Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-14457 — openssl: RPK server signature algorithm selection can dereference a missing certificate CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-54874 — openssl: excessive memory use buffering DTLS records for a future epoch CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63073 — openssl: untrusted sender DN used as format string in CMP response validation CVE-2026-63074 — openssl: CMP indefinite cache growth of ExtraCerts CVE-2026-63075 — openssl: QUIC ACK-only packet retention can cause memory exhaustion CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg
🎯 Affected products4
- Red Hat Hardened Images
- openssl-main@aarch64 as a component of Red Hat Hardened Images
- openssl-main@src as a component of Red Hat Hardened Images
- openssl-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:59641
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-63074
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-63073
- externalhttps://access.redhat.com/security/cve/CVE-2026-14457
- externalhttps://access.redhat.com/security/cve/CVE-2026-63076
- externalhttps://access.redhat.com/security/cve/CVE-2026-63075
- externalhttps://access.redhat.com/security/cve/CVE-2026-63072
- externalhttps://access.redhat.com/security/cve/CVE-2026-54874
- externalhttps://access.redhat.com/security/cve/CVE-2026-18798
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59641.json