Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-26157 — busybox: BusyBox: Arbitrary file overwrite and potential code execution via incomplete path sanitization CVE-2026-26158 — busybox: BusyBox: Arbitrary file modification and privilege escalation via unvalidated tar archive entries
🎯 Affected products4
- Red Hat Hardened Images
- busybox-main@aarch64 as a component of Red Hat Hardened Images
- busybox-main@src as a component of Red Hat Hardened Images
- busybox-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: As a prevention measure, avoid extracting archives from untrusted sources using BusyBox utilities. If extraction of untrusted archives is necessary, perform it within a highly isolated and restricted environment, such as a container with a read-only root filesystem and minimal privileges, to limit the potential impact of arbitrary file overwrites. Workaround: As a prevention measure, avoid extracting tar archives from untrusted sources using BusyBox, especially when operating with elevated privileges. If processing untrusted archives is unavoidable, ensure that the extraction process is performed within a strictly sandboxed environment with minimal permissions. This operational control reduces the risk of arbitrary file modification and privilege escalation.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:13831
- externalhttps://access.redhat.com/security/cve/CVE-2026-26157
- externalhttps://access.redhat.com/security/cve/CVE-2026-26158
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13831.json