Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 security update
🔗 CVE IDs covered (52)
📋 Description
CVE-2026-6464 — postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN
CVE-2026-6471 — postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin
CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error
CVE-2026-8927 — curl: Information disclosure due to uncleared proxy authentication state
CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
CVE-2026-14457 — openssl: RPK server signature algorithm selection can dereference a missing certificate
CVE-2026-14662 — postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions
CVE-2026-14664 — postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp
CVE-2026-14668 — postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator
CVE-2026-14669 — postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation
CVE-2026-14670 — postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow
CVE-2026-14671 — postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module
CVE-2026-14677 — postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl
CVE-2026-14679 — postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation
CVE-2026-14680 — postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments
CVE-2026-15741 — postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse
CVE-2026-15742 — postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound
CVE-2026-16239 — postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle
CVE-2026-18408 — postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump
CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet
CVE-2026-19385 — postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists
CVE-2026-19654 — rsyslog: A configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
CVE-2026-28420 — vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
CVE-2026-52859 — vim: Vim: Denial of Service via out-of-bounds write in terminal handling
CVE-2026-54874 — openssl: excessive memory use buffering DTLS records for a future epoch
CVE-2026-55892 — vim: Vim: Denial of Service via crafted spell file
CVE-2026-56392 — coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
CVE-2026-59857 — vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding
CVE-2026-59995 — openssh: OpenSSH: sftp client allows attacker to control downloaded file location
CVE-2026-59999 — openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping
CVE-2026-63073 — openssl: untrusted sender DN used as format string in CMP response validation
CVE-2026-63074 — openssl: CMP indefinite cache growth of ExtraCerts
CVE-2026-63075 — openssl: QUIC ACK-only packet retention can cause memory exhaustion
CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg
CVE-2026-63379 — libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning
CVE-2026-63381 — libevent: Libevent: Memory corruption due to use-after-free
CVE-2026-63382 — libevent: libevent: Multiple HTTP Parser Bugs Enable Request Smuggling
CVE-2026-63383 — libevent: Libevent: Denial of Service via malformed RPC data
CVE-2026-63384 — libevent: Libevent: Denial of Service via integer conversion error in evtag_unmarshal_header
CVE-2026-63385 — libevent: Libevent: HTTP header handling bugs create risk of access control bypass.
CVE-2026-63387 — libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption
CVE-2026-63388 — libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
CVE-2026-73072 — vim: Vim: Heap buffer overflow allows arbitrary code execution
CVE-2026-73076 — vim: Vim: Arbitrary command execution via crafted vimball
CVE-2026-73077 — vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling
CVE-2026-73078 — vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries
CVE-2026-73281 — openssh: OpenSSH: ssh-agent allows remote execution of local operations
CVE-2026-73282 — openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client
CVE-2026-73283 — openssh: OpenSSH: Tunnel forwarding restriction bypass
CVE-2026-78002 — rsyslog: rsyslog: Denial of service via heap buffer overflow in RainerScript replace() function
CVE-2026-82474 — sudo: Sudo: Policy bypass allows unauthorized program execution via execveat
🎯 Affected products6
- Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/cds-kubernetes-rhel9@sha256:b747ed57a2ed7dfc828ae6b99d8d7fff1fce78fc305b0dea48850368c49482b0_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/cds-rhel9@sha256:e47af425f90cd728c6509fea8ce8063c5b09d3e05f630aa168959ce03e0345b6_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/haproxy-rhel9@sha256:55999d0fdb5cb82536e4f27f820e655afa3036ea04fbb90b949f18c37629c52e_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/installer-rhel9@sha256:d48913b5697bc2befdfc1933ad427edec6b24bdb00ac06916386b6f319dccc4b_amd64 as a component of Red Hat Update Infrastructure 5
