Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update
🔗 CVE IDs covered (17)
📋 Description
CVE-2023-40403 — libxslt: Processing web content may disclose sensitive information CVE-2026-1642 — nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections CVE-2026-3497 — openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables CVE-2026-4111 — libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive CVE-2026-4424 — libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing CVE-2026-4519 — python: Python: Command-line option injection in webbrowser.open() via crafted URLs CVE-2026-5121 — libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-25749 — vim: Vim: Arbitrary code execution via 'helpfile' option processing CVE-2026-27135 — nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination CVE-2026-27651 — NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled CVE-2026-27654 — NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module CVE-2026-27784 — NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file CVE-2026-28417 — vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin CVE-2026-28421 — vim: Vim: Denial of service and information disclosure via crafted swap file CVE-2026-32647 — nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files CVE-2026-33412 — vim: Vim: Arbitrary code execution via command injection in glob() function
🎯 Affected products5
- Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/cds-rhel9@sha256:8ac1507077086484155f94d2289df0f1d22bfe8f5f15589d6b354f11fe21d930_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/haproxy-rhel9@sha256:8e13332d210961a93746eb0bd3761fa220dc710aada98b121320184aef2e5709_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/installer-rhel9@sha256:8fbf461b33717d3463e4f802b1a257b7e43d60c3e9568f710df83db36a04a4fe_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/rhua-rhel9@sha256:7eae5b16539484129c6ce169b41a3e1da7d7dd1296d2677acf7e9c3d1bce00ed_amd64 as a component of Red Hat Update Infrastructure 5
✅ Remediation
The container images provided by this release, apart from the installer, should be deployed using rhui-installer utility. See the official documentation for more details. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, disable GSSAPI key exchange in the OpenSSH server configuration. This prevents the server from processing GSSAPI messages, eliminating the vulnerability's attack surface. Edit `/etc/ssh/sshd_config` and add or modify the line: ``` GSSAPIKeyExchange no ``` After saving the changes, restart the `sshd` service for the mitigation to take effect. This action will prevent users from authenticating via GSSAPI. ``` # systemctl restart sshd ``` Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, avoid processing untrusted ISO9660 images with applications that utilize `libarchive`. Users should only extract or read content from ISO images obtained from trusted sources. Workaround: To mitigate this issue, disable the ngx_http_mp4_module in your NGINX configuration if MP4 file processing is not required. This can be done by commenting out or removing the mp4 directive from the NGINX configuration file. After modifying the configuration, a reload or restart of the NGINX service is required for the changes to take effect. Alternatively, restrict access to the NGINX server to trusted networks and users to prevent the upload and processing of malicious MP4 files.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2026:10065
- externalhttps://access.redhat.com/products/red-hat-update-infrastructure
- externalhttps://access.redhat.com/security/cve/CVE-2023-40403
- externalhttps://access.redhat.com/security/cve/CVE-2026-1642
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-25749
- externalhttps://access.redhat.com/security/cve/CVE-2026-27135
- externalhttps://access.redhat.com/security/cve/CVE-2026-27651
- externalhttps://access.redhat.com/security/cve/CVE-2026-27654
- externalhttps://access.redhat.com/security/cve/CVE-2026-27784
- externalhttps://access.redhat.com/security/cve/CVE-2026-28417
- externalhttps://access.redhat.com/security/cve/CVE-2026-28421
- externalhttps://access.redhat.com/security/cve/CVE-2026-32647
- externalhttps://access.redhat.com/security/cve/CVE-2026-33412
- externalhttps://access.redhat.com/security/cve/CVE-2026-3497
- externalhttps://access.redhat.com/security/cve/CVE-2026-4111
- externalhttps://access.redhat.com/security/cve/CVE-2026-4424
- externalhttps://access.redhat.com/security/cve/CVE-2026-4519
- externalhttps://access.redhat.com/security/cve/CVE-2026-5121
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_update_infrastructure/5
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10065.json