Red Hat Security Advisory: Red Hat Update Infrastructure 5.2 security update
🔗 CVE IDs covered (28)
📋 Description
CVE-2024-34459 — libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c
CVE-2025-5278 — coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification
CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2025-10911 — libxslt: use-after-free with key data stored cross-RVT
CVE-2025-13151 — libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
CVE-2026-5435 — glibc: glibc: Out-of-bounds write via TSIG record processing
CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width
CVE-2026-5928 — glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
CVE-2026-6238 — glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
CVE-2026-6472 — postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
CVE-2026-6473 — postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write
CVE-2026-6474 — postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function
CVE-2026-6475 — postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind
CVE-2026-6477 — postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory
CVE-2026-6478 — postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison
CVE-2026-6479 — postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation
CVE-2026-6637 — postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module
CVE-2026-9256 — nginx: ngx_http_rewrite_module: code execution and denial of service
CVE-2026-15308 — python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations
CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
CVE-2026-41411 — vim: Vim: Command injection allows arbitrary code execution via malicious tag files
CVE-2026-42055 — nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers
CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-48864 — libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions
CVE-2026-54370 — acl: TOCTOU Symlink Traversal via getfacl/setfacl
CVE-2026-58016 — glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2026:44481
- externalhttps://access.redhat.com/products/red-hat-update-infrastructure
- externalhttps://access.redhat.com/security/cve/CVE-2024-34459
- externalhttps://access.redhat.com/security/cve/CVE-2025-10911
- externalhttps://access.redhat.com/security/cve/CVE-2025-13151
- externalhttps://access.redhat.com/security/cve/CVE-2025-5278
- externalhttps://access.redhat.com/security/cve/CVE-2025-6170
- externalhttps://access.redhat.com/security/cve/CVE-2026-15308
- externalhttps://access.redhat.com/security/cve/CVE-2026-31790
- externalhttps://access.redhat.com/security/cve/CVE-2026-41411
- externalhttps://access.redhat.com/security/cve/CVE-2026-42055
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-48864
- externalhttps://access.redhat.com/security/cve/CVE-2026-5435
- externalhttps://access.redhat.com/security/cve/CVE-2026-54369
- externalhttps://access.redhat.com/security/cve/CVE-2026-54370
- externalhttps://access.redhat.com/security/cve/CVE-2026-5450
- externalhttps://access.redhat.com/security/cve/CVE-2026-58016
- externalhttps://access.redhat.com/security/cve/CVE-2026-5928
- externalhttps://access.redhat.com/security/cve/CVE-2026-6238
- externalhttps://access.redhat.com/security/cve/CVE-2026-6472
- externalhttps://access.redhat.com/security/cve/CVE-2026-6473
- externalhttps://access.redhat.com/security/cve/CVE-2026-6474
- externalhttps://access.redhat.com/security/cve/CVE-2026-6475
- externalhttps://access.redhat.com/security/cve/CVE-2026-6477
- externalhttps://access.redhat.com/security/cve/CVE-2026-6478
- externalhttps://access.redhat.com/security/cve/CVE-2026-6479
- externalhttps://access.redhat.com/security/cve/CVE-2026-6637
- externalhttps://access.redhat.com/security/cve/CVE-2026-9256
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_update_infrastructure/5
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44481.json