Red Hat Security Advisory: Red Hat AI Base Images 3.4.3 (Neuron)
🔗 CVE IDs covered (83)
📋 Description
CVE-2023-52355 — libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM
CVE-2024-34459 — libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c
CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2025-10911 — libxslt: use-after-free with key data stored cross-RVT
CVE-2025-14087 — glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
CVE-2025-14512 — glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
CVE-2026-3833 — gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-4775 — libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
CVE-2026-4786 — python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API
CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
CVE-2026-5260 — gnutls: gnutls: Information disclosure via heap overread in RSA key exchange
CVE-2026-5419 — gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal
CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width
CVE-2026-6100 — python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules
CVE-2026-6477 — postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory
CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
CVE-2026-10118 — poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication
CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5
CVE-2026-11940 — python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory
CVE-2026-12912 — libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image
CVE-2026-14164 — libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack()
CVE-2026-15308 — python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations
CVE-2026-15588 — GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering
CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
CVE-2026-26740 — giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
CVE-2026-29111 — systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
CVE-2026-33416 — libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
CVE-2026-33636 — libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
CVE-2026-33845 — gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
CVE-2026-33846 — gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly
CVE-2026-34588 — OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file
CVE-2026-34982 — vim: arbitrary command execution via modeline sandbox bypass
CVE-2026-35177 — vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
CVE-2026-35385 — OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode
CVE-2026-35386 — OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username
CVE-2026-35387 — OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage
CVE-2026-35388 — OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions
CVE-2026-35414 — OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option
CVE-2026-39979 — jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers
CVE-2026-40164 — jq: jq: Denial of Service via crafted JSON object causing hash collisions
CVE-2026-40356 — krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
CVE-2026-41142 — OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing
CVE-2026-41411 — vim: Command injection allows arbitrary code execution via malicious tag files
CVE-2026-41989 — Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
CVE-2026-42009 — gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-42010 — gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-42011 — gnutls: gnutls: Security bypass due to incorrect name constraint handling
CVE-2026-42012 — gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs
CVE-2026-42013 — gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name
CVE-2026-42014 — gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin
CVE-2026-42015 — gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
CVE-2026-42216 — OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files
CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-46483 — vim: command injection when decompressing .tgz archives
CVE-2026-47162 — vim: Vim: Arbitrary Code Execution via crafted directory names
CVE-2026-47167 — vim: Vim: Arbitrary code execution via crafted step-definition patterns
CVE-2026-48864 — libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-52858 — vim: Vim: Arbitrary code execution via Python omni-completion
CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions
CVE-2026-54411 — linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module
CVE-2026-55693 — vim: Vim: Out-of-bounds Write in Spell File Word Count
CVE-2026-55971 — thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow
CVE-2026-57455 — vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo()
CVE-2026-57456 — vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
CVE-2026-58010 — glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58011 — glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
CVE-2026-58012 — glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
CVE-2026-58013 — glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58014 — glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58015 — glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
CVE-2026-58016 — glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-59856 — vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion
CVE-2026-59858 — vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion
CVE-2026-60002 — openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
CVE-2026-64830 — ffmpeg: FFmpeg: Arbitrary code execution via heap buffer overflow in VobSub subtitle demuxer.
CVE-2026-73066 — tesseract: Tesseract: Heap out-of-bounds write via crafted .traineddata
CVE-2026-73072 — vim: Vim: Heap buffer overflow allows arbitrary code execution
CVE-2026-73076 — vim: Vim: Arbitrary command execution via crafted vimball
CVE-2026-73077 — vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling
