RHSA-2026:69321MediumCVSS 5.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
September 21, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-6862 — efivar: efivar: Denial of Service due to stack overflow in device path node parsing

🎯 Affected products8

  • Red Hat Hardened Images
  • efivar-0:39-13.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • efivar-0:39-13.1.hum1@src as a component of Red Hat Hardened Images
  • efivar-0:39-13.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • efivar-devel-0:39-13.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • efivar-devel-0:39-13.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • efivar-libs-0:39-13.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • efivar-libs-0:39-13.1.hum1@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Applications using efi_loadopt_is_valid() should validate the size of the input buffer before passing it to libefiboot. As a library-level fix, the device path iterator should enforce a minimum node Length of 4 before recursing: if (dp->length < 4) return -1;

🔗 References (5)