Skip to main content
EPSS 0.4%top 62%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Medium
Published: 04/11/2026 (04/11/2026, 00:39:54 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: xz: * xz-5.8.3-1.1.hum1 (aarch64, x86_64) * xz-devel-5.8.3-1.1.hum1 (aarch64, x86_64) * xz-libs-5.8.3-1.1.hum1 (aarch64, x86_64) * xz-lzma-compat-5.8.3-1.1.hum1 (aarch64, x86_64) * xz-static-5.8.3-1.1.hum1 (aarch64, x86_64) * xz-5.8.3-1.1.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64xz-main@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:05:59 UTC

Technical Analysis

CVE-2026-34743 is a vulnerability in XZ Utils where the lzma_index_decoder() function, when handling an empty index and a subsequent lzma_index_append() call, allocates insufficient memory. This leads to a buffer overflow that can cause denial of service by crashing or restarting affected systems. The issue is classified under CWE-131 (Incorrect Calculation of Buffer Size). Red Hat has issued an advisory indicating affected RPM packages for Red Hat Hardened Images on aarch64 and x86_64 architectures. The advisory references updated RPM versions (xz-5.8.3-1.1.hum1 and related packages). The vulnerability has a medium severity rating and no CVSS score is provided. Red Hat's advisory notes that scoring may differ from other sources due to product-specific factors. No known exploits in the wild have been reported.

Potential Impact

The vulnerability can cause denial of service (DoS) by triggering a buffer overflow due to insufficient memory allocation during index decoding in XZ Utils. This may result in application or system crashes. There is no indication of confidentiality or integrity impact. No known active exploitation has been reported.

Mitigation Recommendations

Red Hat has released updated RPM packages (xz-5.8.3-1.1.hum1 and related) addressing this issue. Users should apply these updates to affected Red Hat Hardened Images and related products. Since this is not a cloud service, remediation is the responsibility of the system administrators. If updates are not immediately available, consider applying any vendor-provided mitigations or consult Red Hat support. Patch status is not explicitly confirmed in the advisory text; users should verify the availability of fixes via the official Red Hat advisory linked in the report.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:2118-1
Cve Count
1
State
PUBLISHED

Threat ID: 6a1ca16ae29bf47b505e4657

Added to database: 05/31/2026, 21:00:26 UTC

Last enriched: 08/16/2026, 18:05:59 UTC

Last updated: 09/14/2026, 22:01:33 UTC

Views: 106

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses