RHSA-2026:58981CriticalCVSS 9.1

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Published
August 24, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (118)

CVE-2026-4046CVE-2026-6238CVE-2026-45445CVE-2025-6075CVE-2026-8286CVE-2026-58012CVE-2026-6472CVE-2026-5419CVE-2026-42010CVE-2026-42055CVE-2026-29111CVE-2026-31790CVE-2024-34459CVE-2026-2100CVE-2026-4438CVE-2026-42012CVE-2026-42014CVE-2026-45447CVE-2026-59996CVE-2026-9547CVE-2025-6170CVE-2025-15282CVE-2026-44431CVE-2026-45446CVE-2025-13837CVE-2026-3644CVE-2026-13757CVE-2026-34183CVE-2026-35387CVE-2026-35388CVE-2026-55653CVE-2026-58010CVE-2025-10911CVE-2026-42767CVE-2026-48864CVE-2026-59856CVE-2026-59858CVE-2025-14512CVE-2026-4437CVE-2026-6479CVE-2026-34181CVE-2026-35177CVE-2026-40356CVE-2026-41411CVE-2026-1502CVE-2026-3832CVE-2026-55654CVE-2026-1965CVE-2026-9256CVE-2026-14164CVE-2026-35414CVE-2025-14087CVE-2026-5435CVE-2026-3833CVE-2026-6475CVE-2026-42015CVE-2026-4224CVE-2026-34180CVE-2026-42013CVE-2026-5260CVE-2026-5928CVE-2026-33846CVE-2026-34182CVE-2026-58014CVE-2025-13151CVE-2026-6474CVE-2026-15588CVE-2026-42768CVE-2026-55693CVE-2026-58055CVE-2026-6473CVE-2026-52858CVE-2026-42766CVE-2026-58015CVE-2026-0865CVE-2026-2297CVE-2026-42009CVE-2026-47167CVE-2026-46483CVE-2026-47162CVE-2026-58011CVE-2026-11940CVE-2026-5450CVE-2026-9076CVE-2026-35385CVE-2026-35535CVE-2026-44432CVE-2026-57456CVE-2026-6637CVE-2026-33845CVE-2026-34982CVE-2026-45409CVE-2026-4878CVE-2026-54369CVE-2026-58013CVE-2026-35386CVE-2026-0672CVE-2026-7383CVE-2026-42769CVE-2026-42945CVE-2026-57455CVE-2026-28390CVE-2026-40355CVE-2026-42011CVE-2026-45186CVE-2026-3783CVE-2026-55655CVE-2026-58016CVE-2026-42764CVE-2026-42770CVE-2026-60002CVE-2026-15308CVE-2025-5278CVE-2026-6477CVE-2026-6478CVE-2025-59375CVE-2026-41989CVE-2026-54370

📋 Description

CVE-2024-34459 — libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c CVE-2025-5278 — coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification CVE-2025-6075 — python: Quadratic complexity in os.path.expandvars() with user-controlled template CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling CVE-2025-10911 — libxslt: use-after-free with key data stored cross-RVT CVE-2025-13151 — libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string CVE-2025-13837 — cpython: Out-of-memory when loading Plist CVE-2025-14087 — glib: GLib: Buffer underflow in GVariant parser leads to heap corruption CVE-2025-14512 — glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow CVE-2025-15282 — cpython: Header injection via newlines in data URL mediatype in Python CVE-2025-59375 — firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing CVE-2026-0672 — cpython: Header injection in http.cookies.Morsel in Python CVE-2026-0865 — cpython: wsgiref.headers.Headers allows header newline injection in Python CVE-2026-1502 — python: Python: HTTP header injection via CR/LF in proxy tunnel headers CVE-2026-1965 — curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication CVE-2026-2100 — p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters CVE-2026-2297 — cpython: CPython: Logging Bypass in Legacy .pyc File Handling CVE-2026-3644 — cpython: Incomplete control character validation in http.cookies CVE-2026-3783 — curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect CVE-2026-3832 — gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response CVE-2026-3833 — gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison CVE-2026-4046 — glibc: glibc: Denial of Service via iconv() function with specific character sets CVE-2026-4224 — cpython: Stack overflow parsing XML with deeply nested DTD content models CVE-2026-4437 — glibc: glibc: Incorrect DNS response parsing via crafted DNS server response CVE-2026-4438 — glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-5260 — gnutls: gnutls: Information disclosure via heap overread in RSA key exchange CVE-2026-5419 — gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal CVE-2026-5435 — glibc: glibc: Out-of-bounds write via TSIG record processing CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width CVE-2026-5928 — glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings CVE-2026-6238 — glibc: glibc: Application crash or uninitialized memory read via crafted DNS response CVE-2026-6472 — postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVE-2026-6473 — postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVE-2026-6474 — postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function CVE-2026-6475 — postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind CVE-2026-6477 — postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory CVE-2026-6478 — postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison CVE-2026-6479 — postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation CVE-2026-6637 — postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module CVE-2026-7383 — openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-9076 — openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption CVE-2026-9256 — nginx: ngx_http_rewrite_module: code execution and denial of service CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-11940 — python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory CVE-2026-13757 — p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing CVE-2026-14164 — libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() CVE-2026-15308 — python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations CVE-2026-15588 — GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering CVE-2026-28390 — openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing CVE-2026-29111 — systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key CVE-2026-33845 — gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment CVE-2026-33846 — gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly CVE-2026-34180 — openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. CVE-2026-34181 — openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CVE-2026-34982 — vim: arbitrary command execution via modeline sandbox bypass CVE-2026-35177 — vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass CVE-2026-35385 — OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode CVE-2026-35386 — OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username CVE-2026-35387 — OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage CVE-2026-35388 — OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions CVE-2026-35414 — OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option CVE-2026-35535 — sudo: Sudo: Privilege escalation due to failure in privilege drop calls CVE-2026-40355 — krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism CVE-2026-40356 — krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read CVE-2026-41411 — vim: Vim: Command injection allows arbitrary code execution via malicious tag files CVE-2026-41989 — Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext CVE-2026-42009 — gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability CVE-2026-42010 — gnutls: gnutls: Authentication Bypass via NUL Character in Username CVE-2026-42011 — gnutls: gnutls: Security bypass due to incorrect name constraint handling CVE-2026-42012 — gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs CVE-2026-42013 — gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name CVE-2026-42014 — gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin CVE-2026-42015 — gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling CVE-2026-42055 — nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers CVE-2026-42764 — openssl: NULL pointer dereference in QUIC server initial packet handling CVE-2026-42766 — openssl: Possible NULL Dereference in Password-Based CMS Decryption CVE-2026-42767 — openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption CVE-2026-42768 — openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() CVE-2026-42769 — openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate CVE-2026-42770 — openssl: FFC-DH Peer Validation Uses Attacker-Supplied q CVE-2026-42945 — nginx: NGINX: Arbitrary Code Execution Vulnerability CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-45186 — libexpat: denial of service via crafted XML input CVE-2026-45409 — python-idna: idna: Denial of Service via specially crafted long inputs CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path CVE-2026-45446 — openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVE-2026-46483 — vim: command injection when decompressing .tgz archives CVE-2026-47162 — vim: Vim: Arbitrary Code Execution via crafted directory names CVE-2026-47167 — vim: Vim: Arbitrary code execution via crafted step-definition patterns CVE-2026-48864 — libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CVE-2026-52858 — vim: Vim: Arbitrary code execution via Python omni-completion CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions CVE-2026-54370 — acl: TOCTOU Symlink Traversal via getfacl/setfacl CVE-2026-55653 — openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service CVE-2026-55654 — openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination CVE-2026-55655 — openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions CVE-2026-55693 — vim: Vim: Out-of-bounds Write in Spell File Word Count CVE-2026-57455 — vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() CVE-2026-57456 — vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion CVE-2026-58010 — glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() CVE-2026-58011 — glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime CVE-2026-58012 — glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() CVE-2026-58013 — glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" CVE-2026-58014 — glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" CVE-2026-58015 — glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive CVE-2026-58016 — glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" CVE-2026-58055 — nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests CVE-2026-59856 — vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion CVE-2026-59858 — vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion CVE-2026-59996 — openssh: OpenSSH: scp file misplacement vulnerability during remote copy CVE-2026-60002 — openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side

🎯 Affected products5

  • Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/cds-tp-rhel9@sha256:9160d973640e48fd9d72f92f5395f2d61f54fa2dae7dce4e6658dfc420f53088_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/rhua-tp-rhel9@sha256:2dc99bbbcad15bd50b1ad227f6d4557f5b17fed7388e3eb127c058e3f4636b15_amd64 as a component of Red Hat Update Infrastructure 5

