Skip to main content

Threats Tagged 'cve-2026-12413'

View all threats tagged with 'cve-2026-12413'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-12413

Threats Tagged 'cve-2026-12413'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.46. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63043 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Security Fix(es): * dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) * librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) * dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) * libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) * libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) * librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) * librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

Red Hat OpenShift Container Platform 4.20.37 includes multiple security fixes addressing vulnerabilities in components such as libreswan, sg3_utils, and libarchive. These vulnerabilities include denial of service via malformed packets, arbitrary command execution, double-free memory corruption, and assertion failures causing daemon crashes. Users of OpenShift Container Platform 4.20 and 4.21 are advised to upgrade to the updated packages and container images to mitigate these issues.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.37. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63099 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Security Fix(es): * librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) * libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) * libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) * librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) * librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion
0

Multiple denial of service vulnerabilities and a crash issue have been identified in libreswan, an IPsec and IKE implementation for Linux. These include DoS via RSA-SHA1 authentication payloads in IKEv1 and IKEv2, malformed fragmentation in IKEv2, and an assertion failure triggered by badly formatted X.509 certificates causing daemon crashes. The vulnerabilities affect Red Hat Enterprise Linux 9.6 Extended Update Support and related distributions. A security update addressing these issues is available from Red Hat.

Join the discussion
0

Multiple denial of service vulnerabilities and a crash issue have been identified in libreswan, an IPsec and IKE implementation for Linux. These include DoS via RSA-SHA1 authentication payloads in IKEv1 and IKEv2, DoS via malformed fragmentation in IKEv2, and an assertion failure caused by a badly formatted X.509 certificate that crashes the daemon. Red Hat has released an important security update for libreswan in Red Hat Enterprise Linux 10 to address these issues.

Join the discussion
0

Multiple denial of service vulnerabilities have been identified in libreswan, an implementation of IPsec and IKE for Linux, affecting Red Hat Enterprise Linux 9. These include issues with RSA-SHA1 authentication payloads in IKEv1 and IKEv2, malformed fragmentation in IKEv2, and a badly formatted X.509 certificate causing assertion failures that crash the daemon process. Red Hat has issued a security update to address these vulnerabilities.

Join the discussion
0

Multiple denial of service vulnerabilities and a crash issue have been identified in libreswan, an IPsec and IKE implementation for Linux. These include denial of service via RSA-SHA1 authentication payloads in both IKEv1 and IKEv2, malformed fragmentation in IKEv2, and an assertion failure caused by badly formatted X.509 certificates. These issues affect Red Hat Enterprise Linux 8 versions prior to 8.10.6. A security update addressing these vulnerabilities is available from Red Hat.

Join the discussion

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cve-2026-12413
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses