Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-15281 — glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory CVE-2026-0861 — glibc: Integer overflow in memalign leads to heap corruption CVE-2026-0915 — glibc: glibc: Information disclosure via zero-valued network query CVE-2026-1642 — nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections CVE-2026-22695 — libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read CVE-2026-22801 — libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API CVE-2026-25646 — libpng: LIBPNG has a heap buffer overflow in png_set_quantize
🎯 Affected products5
- Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:14856acc3c3e5403f53638618e7754e7fd73ffd2738ebae0a9f4f87da971dd28_arm64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:78ecba931b8e5ddcb90229391c486b9bddd367a75764e6299762290436f9eaab_amd64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:d167d7926b4a9e7bb51cab5108ad3e826a3ae826536924e8d4129f826c6c5de5_amd64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:f80b4635aa39ed1f1633277939dd8a54374a65fc9fd24cc31a4bd88cdc3cde6d_arm64 as a component of Red Hat Discovery 2
✅ Remediation
The containers required to run Discovery can be installed through discovery-installer RPM. See the official documentation for more details. Workaround: To mitigate this issue, consider refactoring the use of the wordexp function to not use the WRDE_REUSE and WRDE_APPEND flags together. Workaround: Applications calling one of the vulnerable functions and allowing the alignment parameter to be set by user-controlled input can implement additional validations checks, ensuring the alignment value is a power of two and does not exceed a sane limit, for example the system page size or a maximum of 64KB. This prevents the excessively large value required to trigger the integer overflow. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, users should avoid opening untrusted PNG image files. Applications that process PNG images should be configured to restrict processing of untrusted or unverified content where possible.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:4501
- externalhttps://access.redhat.com/security/cve/CVE-2025-15281
- externalhttps://access.redhat.com/security/cve/CVE-2026-0861
- externalhttps://access.redhat.com/security/cve/CVE-2026-0915
- externalhttps://access.redhat.com/security/cve/CVE-2026-1642
- externalhttps://access.redhat.com/security/cve/CVE-2026-22695
- externalhttps://access.redhat.com/security/cve/CVE-2026-22801
- externalhttps://access.redhat.com/security/cve/CVE-2026-25646
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4501.json