Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-75593 — github.com/moby/buildkit: BuildKit: File escape vulnerability allows unauthorized file modification
🎯 Affected products4
- Red Hat Hardened Images
- trivy-main@aarch64 as a component of Red Hat Hardened Images
- trivy-main@src as a component of Red Hat Hardened Images
- trivy-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:50953
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-75593
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50953.json