Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-13608 — curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack CVE-2026-18924 — curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections CVE-2026-19931 — curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication CVE-2026-80230 — curl: curl: Public key pinning bypass allows unauthenticated connections CVE-2026-80231 — curl: curl: Incorrect HTTPS connection reuse with Native CA Store CVE-2026-82209 — curl: libcurl: Information disclosure via improper Public Suffix List boundary check
🎯 Affected products10
- Red Hat Hardened Images
- curl-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- curl-0:8.22.0-0.1.hum1@src as a component of Red Hat Hardened Images
- curl-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- libcurl-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- libcurl-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- libcurl-devel-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- libcurl-devel-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- libcurl-minimal-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- libcurl-minimal-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate enforce strict mutual authentication and cryptographic verification of both endpoints before transmitting sensitive data. Implement robust TLS/SSL configurations with explicit certificate pinning or strict CA validation to prevent Man-in-the-Middle (MITM) attackers from intercepting, prematurely concluding, or manipulating the handshake. Workaround: Disable HTTP/2 Server Push (CURLMOPT_PUSHFUNCTION) and shared connection handles (CURL_LOCK_DATA_CONNECT) in libcurl clients to eliminate the vulnerable code path. If these features cannot be disabled, enforce host-based firewalls to restrict affected applications' outbound HTTPS traffic solely to trusted endpoints, neutralizing the risk of exploitation by malicious HTTP/2 servers. Workaround: To mitigate this prevent connection reuse (CURLOPT_FORBID_REUSE) for transfers using Negotiate authentication with empty credentials and strictly isolate libcurl connection pools across different security principals. For defense-in-depth, enforce network boundaries to limit outbound HTTP access, mitigating the impact of any potential cross-session data exposure while pending upstream patches. Workaround: To mitigate this issue, ensure that SSL/TLS peer verification is enabled by setting `CURLOPT_SSL_VERIFYPEER` and `CURLOPT_SSL_VERIFYHOST` to `1` (or not explicitly disabling them). This ensures that libcurl properly enforces public key pinning and validates server certificates. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:63161
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-19931
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-13608
- externalhttps://access.redhat.com/security/cve/CVE-2026-18924
- externalhttps://access.redhat.com/security/cve/CVE-2026-82209
- externalhttps://access.redhat.com/security/cve/CVE-2026-80231
- externalhttps://access.redhat.com/security/cve/CVE-2026-80230
- externalhttps://access.redhat.com/security/cve/CVE-2026-80229
- externalhttps://access.redhat.com/security/cve/CVE-2026-80255
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63161.json