RHSA-2026:4501HighCVSS 8.1
Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-15281 — glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory CVE-2026-0861 — glibc: Integer overflow in memalign leads to heap corruption CVE-2026-0915 — glibc: glibc: Information disclosure via zero-valued network query CVE-2026-1642 — nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections CVE-2026-22695 — libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read CVE-2026-22801 — libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API CVE-2026-25646 — libpng: LIBPNG has a heap buffer overflow in png_set_quantize
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:4501
- externalhttps://access.redhat.com/security/cve/CVE-2025-15281
- externalhttps://access.redhat.com/security/cve/CVE-2026-0861
- externalhttps://access.redhat.com/security/cve/CVE-2026-0915
- externalhttps://access.redhat.com/security/cve/CVE-2026-1642
- externalhttps://access.redhat.com/security/cve/CVE-2026-22695
- externalhttps://access.redhat.com/security/cve/CVE-2026-22801
- externalhttps://access.redhat.com/security/cve/CVE-2026-25646
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4501.json