Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
Multiple security vulnerabilities have been identified and fixed in apr-util, including a timing attack vulnerability in apr_password_validate(), XML stack recursion crash, SQL injection in apr_dbd_oracle, and heap buffer overflows in Redis and memcached clients. The timing attack vulnerability allows potential leakage of password hash content via side-channel timing differences but is assessed as low impact due to practical exploitation difficulties. Red Hat has released updated apr-util packages to address these issues.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security update for apr-util addresses several vulnerabilities: CVE-2025-49506 is a timing side-channel attack in apr_password_validate() that can leak password hash content by measuring comparison timing differences, primarily affecting platforms without crypt() implementations. CVE-2026-32327 is an XML stack recursion crash. CVE-2026-34191 is an SQL injection vulnerability in apr_dbd_oracle. CVE-2026-34501 and CVE-2026-34502 are heap buffer overflows in Redis and APR memcached clients respectively. Red Hat released apr-util version 1.6.5-1 to fix these issues. The timing attack vulnerability is considered low impact due to high attack complexity and practical network noise, and standard deployments typically rely on system crypt() bypassing the vulnerable code path.
Potential Impact
The timing attack vulnerability (CVE-2025-49506) could theoretically disclose password hash content, impacting confidentiality, but practical exploitation is highly complex and unlikely over networks due to timing noise. The other vulnerabilities include potential denial of service (XML stack recursion crash) and remote code execution or data compromise risks from SQL injection and heap buffer overflows. Overall, these vulnerabilities pose critical security risks if unpatched.
Mitigation Recommendations
Red Hat has released updated apr-util packages (version 1.6.5-1) that fix these vulnerabilities. Users should apply these official updates promptly. No alternative mitigations are currently recommended or available. The timing attack vulnerability is of low practical impact and no specific mitigation beyond patching is advised.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:58474
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-32327","CVE-2026-34501","CVE-2026-34502"]
- State
- PUBLISHED
Threat ID: 6a89a6d2acd9273b491510b1
Added to database: 08/22/2026, 13:40:34 UTC
Last enriched: 09/29/2026, 21:44:27 UTC
Last updated: 10/06/2026, 18:48:16 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.