RHSA-2026:23245HighCVSS 8.2
Red Hat Security Advisory: OpenShift Container Platform 4.19.33 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-39979 — jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers CVE-2026-40164 — jq: jq: Denial of Service via crafted JSON object causing hash collisions CVE-2026-41035 — rsync: Rsync: Use-after-free vulnerability in extended attribute handling CVE-2026-46300 — kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:23245
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2451615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458077
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458898
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477015
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_23245.json