RHSA-2026:67956HighCVSS 8.8

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 security update

Published
September 16, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2026-13221 — perl: Perl: Incorrect regular expression processing via large regular expressions CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server CVE-2026-14457 — openssl: RPK server signature algorithm selection can dereference a missing certificate CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-28420 — vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-50219 — expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking CVE-2026-52859 — vim: Vim: Denial of Service via out-of-bounds write in terminal handling CVE-2026-54874 — openssl: excessive memory use buffering DTLS records for a future epoch CVE-2026-55892 — vim: Vim: Denial of Service via crafted spell file CVE-2026-56132 — expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow CVE-2026-56392 — coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values CVE-2026-59857 — vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63073 — openssl: untrusted sender DN used as format string in CMP response validation CVE-2026-63074 — openssl: CMP indefinite cache growth of ExtraCerts CVE-2026-63075 — openssl: QUIC ACK-only packet retention can cause memory exhaustion CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg CVE-2026-73072 — vim: Vim: Heap buffer overflow allows arbitrary code execution CVE-2026-73076 — vim: Vim: Arbitrary command execution via crafted vimball CVE-2026-73077 — vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling CVE-2026-73078 — vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries

🎯 Affected products6

  • Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/cds-kubernetes-rhel9@sha256:1d39c59219055e1ebf4b62694a1d95b61733d543bcdf21bfd00a37a5f7bfd361_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/cds-rhel9@sha256:4cd9948823c36de5395d4da310fb2c0fab96129c24c0d156ee844d046be8eeaa_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/haproxy-rhel9@sha256:ff9abb0abb666e8f0feb0ea2f5bfaa0fa5711f8271334fa894cedfd1b6ef02ad_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/installer-rhel9@sha256:bb76e35f5208b23e3316038d06a2e418800e9c1a628d53dbe7c191f6ee7f1031_amd64 as a component of Red Hat Update Infrastructure 5
  • registry.redhat.io/rhui5/rhua-rhel9@sha256:4598bbf0e99024bf6253fcc4cb4d6c85f97990813aef6d46564f02f7cecae743_amd64 as a component of Red Hat Update Infrastructure 5

✅ Remediation

The container images provided by this release, apart from the installer, should be deployed using rhui-installer utility. See the official documentation for more details. Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Users should exercise caution when opening untrusted files or executing untrusted programs within vim's `:terminal` window. Avoiding interaction with untrusted content in this context can prevent the exploitation of this vulnerability, which leads to a denial of service. Workaround: Do not load untrusted spell files (.spl) from unknown sources. Avoid using :spelldump with spell files of unknown provenance. Workaround: This vulnerability can be mitigated by preventing Vim from automatically applying editor configurations embedded in files. Add the following line to the global /etc/vimrc or local ~/.vimrc configuration file: set nomodeline Workaround: If spell checking is unused, disable it with set nospell in ~/.vimrc and do not set spelllang. If spell is required, load only trusted .spl files from Vim’s spell directories and do not place untrusted spell files on runtimepath. Additionally, consider disabling modelines (set nomodeline in ~/.vimrc) to prevent untrusted text files from automatically overriding these settings when opened. Workaround: Avoid installing or removing vimballs from untrusted sources. This vulnerability relies on a user processing a malicious vimball, which then injects commands that are executed during a subsequent vimball operation. Exercise caution when handling vimball files from unknown or unverified origins. Workaround: To mitigate this vulnerability, users can disable the `keywordprg` option for shell script filetypes. This prevents Vim from executing external commands via the `K` command with potentially untrusted input. Create or edit the following files in your Vim configuration directory: - `~/.vim/after/ftplugin/sh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/zsh.vim`: `setlocal keywordprg=` - `~/.vim/after/ftplugin/ps1.vim`: `setlocal keywordprg=` This change takes effect the next time a shell script is opened in Vim. Workaround: To mitigate this issue, avoid browsing or bookmarking untrusted or maliciously crafted directory paths within GUI Vim. Users should exercise caution when interacting with `netrw` menu entries derived from external or untrusted sources.

🔗 References (28)