences but is assessed as low impact due to practical exploitation difficulties. Red Hat has released updated apr-util packages to address these issues.

Affected software

Affected versions
>=1.6.1 <1.6.5Red HatRed Hat Hardened Imagesaarch64apr-util-0:1.6.5-1.hum1@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:44:27 UTC

Technical Analysis

This security update for apr-util addresses several vulnerabilities: CVE-2025-49506 is a timing side-channel attack in apr_password_validate() that can leak password hash content by measuring comparison timing differences, primarily affecting platforms without crypt() implementations. CVE-2026-32327 is an XML stack recursion crash. CVE-2026-34191 is an SQL injection vulnerability in apr_dbd_oracle. CVE-2026-34501 and CVE-2026-34502 are heap buffer overflows in Redis and APR memcached clients respectively. Red Hat released apr-util version 1.6.5-1 to fix these issues. The timing attack vulnerability is considered low impact due to high attack complexity and practical network noise, and standard deployments typically rely on system crypt() bypassing the vulnerable code path.

Potential Impact

The timing attack vulnerability (CVE-2025-49506) could theoretically disclose password hash content, impacting confidentiality, but practical exploitation is highly complex and unlikely over networks due to timing noise. The other vulnerabilities include potential denial of service (XML stack recursion crash) and remote code execution or data compromise risks from SQL injection and heap buffer overflows. Overall, these vulnerabilities pose critical security risks if unpatched.

Mitigation Recommendations

Red Hat has released updated apr-util packages (version 1.6.5-1) that fix these vulnerabilities. Users should apply these official updates promptly. No alternative mitigations are currently recommended or available. The timing attack vulnerability is of low practical impact and no specific mitigation beyond patching is advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:58474
Cve Count
4
Additional Cves
["CVE-2026-32327","CVE-2026-34501","CVE-2026-34502"]
State
PUBLISHED

Threat ID: 6a89a6d2acd9273b491510b1

Added to database: 08/22/2026, 13:40:34 UTC

Last enriched: 09/29/2026, 21:44:27 UTC

Last updated: 10/06/2026, 18:48:16 UTC

Views: 46

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses