Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
CVE-2026-15788 is a medium severity vulnerability in BuildKit used by Red Hat Hardened Images. It allows an untrusted user authoring a build on a Windows Container on Windows (WCOW) configured BuildKit daemon to read arbitrary files from the host system due to improper handling of NTFS directory junctions, leading to information disclosure. The issue is related to a path traversal flaw (CWE-22). Red Hat has released updated RPM packages including buildah-1.44.0-3.2.hum1 to address this vulnerability.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-15788) affects BuildKit in Red Hat Hardened Images. An untrusted user can exploit a flaw in the cache mount source selector on a Windows Container on Windows (WCOW) configured BuildKit daemon to read arbitrary files from the host system. The root cause is improper limitation of pathnames leading to a path traversal (CWE-22). This results in information disclosure without requiring privileges or user interaction. Red Hat has issued a security advisory (RHSA-2026:43122) with updated buildah RPMs to fix this issue.
Potential Impact
An attacker with the ability to author builds on a vulnerable BuildKit daemon configured for WCOW can read arbitrary files on the host system, leading to confidentiality breaches. There is no impact on integrity or availability reported. The vulnerability does not require privileges or user interaction, but the attack vector is local to the BuildKit daemon environment. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (buildah-1.44.0-3.2.hum1 and buildah-tests-1.44.0-3.2.hum1) that address this vulnerability. Users should apply these updates promptly to remediate the issue. No additional mitigations or workarounds are specified in the vendor advisory. Patch status is confirmed by Red Hat's official advisory.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
CVE-2026-15788 is a medium severity vulnerability in BuildKit used by Red Hat Hardened Images. It allows an untrusted user authoring a build on a Windows Container on Windows (WCOW) configured BuildKit daemon to read arbitrary files from the host system due to improper handling of NTFS directory junctions, leading to information disclosure. The issue is related to a path traversal flaw (CWE-22). Red Hat has released updated RPM packages including buildah-1.44.0-3.2.hum1 to address this vulnerability.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-15788) affects BuildKit in Red Hat Hardened Images. An untrusted user can exploit a flaw in the cache mount source selector on a Windows Container on Windows (WCOW) configured BuildKit daemon to read arbitrary files from the host system. The root cause is improper limitation of pathnames leading to a path traversal (CWE-22). This results in information disclosure without requiring privileges or user interaction. Red Hat has issued a security advisory (RHSA-2026:43122) with updated buildah RPMs to fix this issue.
Potential Impact
An attacker with the ability to author builds on a vulnerable BuildKit daemon configured for WCOW can read arbitrary files on the host system, leading to confidentiality breaches. There is no impact on integrity or availability reported. The vulnerability does not require privileges or user interaction, but the attack vector is local to the BuildKit daemon environment. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (buildah-1.44.0-3.2.hum1 and buildah-tests-1.44.0-3.2.hum1) that address this vulnerability. Users should apply these updates promptly to remediate the issue. No additional mitigations or workarounds are specified in the vendor advisory. Patch status is confirmed by Red Hat's official advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:43122
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a74cf8fbf8831d5391aef0f
Added to database: 08/06/2026, 18:16:47 UTC
Last enriched: 08/06/2026, 18:43:26 UTC
Last updated: 08/07/2026, 03:40:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.