RHSA-2026:52807HighCVSS 7.8

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
August 10, 2026
Last Modified
September 5, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-75593 — github.com/moby/buildkit: BuildKit: File escape vulnerability allows unauthorized file modification

🎯 Affected products5

  • Red Hat Hardened Images
  • podman-main@aarch64 as a component of Red Hat Hardened Images
  • podman-main@noarch as a component of Red Hat Hardened Images
  • podman-main@src as a component of Red Hat Hardened Images
  • podman-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes.

🔗 References (6)