RHSA-2026:62790HighCVSS 9.1

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
September 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (19)

📋 Description

CVE-2026-7383 — openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing CVE-2026-9076 — openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption CVE-2026-34180 — openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. CVE-2026-34181 — openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CVE-2026-35188 — openssl: Double-free When Checking OCSP Stapled Response CVE-2026-42764 — openssl: NULL pointer dereference in QUIC server initial packet handling CVE-2026-42765 — openssl: NULL Dereference in Certificate Verification with OCSP Checking CVE-2026-42766 — openssl: Possible NULL Dereference in Password-Based CMS Decryption CVE-2026-42767 — openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption CVE-2026-42768 — openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() CVE-2026-42769 — openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate CVE-2026-42770 — openssl: FFC-DH Peer Validation Uses Attacker-Supplied q CVE-2026-42771 — openssl: Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path CVE-2026-45446 — openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVE-2026-84782 — openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission

🎯 Affected products50

  • Red Hat Hardened Images
  • ruby3.4-0:3.4.10-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • ruby3.4-0:3.4.10-31.7.hum1@src as a component of Red Hat Hardened Images
  • ruby3.4-0:3.4.10-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • ruby3.4-bundled-gems-0:3.4.10-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • ruby3.4-bundled-gems-0:3.4.10-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • ruby3.4-default-gems-0:3.4.10-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • ruby3.4-default-gems-0:3.4.10-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • ruby3.4-devel-0:3.4.10-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • ruby3.4-devel-0:3.4.10-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • ruby3.4-doc-0:3.4.10-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • ruby3.4-doc-0:3.4.10-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • ruby3.4-libs-0:3.4.10-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • ruby3.4-libs-0:3.4.10-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • rubygem3.4-bigdecimal-0:3.1.8-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • rubygem3.4-bigdecimal-0:3.1.8-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • rubygem3.4-bundler-0:2.6.9-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-bundler-0:2.6.9-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-devel-0:3.6.9-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-devel-0:3.6.9-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-io-console-0:0.8.1-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • rubygem3.4-io-console-0:0.8.1-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • rubygem3.4-irb-0:1.14.3-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-irb-0:1.14.3-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-json-0:2.9.1-31.7.hum1@aarch64 as a component of Red Hat Hardened Images
  • rubygem3.4-json-0:2.9.1-31.7.hum1@x86_64 as a component of Red Hat Hardened Images
  • rubygem3.4-minitest-0:5.25.4-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-minitest-0:5.25.4-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-power_assert-0:2.0.5-31.7.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • rubygem3.4-power_assert-0:2.0.5-31.7.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • +20 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, enforce strict validation on all uploaded PKCS#12 files to reject those containing abnormally short security keys. Additionally, enabling FIPS mode on your system can help protect your environment, as the vulnerable OpenSSL code operates entirely outside the approved FIPS cryptographic boundary. Workaround: Systems configured to operate in FIPS mode are not affected by this vulnerability. To mitigate this issue, ensure that OpenSSL is operating in FIPS mode by enabling the system-wide FIPS policy. This may have broader implications for cryptographic operations on the system and should be evaluated for compatibility with existing applications. A system reboot may be required for the changes to take effect. Workaround: To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack. Workaround: To mitigate this issue, ensure that OCSP stapling is disabled. As OCSP stapling is not enabled by default, no action is required unless it has been explicitly configured. If OCSP stapling has been enabled, consult the documentation for your specific application or service to disable it. Disabling OCSP stapling may affect the real-time revocation status checking of certificates. Workaround: To mitigate this issue, ensure that the OpenSSL QUIC server has client address validation enabled. This is the default configuration. If the `SSL_LISTENER_FLAG_NO_VALIDATE` flag is being used with the `SSL_new_listener()` call, it should be removed to prevent the vulnerability from being exploitable. Workaround: To mitigate this issue, ensure that applications do not enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) simultaneously. These flags are disabled by default, and maintaining the default configuration prevents exposure to this flaw. Consult application-specific documentation for details on how to configure certificate verification flags. Workaround: To mitigate this issue, ensure that OpenSSL CMP client applications only communicate with trusted Certificate Management Protocol (CMP) servers. If CMP client functionality is not required, consider disabling or restricting its use to reduce exposure. Workaround: To mitigate this vulnerability, applications utilizing CMS_decrypt() or PKCS7_decrypt() should ensure a recipient certificate is always provided to identify the specific RecipientInfo for decryption. This practice helps prevent the Bleichenbacher-style oracle attack by ensuring proper key identification. Workaround: The vulnerability arises from specific application implementations using OpenSSL's AES-SIV or AES-GCM-SIV modes with custom protocols and an atypical handling of empty ciphertexts. As this scenario is not a default or commonly deployed configuration in Red Hat products, and no direct configuration or operational control exists to mitigate this specific flaw without patching, the following applies: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (23)