Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2018-12015 — perl: Directory traversal in Archive::Tar CVE-2018-18311 — perl: Integer overflow leading to buffer overflow in Perl_my_setenv() CVE-2018-18312 — perl: Heap-based buffer overflow in S_handle_regex_sets() CVE-2018-18313 — perl: Heap-based buffer read overflow in S_grok_bslash_N() CVE-2018-18314 — perl: Heap-based buffer overflow in S_regatom() CVE-2020-10878 — perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS CVE-2020-12723 — perl: corruption of intermediate language state of compiled regular expression due to recursive S_study_chunk() calls leads to DoS CVE-2023-31484 — perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS CVE-2023-31486 — http-tiny: perl: insecure TLS cert default
🎯 Affected products5
- Red Hat Hardened Images
- perl-main@aarch64 as a component of Red Hat Hardened Images
- perl-main@noarch as a component of Red Hat Hardened Images
- perl-main@src as a component of Red Hat Hardened Images
- perl-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this flaw, developers should not allow untrusted regular expressions to be compiled by the Perl regular expression compiler.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:7604
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2023-31486
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2023-31484
- externalhttps://access.redhat.com/security/cve/CVE-2020-12723
- externalhttps://access.redhat.com/security/cve/CVE-2020-10878
- externalhttps://access.redhat.com/security/cve/CVE-2018-18314
- externalhttps://access.redhat.com/security/cve/CVE-2018-18313
- externalhttps://access.redhat.com/security/cve/CVE-2018-18312
- externalhttps://access.redhat.com/security/cve/CVE-2018-18311
- externalhttps://access.redhat.com/security/cve/CVE-2018-12015
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7604.json