Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update
🔗 CVE IDs covered (32)
📋 Description
CVE-2025-9086 — curl: libcurl: Curl out of bounds read for cookie path
CVE-2025-9820 — gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function
CVE-2025-11187 — openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file
CVE-2025-12084 — cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service
CVE-2025-13836 — cpython: Excessive read buffering DoS in http.client
CVE-2025-14104 — util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames
CVE-2025-14831 — gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
CVE-2025-15281 — glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
CVE-2025-15366 — cpython: IMAP command injection in user-controlled commands
CVE-2025-15367 — cpython: POP3 command injection in user-controlled commands
CVE-2025-15467 — openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
CVE-2025-15468 — openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
CVE-2025-15469 — openssl: OpenSSL: Data integrity bypass in openssl dgst command due to silent truncation
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url
CVE-2025-66199 — openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
CVE-2025-68160 — openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
CVE-2025-69418 — openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
CVE-2025-69419 — openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
CVE-2025-69420 — openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
CVE-2025-69421 — openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
CVE-2026-0861 — glibc: Integer overflow in memalign leads to heap corruption
CVE-2026-0865 — cpython: wsgiref.headers.Headers allows header newline injection in Python
CVE-2026-0915 — glibc: glibc: Information disclosure via zero-valued network query
CVE-2026-1299 — cpython: email header injection due to unquoted newlines
CVE-2026-1642 — nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections
CVE-2026-2003 — postgresql: PostgreSQL oidvector discloses a few bytes of memory
CVE-2026-2004 — postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
CVE-2026-2005 — postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
CVE-2026-2006 — postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code
CVE-2026-22795 — openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
CVE-2026-22796 — openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID
🎯 Affected products5
- Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/installer-rhel9@sha256:2c50c87906a1abebf427a70f401c409f1258cb55d2096f517db870ec991cfd7f_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/rhua-rhel9@sha256:5f1fbf66fb349a7baf066a1216d39989c3b89f18ec5108b96d9643baf4856778_amd64 as a component of Red Hat Update Infrastructure 5
✅ Remediation
The container images provided by this release, apart from the installer, should be deployed using rhui-installer utility. See the official documentation for more details. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Applying the upstream patch or vendor-supplied security update is the recommended resolution. Workaround: To mitigate this issue, avoid processing untrusted PKCS#12 files. Applications should only handle PKCS#12 files from trusted sources, as these files are typically used for storing private keys and are expected to be secure. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Since this vulnerability is triggered when no read amount is specified and the client defaults to using the potentially malicious Content-Length header, developers can mitigate this issue in their code by always imposing an explicit, safe limit on data reads. Applications using the http.client.HTTPResponse.read function directly can ensure that read operations specify a byte limit: ~~~ ... max_safe_read = 10 * 1024 * 1024 data = response.read(max_safe_read) ... ~~~ Workaround: To mitigate this issue, consider refactoring the use of the wordexp function to not use the WRDE_REUSE and WRDE_APPEND flags together. Workaround: To mitigate this vulnerability, ensure that no data passed to the imaplib module contains newline or carriage return characters. Workaround: To mitigate this vulnerability, ensure that no data passed to the poplib module contains newline or carriage return characters. Workaround: To mitigate this issue, avoid using the `openssl dgst` command with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) for files larger than 16MB. Instead, utilize streaming digest algorithms with `openssl dgst` or use library APIs for signing and verification, as these are not affected by the truncation vulnerability. Users should ensure that input files for one-shot signing/verification with `openssl dgst` do not exceed 16MB. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, disable the reception of compressed certificates by setting the SSL_OP_NO_RX_CERTIFICATE_COMPRESSION option in OpenSSL configurations. This will prevent the vulnerable code path from being exercised. Workaround: To mitigate this vulnerability, Red Hat recommends avoiding the processing of PKCS#12 files from untrusted or unverified sources. Applications that use the `PKCS12_get_friendlyname()` API should ensure that PKCS#12 files are only processed if they originate from trusted entities. Restricting the input sources for PKCS#12 files can significantly reduce the attack surface for this flaw. Workaround: Restrict applications from processing untrusted or externally supplied PKCS#12 files, ensuring certificates are sourced only from trusted internal authorities. Additionally, configure critical background services with automatic restart policies (such as systemd's Restart=on-failure) to quickly restore availability if a denial-of-service crash occurs. Workaround: Applications calling one of the vulnerable functions and allowing the alignment parameter to be set by user-controlled input can implement additional validations checks, ensuring the alignment value is a power of two and does not exceed a sane limit, for example the system page size or a maximum of 64KB. This prevents the excessively large value required to trigger the integer overflow. Workaround: To mitigate this issue, applications accepting user-supplied data for email headers should sanitize the input by stripping or rejecting any strings containing carriage return or line feed characters, '\r' or '\n', respectively, preventing malicious sequences that could lead to header manipulation.
🔗 References (37)
- selfhttps://access.redhat.com/errata/RHSA-2026:4943
- externalhttps://access.redhat.com/products/red-hat-update-infrastructure
- externalhttps://access.redhat.com/security/cve/CVE-2025-11187
- externalhttps://access.redhat.com/security/cve/CVE-2025-12084
- externalhttps://access.redhat.com/security/cve/CVE-2025-13836
- externalhttps://access.redhat.com/security/cve/CVE-2025-14104
- externalhttps://access.redhat.com/security/cve/CVE-2025-14831
- externalhttps://access.redhat.com/security/cve/CVE-2025-15281
- externalhttps://access.redhat.com/security/cve/CVE-2025-15366
- externalhttps://access.redhat.com/security/cve/CVE-2025-15367
- externalhttps://access.redhat.com/security/cve/CVE-2025-15467
- externalhttps://access.redhat.com/security/cve/CVE-2025-15468
- externalhttps://access.redhat.com/security/cve/CVE-2025-15469
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-66199
- externalhttps://access.redhat.com/security/cve/CVE-2025-68160
- externalhttps://access.redhat.com/security/cve/CVE-2025-69418
- externalhttps://access.redhat.com/security/cve/CVE-2025-69419
- externalhttps://access.redhat.com/security/cve/CVE-2025-69420
- externalhttps://access.redhat.com/security/cve/CVE-2025-69421
- externalhttps://access.redhat.com/security/cve/CVE-2025-9086
- externalhttps://access.redhat.com/security/cve/CVE-2025-9820
- externalhttps://access.redhat.com/security/cve/CVE-2026-0861
- externalhttps://access.redhat.com/security/cve/CVE-2026-0865
- externalhttps://access.redhat.com/security/cve/CVE-2026-0915
- externalhttps://access.redhat.com/security/cve/CVE-2026-1299
- externalhttps://access.redhat.com/security/cve/CVE-2026-1642
- externalhttps://access.redhat.com/security/cve/CVE-2026-2003
- externalhttps://access.redhat.com/security/cve/CVE-2026-2004
- externalhttps://access.redhat.com/security/cve/CVE-2026-2005
- externalhttps://access.redhat.com/security/cve/CVE-2026-2006
- externalhttps://access.redhat.com/security/cve/CVE-2026-22795
- externalhttps://access.redhat.com/security/cve/CVE-2026-22796
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_update_infrastructure/5
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4943.json