RHSA-2026:7604HighCVSS 8.6

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 10, 2026
Last Modified
August 18, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2018-12015 — perl: Directory traversal in Archive::Tar CVE-2018-18311 — perl: Integer overflow leading to buffer overflow in Perl_my_setenv() CVE-2018-18312 — perl: Heap-based buffer overflow in S_handle_regex_sets() CVE-2018-18313 — perl: Heap-based buffer read overflow in S_grok_bslash_N() CVE-2018-18314 — perl: Heap-based buffer overflow in S_regatom() CVE-2020-10878 — perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS CVE-2020-12723 — perl: corruption of intermediate language state of compiled regular expression due to recursive S_study_chunk() calls leads to DoS CVE-2023-31484 — perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS CVE-2023-31486 — http-tiny: perl: insecure TLS cert default

🎯 Affected products5

  • Red Hat Hardened Images
  • perl-main@aarch64 as a component of Red Hat Hardened Images
  • perl-main@noarch as a component of Red Hat Hardened Images
  • perl-main@src as a component of Red Hat Hardened Images
  • perl-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this flaw, developers should not allow untrusted regular expressions to be compiled by the Perl regular expression compiler.

🔗 References (13)