Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-82458 — thrift: thrift: Denial of Service via excessive memory allocation CVE-2026-82459 — thrift: thrift: Denial of Service via integer underflow in THeaderTransport CVE-2026-85086 — thrift: thrift: Information disclosure via improper certificate validation in Perl bindings CVE-2026-85494 — thrift: thrift: Denial of Service via improper message handling in language bindings CVE-2026-93925 — thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol CVE-2026-93926 — thrift: thrift: Denial of Service via memory leak in THeaderTransport CVE-2026-94633 — thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings CVE-2026-94635 — thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings
🎯 Affected products14
- Red Hat Hardened Images
- perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- python3-thrift-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3-thrift-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- thrift-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- thrift-0:0.25.0-0.1.hum1@src as a component of Red Hat Hardened Images
- thrift-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- thrift-devel-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- thrift-devel-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- thrift-glib-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- thrift-glib-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- thrift-qt-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- thrift-qt-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:74369
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-94635
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-93926
- externalhttps://access.redhat.com/security/cve/CVE-2026-94634
- externalhttps://access.redhat.com/security/cve/CVE-2026-93925
- externalhttps://access.redhat.com/security/cve/CVE-2026-94633
- externalhttps://access.redhat.com/security/cve/CVE-2026-85483
- externalhttps://access.redhat.com/security/cve/CVE-2026-85494
- externalhttps://access.redhat.com/security/cve/CVE-2026-91137
- externalhttps://access.redhat.com/security/cve/CVE-2026-85087
- externalhttps://access.redhat.com/security/cve/CVE-2026-87117
- externalhttps://access.redhat.com/security/cve/CVE-2026-90440
- externalhttps://access.redhat.com/security/cve/CVE-2026-94650
- externalhttps://access.redhat.com/security/cve/CVE-2026-96294
- externalhttps://access.redhat.com/security/cve/CVE-2026-94644
- externalhttps://access.redhat.com/security/cve/CVE-2026-85086
- externalhttps://access.redhat.com/security/cve/CVE-2026-82458
- externalhttps://access.redhat.com/security/cve/CVE-2026-96990
- externalhttps://access.redhat.com/security/cve/CVE-2026-94645
- externalhttps://access.redhat.com/security/cve/CVE-2026-82459
- externalhttps://access.redhat.com/security/cve/CVE-2026-85493
- externalhttps://access.redhat.com/security/cve/CVE-2026-96292
- externalhttps://access.redhat.com/security/cve/CVE-2026-96288
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74369.json