Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-39243 — decompress: Decompress: File disclosure and corruption via arbitrary hardlink creation CVE-2026-39245 — decompress: decompress: path traversal via indexOf containment bypass allows arbitrary file write (bypass of CVE-2020-12265 fix) CVE-2026-59725 — socket.io: engine.io: Socket.IO: Denial of Service via invalid binary POST requests CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products4
- Red Hat Hardened Images
- dotnet8-0-main@aarch64 as a component of Red Hat Hardened Images
- dotnet8-0-main@src as a component of Red Hat Hardened Images
- dotnet8-0-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, avoid extracting archives from untrusted or unknown sources. When processing archives from potentially untrusted origins, consider using a sandboxed environment to limit the impact of any malicious content. Workaround: No upstream fix is available. The decompress package is unmaintained and no 4.2.2 release was ever published. Applications should avoid extracting untrusted archives with decompress 4.2.1, or migrate to a maintained fork such as @xhmikosr/decompress. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:37577
- externalhttps://access.redhat.com/security/cve/CVE-2026-59725
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-39243
- externalhttps://access.redhat.com/security/cve/CVE-2026-39245
- externalhttps://access.redhat.com/security/cve/CVE-2020-12265
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37577.json