- registry.redhat.io/rhui5/rhua-rhel9@sha256:d20d237b12a31033a78d5a4dccf3ba61cfa43cdb564993c98997e6813d20cfd8_amd64 as a component of Red Hat Update Infrastructure 5
✅ Remediation
The container images provided by this release, apart from the installer, should be deployed using rhui-installer utility. See the official documentation for more details. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, ensure that the REPLICATION privilege is granted only to highly trusted database superusers. Regularly review user privileges to confirm that non-superuser accounts do not possess the REPLICATION privilege unless absolutely necessary and their activities are closely monitored. If logical decoding is not actively used, consider disabling it to further reduce the attack surface, though specific configuration steps for disabling logical decoding are beyond the scope of this mitigation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications utilizing libcurl should avoid reusing handles when switching between different proxy configurations. This operational control prevents the unintended leakage of `Proxy-Authorization` headers to incorrect proxies. Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: Restrict PostgreSQL to trusted hosts and bind only required interfaces. Do not grant CONNECT to untrusted roles; any session that can run SQL can call regexp_match / regexp_matches / regexp_split_to_*. If those functions are unused, REVOKE EXECUTE on them from PUBLIC. Workaround: To mitigate this vulnerability, administrators should enforce the principle of least privilege by revoking CREATE permissions on all databases from untrusted users. Because exploiting this flaw strictly requires the attacker to be an object creator, removing this privilege effectively neutralizes the threat. Ensure only highly trusted administrative roles can create database objects Workaround: To reduce the risk of exploitation, ensure that only trusted users have privileges to modify timezone settings within the PostgreSQL database. Additionally, restrict network access to the PostgreSQL server to only trusted clients and applications through firewall rules, limiting the attack surface for remote exploitation. Workaround: Disable the plperl procedural language if it is not actively required by executing DROP LANGUAGE plperl; on affected databases. Alternatively, restrict access by revoking USAGE privileges on plperl from untrusted roles. These actions prevent the execution of crafted plperl functions, mitigating the risk(a database restart may be required to clear active sessions). Workaround: To mitigate this vulnerability, administrators should avoid installing the refint module and remove it if it is currently deployed by executing DROP EXTENSION refint; as a database superuser. Additionally, enforcing the principle of least privilege by revoking CREATE permissions on databases from untrusted users prevents them from creating the malicious objects necessary to exploit this flaw. Workaround: To mitigate this issue, disable or remove the `pltcl` and `plperl` extensions if they are not essential for your PostgreSQL deployment, particularly in 32-bit environments. This can be done by revoking `CREATE` privilege on `LANGUAGE pltcl` and `LANGUAGE plperl` from untrusted users. If these extensions are necessary, ensure that only trusted users possess object creation privileges within the database. Workaround: Restrict PostgreSQL to trusted hosts and bind only the required interfaces; use pg_hba.conf so only trusted clients can reach the port. Do not grant CONNECT (or any SQL login) to untrusted roles —any session can trigger this. Workaround: To mitigate this vulnerability, administrators should strictly limit database object creation privileges to highly trusted users. When performing backups or database introspection using pg_dump or psql, exercise caution when operating on databases that allow untrusted users to define objects, Workaround: To mitigate this issue, consider disabling the `fuzzystrmatch` extension within PostgreSQL if its functionality is not essential. Alternatively, the `postgresql-fuzzystrmatch` package can be removed. Disabling or removing the extension may affect applications that rely on the `levenshtein()` or `levenshtein_less_equal()` functions. A database service restart may be required for these changes to take effect. Workaround: To mitigate this vulnerability, restrict direct database access strictly to trusted roles and minimize multi-tenant database scenarios where untrusted users can execute arbitrary SQL. Monitor database audit logs for anomalous or high-frequency cursor lifecycle activities involving unexpected CLOSE and DECLARE operations. Workaround: To mitigate this vulnerability, administrators should avoid generating or restoring pg_dump files from untrusted or