CVE-2026-73078 — vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries
🎯 Affected products2
- Red Hat OpenShift AI 3.4
- registry.redhat.io/rhai/base-image-neuron-rhel9@sha256:fc44ace0f21e043cd2335b21ecfb934cceb4ee82f7fd6c5e07211a6bba71158c_amd64 as a component of Red Hat OpenShift AI 3.4
✅ Remediation
For more information visit https://access.redhat.com/errata/RHSA-2026:74674 Workaround: Do not process untrusted files with the xmllint program. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, avoid processing untrusted or maliciously crafted TIFF files with applications linked against the libtiff library. If processing untrusted TIFF files is unavoidable, consider running the affected applications within a sandboxed environment to limit the potential impact of successful exploitation. This operational control helps contain the effects of an out-of-bounds write, reducing the risk of denial of service or arbitrary code execution. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Only connect to trusted PostgreSQL servers. Avoid using psql or pg_dump against untrusted or potentially compromised database servers. Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: To mitigate this issue, users should avoid opening untrusted or suspicious PDF documents with applications that utilize the Poppler library for rendering. Limiting exposure to untrusted content can reduce the risk of exploitation. Workaround: To mitigate this issue, applications processing untrusted TIFF images should avoid explicitly configuring `PIXARLOGDATAFMT_8BITABGR` when decoding PixarLog-compressed TIFF images with three samples per pixel. This specific combination of output format and samples per pixel is required to trigger the heap-based buffer overflow. Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available. Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: To reduce exposure, avoid processing untrusted PNG image files with applications that utilize libpng. Restricting the source of PNG images to trusted origins can limit the attack surface. Workaround: To mitigate this issue, disable the modeline support by adding the following command to the Vim configuration file: ~~~ set nomodeline ~~~ Workaround: Avoid opening untrusted zip archives with Vim. This operational control prevents the necessary user interaction required to trigger the path traversal vulnerability in the `zip.vim` plugin. Workaround: To mitigate this issue, manually ensure that every buffer is NUL-terminated before passing it to the 'jv_parse_sized' function. Workaround: To mitigate this issue, ensure that the NegoEx mechanism is not registered in the `/etc/gss/mech` configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect. Workaround: To mitigate this vulnerability, users should avoid processing or opening OpenEXR image files from untrusted or unknown sources. Restricting the input of OpenEXR files to only trusted origins can reduce the risk of exploitation. Workaround: Mitigation for this issue involves exercising caution when opening or processing tag files from untrusted sources. Users should avoid loading tag files from unknown or suspicious origins to prevent the execution of arbitrary commands. Workaround: To mitigate this issue, avoid processing untrusted or unverified EXR image files. Users should exercise caution when opening EXR files from unknown or suspicious sources, as this vulnerability requires user interaction with a malicious file. Workaround: To mitigate this vulnerability, do not decompress untrusted .tgz archives with the Vimuntar command. Use 'tar -x -z -f' directly, instead. Workaround: To mitigate this issue, users should exercise caution when opening untrusted files or repositories with Vim, particularly those that might trigger the `cucumber` filetype plugin. Avoiding interaction with untrusted content can prevent the execution of malicious step-definition patterns. Workaround: Users can mitigate this vulnerability by disabling Python omni-completion in Vim if it is not essential for their workflow. This prevents the execution of untrusted Python code when opening hostile files. To disable this feature, ensure that the `omnifunc` option in your Vim configuration (e.g., `~/.vimrc`) is not set to `pythoncomplete#Complete` or `python3complete#Complete`. Alternatively, users should avoid invoking omni-completion (`Ctrl-X Ctrl-O`) on Python files from untrusted sources. Disabling Python omni-completion may affect Python development functionality within Vim. Workaround: Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory. Workaround: To mitigate this issue, administrators should ensure that the `pam_userdb` module is not configured to store or compare credentials in plaintext. Verify that `pam_userdb` is either configured with a strong cryptographic hashing method or, if not required, is disabled. Avoid using `crypt=none` or omitting the `crypt=` argument when configuring `pam_userdb`. If changes are made to PAM configuration files, services relying on PAM may need to be restarted for the changes to take effect. Workaround: No mitigation is available other than upgrading to Apache Thrift 0.24.0 or later, which contains the fix. AIPCC's PyArrow build pipeline is tracked separately for remediation under AIPCC-28667. Workaround: To mitigate this issue disable spell checking or avoid using SOFO-based spell files. This can be achieved globally by adding set nospell to your ~/.vimrc configuration file. Ensure your systems utilize standard UTF-8 encoding. This flaw is strictly confined to legacy 8-bit encodings and cannot be triggered under default Red Hat configurations. Workaround: To mitigate this vulnerability, users should avoid opening untrusted Python files or using Python omni-completion on such files. If Python omni-completion is not required, it can be disabled by adding `autocmd FileType python setlocal omnifunc=` to your `.vimrc` file. This will prevent the vulnerable code from being executed. Disabling Python omni-completion will remove the ability to use `Ctrl-X Ctrl-O` for Python code completion. A restart of Vim is required for the changes to take effect. Workaround: To mitigate this vulnerability, in applications processing user-supplied dates, implement input validation to ensure the supplied date is within the supported range before calling g_date_time_add_full() with untrusted data, specifically rejecting inputs that result in a n…
