RHSA-2026:39981HighCVSS 9.1

Red Hat Security Advisory: Cost Management Metrics Operator Update

Published
July 15, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2025-5278 — coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification CVE-2026-0915 — glibc: glibc: Information disclosure via zero-valued network query CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CVE-2026-42764 — openssl: NULL pointer dereference in QUIC server initial packet handling CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

🔗 References (15)