✅ Remediation

Please consult the RHUI Technology Preview Release Notes at https://access.redhat.com/articles/7141172 for instructions on how to use this image set. Workaround: Do not process untrusted files with the xmllint program. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate the issue, limit XML input size and complexity before parsing, and avoid accepting compressed or deeply nested XML. Use OS-level resource controls (like ulimit or setrlimit()) to cap memory usage, or run the parser in a sandboxed or isolated process with strict memory and CPU limits. This helps prevent denial-of-service by containing excessive resource consumption. Workaround: To prevent the leakage of OAuth2 bearer tokens, ensure that `.netrc` files are carefully managed. Avoid configuring `.netrc` entries for untrusted or unknown hostnames, particularly when `curl` is used with OAuth2 bearer tokens and is configured to follow redirects. Regularly review and restrict the scope of credentials stored in `.netrc` files to only explicitly trusted destinations. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Workaround: To mitigate this vulnerability, validate the length of data and the size of objects on all client APIs and web interfaces. Also, block, drop, or truncate oversized string, array, or binary objects before they are passed into backend SQL queries. Workaround: Only connect to trusted PostgreSQL servers. Avoid using psql or pg_dump against untrusted or potentially compromised database servers. Workaround: To mitigate this vulnerability, ensure that all PostgreSQL user passwords are not hashed using MD5. Users should migrate to stronger hashing algorithms such as `scram-sha-256`. This can be achieved by altering user passwords, which will automatically update their hash to the currently configured default. For example, to change a user's password: `ALTER USER username WITH PASSWORD 'new_password';` This action will require users to re-authenticate. If a service relies on these credentials, it may require a restart to pick up the new authentication details. Workaround: Upgrade to PostgreSQL 18.4, 17.10, 16.14, 15.18, or 14.23 (matching your major version) or later. Restricting network/socket access to trusted clients reduces exposure but does not eliminate the vulnerability. Workaround: To mitigate this vulnerability, use named captures instead of unnamed captures in rewrite definitions. For example, the following rewrite directive uses unnamed PCRE capture groups, $1 and $2: ~~~ rewrite ^/users/([0-9]+)/profile/(.*)$ /profile.php?id=$1&tab=$2 last; ~~~ To mitigate this vulnerability for this example, replace $1 and $2 with the appropriate named captures, $user_id and $section: ~~~ rewrite ^/users/(?<user_id>[0-9]+)/profile/(?<section>.*)$ /profile.php?id=$user_id&tab=$section last; ~~~ Workaround: This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user/<uid>/p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure `Restart=on-failure` is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw. Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available. Workaround: Applications that process Cryptographic Message Syntax (CMS) EnvelopedData messages should be configured to only accept input from trusted sources. Restricting network access to services that process untrusted CMS data can also reduce exposure to this Denial of Service vulnerability. Workaround: To mitigate this issue, enforce strict validation on all uploaded PKCS#12 files to reject those containing abnormally short security keys. Additionally, enabling FIPS mode on your system can help protect your environment, as the vulnerable OpenSSL code operates entirely outside the approved FIPS cryptographic boundary. Workaround: Systems configured to operate in FIPS mode are not affected by this vulnerability. To mitigate this issue, ensure that OpenSSL is operating in FIPS mode by enabling the system-wide FIPS policy. This may have broader implications for cryptographic operations on the system and should be evaluated for compatibility with existing applications. A system reboot may be required for the changes to take effect. Workaround: To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack. Workaround: To mitigate this issue, disable the modeline support by adding the following command to the Vim configuration file: ~~~ set nomodeline ~~~ Workaround: Avoid opening untrusted zip archives with Vim. This operational control prevents the necessary user interaction required to trigger the path traversal vulnerability in the `zip.vim` plugin. Workaround: To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in `/etc/gss/mech`. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality. Workaround: To mitigate this issue, ensure that the NegoEx mechanism is not registered in the `/etc/gss/mech` configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect. Workaround: Mitigation for this issue involves exercising caution when opening or processing tag files from untrusted sources. Users should avoid loading tag files from unknown or suspicious origins to prevent the execution of arbitrary commands. Workaround: To mitigate this vulnerability, ensure that the `ignore_invalid_headers` directive is set to `on` in your NGINX configuration, or reduce the size specified by the `large_client_header_buffers` directive …

🔗 References (124)