🔗 References (87)
- selfhttps://access.redhat.com/errata/RHSA-2026:74674
- externalhttps://access.redhat.com/security/cve/CVE-2023-52355
- externalhttps://access.redhat.com/security/cve/CVE-2024-34459
- externalhttps://access.redhat.com/security/cve/CVE-2025-10911
- externalhttps://access.redhat.com/security/cve/CVE-2025-14087
- externalhttps://access.redhat.com/security/cve/CVE-2025-14512
- externalhttps://access.redhat.com/security/cve/CVE-2025-6170
- externalhttps://access.redhat.com/security/cve/CVE-2026-10118
- externalhttps://access.redhat.com/security/cve/CVE-2026-11822
- externalhttps://access.redhat.com/security/cve/CVE-2026-11824
- externalhttps://access.redhat.com/security/cve/CVE-2026-11940
- externalhttps://access.redhat.com/security/cve/CVE-2026-12912
- externalhttps://access.redhat.com/security/cve/CVE-2026-14164
- externalhttps://access.redhat.com/security/cve/CVE-2026-15308
- externalhttps://access.redhat.com/security/cve/CVE-2026-15588
- externalhttps://access.redhat.com/security/cve/CVE-2026-16118
- externalhttps://access.redhat.com/security/cve/CVE-2026-26740
- externalhttps://access.redhat.com/security/cve/CVE-2026-29111
- externalhttps://access.redhat.com/security/cve/CVE-2026-31790
- externalhttps://access.redhat.com/security/cve/CVE-2026-33416
- externalhttps://access.redhat.com/security/cve/CVE-2026-33636
- externalhttps://access.redhat.com/security/cve/CVE-2026-33845
- externalhttps://access.redhat.com/security/cve/CVE-2026-33846
- externalhttps://access.redhat.com/security/cve/CVE-2026-34588
- externalhttps://access.redhat.com/security/cve/CVE-2026-34982
- externalhttps://access.redhat.com/security/cve/CVE-2026-35177
- externalhttps://access.redhat.com/security/cve/CVE-2026-35385
- externalhttps://access.redhat.com/security/cve/CVE-2026-35386
- externalhttps://access.redhat.com/security/cve/CVE-2026-35387
- externalhttps://access.redhat.com/security/cve/CVE-2026-35388
- externalhttps://access.redhat.com/security/cve/CVE-2026-35414
- externalhttps://access.redhat.com/security/cve/CVE-2026-3833
- externalhttps://access.redhat.com/security/cve/CVE-2026-39979
- externalhttps://access.redhat.com/security/cve/CVE-2026-40164
- externalhttps://access.redhat.com/security/cve/CVE-2026-40356
- externalhttps://access.redhat.com/security/cve/CVE-2026-41142
- externalhttps://access.redhat.com/security/cve/CVE-2026-41411
- externalhttps://access.redhat.com/security/cve/CVE-2026-41989
- externalhttps://access.redhat.com/security/cve/CVE-2026-42009
- externalhttps://access.redhat.com/security/cve/CVE-2026-42010
- externalhttps://access.redhat.com/security/cve/CVE-2026-42011
- externalhttps://access.redhat.com/security/cve/CVE-2026-42012
- externalhttps://access.redhat.com/security/cve/CVE-2026-42013
- externalhttps://access.redhat.com/security/cve/CVE-2026-42014
- externalhttps://access.redhat.com/security/cve/CVE-2026-42015
- externalhttps://access.redhat.com/security/cve/CVE-2026-42216
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-46483
- externalhttps://access.redhat.com/security/cve/CVE-2026-47162
- externalhttps://access.redhat.com/security/cve/CVE-2026-47167
- externalhttps://access.redhat.com/security/cve/CVE-2026-4775
- externalhttps://access.redhat.com/security/cve/CVE-2026-4786
- externalhttps://access.redhat.com/security/cve/CVE-2026-4878
- externalhttps://access.redhat.com/security/cve/CVE-2026-48864
- externalhttps://access.redhat.com/security/cve/CVE-2026-5260
- externalhttps://access.redhat.com/security/cve/CVE-2026-52858
- externalhttps://access.redhat.com/security/cve/CVE-2026-5419
- externalhttps://access.redhat.com/security/cve/CVE-2026-54369
- externalhttps://access.redhat.com/security/cve/CVE-2026-54411
- externalhttps://access.redhat.com/security/cve/CVE-2026-5450
- externalhttps://access.redhat.com/security/cve/CVE-2026-55693
- externalhttps://access.redhat.com/security/cve/CVE-2026-55971
- externalhttps://access.redhat.com/security/cve/CVE-2026-57455
- externalhttps://access.redhat.com/security/cve/CVE-2026-57456
- externalhttps://access.redhat.com/security/cve/CVE-2026-58010
- externalhttps://access.redhat.com/security/cve/CVE-2026-58011
- externalhttps://access.redhat.com/security/cve/CVE-2026-58012
- externalhttps://access.redhat.com/security/cve/CVE-2026-58013
- externalhttps://access.redhat.com/security/cve/CVE-2026-58014
- externalhttps://access.redhat.com/security/cve/CVE-2026-58015
- externalhttps://access.redhat.com/security/cve/CVE-2026-58016
- externalhttps://access.redhat.com/security/cve/CVE-2026-59856
- externalhttps://access.redhat.com/security/cve/CVE-2026-59858
- externalhttps://access.redhat.com/security/cve/CVE-2026-60002
- externalhttps://access.redhat.com/security/cve/CVE-2026-6100
- externalhttps://access.redhat.com/security/cve/CVE-2026-6477
- externalhttps://access.redhat.com/security/cve/CVE-2026-64830
- externalhttps://access.redhat.com/security/cve/CVE-2026-73066
- externalhttps://access.redhat.com/security/cve/CVE-2026-73072
- externalhttps://access.redhat.com/security/cve/CVE-2026-73076
- externalhttps://access.redhat.com/security/cve/CVE-2026-73077
- externalhttps://access.redhat.com/security/cve/CVE-2026-73078
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://www.redhat.com/en/products/ai
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74674.json