Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'red-hat-product-security'

View all threats tagged with 'red-hat-product-security'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: red-hat-product-security

Threats Tagged 'red-hat-product-security'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-84292
0

Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, specifically updating grafana12.4 packages to address multiple vulnerabilities including CVE-2026-84292 and CVE-2026-84394. CVE-2026-84292 is a high severity flaw in the fast-uri component where improper serialization of the URI port allows an attacker to inject authority delimiters, potentially causing information disclosure by redirecting authority to an attacker-controlled host. The advisory includes updated RPMs for grafana12.4 on aarch64 and x86_64 architectures. No explicit patch availability statement is provided, but updated packages are released. No known exploits in the wild have been reported. The vulnerabilities relate to improper input validation and serialization issues.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement updateCVE-2026-18149
0

This update includes the following RPMs: nodejs24: * nodejs24-24.18.1-0.2.2.hum1 (aarch64, x86_64) * nodejs24-bin-24.18.1-0.2.2.hum1 (noarch) * nodejs24-devel-24.18.1-0.2.2.hum1 (aarch64, x86_64) * nodejs24-docs-24.18.1-0.2.2.hum1 (noarch) * nodejs24-full-i18n-24.18.1-0.2.2.hum1 (aarch64, x86_64) * nodejs24-libs-24.18.1-0.2.2.hum1 (aarch64, x86_64) * nodejs24-npm-11.16.0-1.24.18.1.0.2.2.hum1 (noarch) * nodejs24-npm-bin-24.18.1-0.2.2.hum1 (noarch) * v8-13.6-devel-13.6.233.17-1.24.18.1.0.2.2.hum1 (aarch64, x86_64) * nodejs24-24.18.1-0.2.2.hum1.src (src)

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-15534
0

A vulnerability (CVE-2026-15534) was found in Perl's regular expression engine used in Red Hat Hardened Images. It involves a signed 32-bit integer overflow in the superlinear cache size calculation, which can cause out-of-bounds heap memory reads and writes during regex matching. Exploitation requires matching a very large input (~273 MiB) against a complex pattern with at least 15 participating WHILEM nodes. The primary impact is denial of service due to process crashes; arbitrary code execution has not been demonstrated. Red Hat has deferred fixing this issue due to the high complexity and limited exposure. Mitigations include limiting untrusted input size and avoiding complex regex patterns on untrusted data.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement updateCVE-2026-40930
0

A moderate security flaw (CVE-2026-40930) was found in libpng, a library used for processing PNG image files, including Animated PNGs (APNG). The vulnerability allows a remote attacker to craft a malicious APNG file that causes the application to misinterpret attacker-controlled data as a new chunk header. This can lead to denial of service or unexpected application behavior affecting data integrity and availability. Red Hat has issued an update for Red Hat Hardened Images RPMs including libpng version 1.6.58-1.hum1 to address this issue. No direct patch link is provided, but the advisory references updated RPMs. Mitigations are currently not available or do not meet Red Hat's criteria for deployment. The vulnerability has not been observed exploited in the wild.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement updateCVE-2026-77117
0

A moderate severity vulnerability (CVE-2026-80489) was found in the GNU C Library (glibc) affecting Red Hat Hardened Images RPMs. The flaw involves an infinite loop during SHIFT_JISX0213 to UCS-4 text conversion when processing specially crafted input, leading to a denial of service (DoS) condition by causing the application to become unresponsive. Exploitation requires specific application behavior and input, limiting the attack surface. Red Hat has released an update including glibc packages to address this issue.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-55893
0

A heap buffer overflow vulnerability exists in the Capstone disassembly framework's SH floating-point decoders due to improper validation of operand array size. This flaw allows a local attacker to provide crafted SH2A FPU bytecode, potentially causing application crashes (Denial of Service) and possibly enabling arbitrary code execution. The issue affects Red Hat Hardened Images RPMs including various capstone packages. Red Hat has issued a security advisory with updated RPMs addressing these vulnerabilities. No CVSS score is provided, but the impact is significant due to potential code execution and denial of service.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-76642
0

A local privilege escalation vulnerability exists in util-linux versions 2.39 through 2.42.2 used in Red Hat Hardened Images. When an external mount helper fails with a nonzero exit status, libmount incorrectly treats the mount as successful and executes privileged post-mount hooks. This can allow a local unprivileged user with a specific /etc/fstab configuration to escalate privileges by manipulating filesystem ownership or cloning. Red Hat has released updates to util-linux to address this issue.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement updateCVE-2026-75593
0

CVE-2026-75593 is a medium severity vulnerability in BuildKit, a toolkit used for building software artifacts. It allows an authenticated client with valid permissions to the BuildKit control API to craft a special upload request that escapes the intended build state directory. This can lead to unauthorized modification or deletion of files on the system. The vulnerability is related to improper limitation of pathname to a restricted directory (CWE-22).

Join the discussion
Node undici: (undici 8.10.0 omits the destination origin from the cache and request- ...) (CVE-2026-85152)CVE-2026-85152
0

(undici 8.10.0 omits the destination origin from the cache and request- ...)

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-41992
0

This update includes the following RPMs: gzip: * gzip-1.14-2.3.hum1 (aarch64, x86_64) * gzip-1.14-2.3.hum1.src (src) Security Fix(es): gzip: * CVE-2026-41992

Join the discussion

Showing 1 to 10 of 221 results

Filters:Tag: red-hat-product-security
Page 1 of 23
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses