Threats Tagged 'cve-2026-50722'
View all threats tagged with 'cve-2026-50722'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-50722'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.46. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63043 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Security Fix(es): * dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) * librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) * dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) * libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) * libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) * librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) * librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 09/09/2026, 10:01:11 UTC Added: 06/17/2026, 16:47:11 UTC |
0 Red Hat OpenShift Container Platform 4.20.37 includes multiple security fixes addressing vulnerabilities in components such as libreswan, sg3_utils, and libarchive. These vulnerabilities include denial of service via malformed packets, arbitrary command execution, double-free memory corruption, and assertion failures causing daemon crashes. Users of OpenShift Container Platform 4.20 and 4.21 are advised to upgrade to the updated packages and container images to mitigate these issues. Join the discussion | GCVE Database | 09/08/2026, 12:01:14 UTC Added: 08/21/2026, 14:22:18 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.37. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63099 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Security Fix(es): * librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) * libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) * libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) * librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) * librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 09/08/2026, 12:01:14 UTC Added: 08/21/2026, 14:22:11 UTC |
0 Multiple denial of service vulnerabilities and a crash issue have been identified in libreswan, an IPsec and IKE implementation for Linux. These include DoS via RSA-SHA1 authentication payloads in IKEv1 and IKEv2, malformed fragmentation in IKEv2, and an assertion failure triggered by badly formatted X.509 certificates causing daemon crashes. The vulnerabilities affect Red Hat Enterprise Linux 9.6 Extended Update Support and related distributions. A security update addressing these issues is available from Red Hat. Join the discussion | GCVE Database | 08/31/2026, 04:16:47 UTC Added: 08/21/2026, 14:22:18 UTC |
0 Multiple denial of service vulnerabilities and a crash issue have been identified in libreswan, an IPsec and IKE implementation for Linux. These include DoS via RSA-SHA1 authentication payloads in IKEv1 and IKEv2, DoS via malformed fragmentation in IKEv2, and an assertion failure caused by a badly formatted X.509 certificate that crashes the daemon. Red Hat has released an important security update for libreswan in Red Hat Enterprise Linux 10 to address these issues. Join the discussion | GCVE Database | 07/27/2026, 03:46:42 UTC Added: 08/21/2026, 14:22:11 UTC |
0 Multiple denial of service vulnerabilities have been identified in libreswan, an implementation of IPsec and IKE for Linux, affecting Red Hat Enterprise Linux 9. These include issues with RSA-SHA1 authentication payloads in IKEv1 and IKEv2, malformed fragmentation in IKEv2, and a badly formatted X.509 certificate causing assertion failures that crash the daemon process. Red Hat has issued a security update to address these vulnerabilities. Join the discussion | GCVE Database | 07/27/2026, 03:46:32 UTC Added: 08/21/2026, 14:22:11 UTC |
0 Multiple denial of service vulnerabilities and a crash issue have been identified in libreswan, an IPsec and IKE implementation for Linux. These include denial of service via RSA-SHA1 authentication payloads in both IKEv1 and IKEv2, malformed fragmentation in IKEv2, and an assertion failure caused by badly formatted X.509 certificates. These issues affect Red Hat Enterprise Linux 8 versions prior to 8.10.6. A security update addressing these vulnerabilities is available from Red Hat. Join the discussion | GCVE Database | 07/27/2026, 03:23:42 UTC Added: 08/21/2026, 14:22:11 UTC |
0 Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected. Join the discussion | CVE Database V5 | 07/02/2026, 21:34:41 UTC Added: 07/02/2026, 22:06:45 UTC |
Showing 1 to 8 of 8 results