public origin servers using the psql client. If restoring a plain-format dump from an unverified source is strictly necessary, manually inspect the file for unauthorized \restrict or \unrestrict meta-commands before execution, or isolate the restore process in a sandboxed environment Workaround: Restrict database user privileges, particularly object creation, to trusted administrators only. Ensure that `pg_dump` operations are performed by users with the least necessary operating system privileges to limit the impact of potential code execution. Workaround: To mitigate this issue, users that are relying on the imptcp module can implement one of the following options: 1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only Workaround: Users should exercise caution when opening untrusted files or executing untrusted programs within vim's `:terminal` window. Avoiding interaction with untrusted content in this context can prevent the exploitation of this vulnerability, which leads to a denial of service. Workaround: Do not load untrusted spell files (.spl) from unknown sources. Avoid using :spelldump with spell files of unknown provenance. Workaround: This vulnerability can be mitigated by preventing Vim from automatically…
🔗 References (57)
- selfhttps://access.redhat.com/errata/RHSA-2026:71603
- externalhttps://access.redhat.com/products/red-hat-update-infrastructure
- externalhttps://access.redhat.com/security/cve/CVE-2026-14456
- externalhttps://access.redhat.com/security/cve/CVE-2026-14457
- externalhttps://access.redhat.com/security/cve/CVE-2026-14662
- externalhttps://access.redhat.com/security/cve/CVE-2026-14664
- externalhttps://access.redhat.com/security/cve/CVE-2026-14668
- externalhttps://access.redhat.com/security/cve/CVE-2026-14669
- externalhttps://access.redhat.com/security/cve/CVE-2026-14670
- externalhttps://access.redhat.com/security/cve/CVE-2026-14671
- externalhttps://access.redhat.com/security/cve/CVE-2026-14677
- externalhttps://access.redhat.com/security/cve/CVE-2026-14679
- externalhttps://access.redhat.com/security/cve/CVE-2026-14680
- externalhttps://access.redhat.com/security/cve/CVE-2026-15741
- externalhttps://access.redhat.com/security/cve/CVE-2026-15742
- externalhttps://access.redhat.com/security/cve/CVE-2026-16239
- externalhttps://access.redhat.com/security/cve/CVE-2026-18408
- externalhttps://access.redhat.com/security/cve/CVE-2026-18798
- externalhttps://access.redhat.com/security/cve/CVE-2026-19385
- externalhttps://access.redhat.com/security/cve/CVE-2026-19654
- externalhttps://access.redhat.com/security/cve/CVE-2026-28420
- externalhttps://access.redhat.com/security/cve/CVE-2026-52859
- externalhttps://access.redhat.com/security/cve/CVE-2026-54874
- externalhttps://access.redhat.com/security/cve/CVE-2026-55892
- externalhttps://access.redhat.com/security/cve/CVE-2026-56392
- externalhttps://access.redhat.com/security/cve/CVE-2026-59857
- externalhttps://access.redhat.com/security/cve/CVE-2026-59995
- externalhttps://access.redhat.com/security/cve/CVE-2026-59999
- externalhttps://access.redhat.com/security/cve/CVE-2026-63072
- externalhttps://access.redhat.com/security/cve/CVE-2026-63073
- externalhttps://access.redhat.com/security/cve/CVE-2026-63074
- externalhttps://access.redhat.com/security/cve/CVE-2026-63075
- externalhttps://access.redhat.com/security/cve/CVE-2026-63076
- externalhttps://access.redhat.com/security/cve/CVE-2026-63379
- externalhttps://access.redhat.com/security/cve/CVE-2026-63381
- externalhttps://access.redhat.com/security/cve/CVE-2026-63382
- externalhttps://access.redhat.com/security/cve/CVE-2026-63383
- externalhttps://access.redhat.com/security/cve/CVE-2026-63384
- externalhttps://access.redhat.com/security/cve/CVE-2026-63385
- externalhttps://access.redhat.com/security/cve/CVE-2026-63387
- externalhttps://access.redhat.com/security/cve/CVE-2026-63388
- externalhttps://access.redhat.com/security/cve/CVE-2026-6464
- externalhttps://access.redhat.com/security/cve/CVE-2026-6471
- externalhttps://access.redhat.com/security/cve/CVE-2026-73072
- externalhttps://access.redhat.com/security/cve/CVE-2026-73076
- externalhttps://access.redhat.com/security/cve/CVE-2026-73077
- externalhttps://access.redhat.com/security/cve/CVE-2026-73078
- externalhttps://access.redhat.com/security/cve/CVE-2026-73281
- externalhttps://access.redhat.com/security/cve/CVE-2026-73282
- externalhttps://access.redhat.com/security/cve/CVE-2026-73283
- externalhttps://access.redhat.com/security/cve/CVE-2026-78002
- externalhttps://access.redhat.com/security/cve/CVE-2026-82474
- externalhttps://access.redhat.com/security/cve/CVE-2026-8458
- externalhttps://access.redhat.com/security/cve/CVE-2026-8927
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_update_infrastructure/5
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71603.json