Red Hat Security Advisory: Red Hat Cost Management On-Premise container image update
🔗 CVE IDs covered (55)
📋 Description
CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error
CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies
CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup
CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse
CVE-2026-13221 — perl: Perl: Incorrect regular expression processing via large regular expressions
CVE-2026-13732 — gdb: gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF
CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
CVE-2026-15028 — libarchive: heap overflow OOB read while parsing a tar archive contains a PAX extended header
CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet
CVE-2026-34743 — xz: XZ Utils: Denial of Service via buffer overflow in index decoding
CVE-2026-40467 — gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c
CVE-2026-40468 — gawk: gawk: Memory corruption via integer overflow
CVE-2026-40553 — gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service
CVE-2026-42533 — nginx: NGINX: Arbitrary code execution via crafted HTTP requests
CVE-2026-42784 — sequoia-openpgp: sequoia-openpgp: Cryptographic integrity compromise via key flag confusion
CVE-2026-50219 — expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
CVE-2026-53783 — rsync: rsync: Directory escape via TOCTOU race condition in rrsync
CVE-2026-53784 — rsync: rsync: Unauthorized File Access via Symlink Module Root
CVE-2026-53785 — rsync: rsync: Arbitrary file write via path traversal in --relative mode
CVE-2026-53789 — rsync: rsync: Arbitrary file deletion via malicious file list
CVE-2026-53790 — rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths
CVE-2026-53791 — rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
CVE-2026-53793 — rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
CVE-2026-53795 — rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options
CVE-2026-53802 — rsync: rsync: Arbitrary File Read via Symlink Following
CVE-2026-53803 — rsync: rsync: Local Privilege Escalation via Symlink Following
CVE-2026-56392 — coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping
CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg
CVE-2026-66046 — expat: Expat: Denial of Service via quadratic complexity in attribute processing
CVE-2026-70452 — rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2026-70453 — rsync: rsync: Denial of Service via Algorithmic Complexity
CVE-2026-70454 — rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions
CVE-2026-70455 — rsync: rsync: Denial of Service via Zstandard compression thread exhaustion
CVE-2026-70456 — rsync: rsync: Heap Out-of-Bounds Write via crafted argument list
CVE-2026-70457 — rsync: rsync: Memory corruption via out-of-bounds write in size parsing
CVE-2026-70458 — rsync: rsync: Memory corruption via crafted file entries
CVE-2026-70460 — rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
CVE-2026-70461 — rsync: rsync: Information disclosure and denial of service via crafted files-from entry
CVE-2026-70463 — rsync: rsync: Authorization bypass via auth users directive parsing
CVE-2026-70464 — rsync: rsync: Denial of Service via handshake stall
CVE-2026-74860 — libxml2: double-free/UAF in libxml2 Python bindings
CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding
CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization
CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
CVE-2026-86138 — libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
CVE-2026-86140 — libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements
CVE-2026-86142 — libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation
CVE-2026-86143 — libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
CVE-2026-86144 — libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.
CVE-2026-93749 — source-map-js: source-map-js: Denial of Service via malformed indexed source maps
CVE-2026-93990 — expat: Expat: XML Injection via Malformed UTF-16 Input
🎯 Affected products2
- Red Hat Cost Management On-Premise 1
- registry.redhat.io/costmanagement/costmanagement-ui-rhel10@sha256:39700faac93e613fdd8139aed7b6dbb79a4d542f3f3cca6be04c4edce72eaf5d_amd64 as a component of Red Hat Cost Management On-Premise 1
✅ Remediation
The container image provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not use trailing-dot hostnames in URLs passed to curl. Trailing dots are uncommon and incompatible with TLS SNI. Upgrade to curl 8.21.0 to resolve Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Correct usage of the library: Create a fresh handle for a different origin, or explicitly clear authentication-related state before reuse: ```c // req.A curl = curl_easy_init(); ... curl_easy_cleanup(curl); // req.B curl = curl_easy_init(); ... curl_easy_cleanup(curl); ``` Fixed in libcurl 8.21.0; affected range: 7.10.6 – 8.20.0 Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Do not open untrusted or unknown ELF binaries in GDB without first stripping debug sections. Use `objcopy --remove-section=.stab --remove-section=.stabstr <binary>` before debugging. - Use `readelf -S <binary> | grep stab` to check for the presence of STABS sections before opening a binary in GDB. Legitimate modern binaries use DWARF, not STABS. - Consider using LLDB or other debuggers that do not support STABS for analysis of untrusted binaries. - For automated environments (CI, test farms) that invoke GDB on potentially untrusted binaries, run GDB in a sandboxed or containerized environment with restricted filesystem access. - GDB 17+ deprecates STABS support but still parses it. GDB 18 (expected late 2026/2027) will remove STABS support entirely. - GCC removed STABS emitting in GCC 13 (2023), so legitimately compiled binaries from recent GCC versions will not contain STABS data. Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: To mitigate this issue, avoid processing untrusted or unverified tar archives. Users should exercise caution when handling archives from unknown sources or those with unexpected content, as processing a specially crafted archive could trigger the vulnerability. Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: To mitigate this issue, users should avoid processing untrusted or maliciously crafted input with `gawk`. Exercise caution when executing `gawk` scripts or commands that process data from unknown or unverified sources. Workaround: Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c. Workaround: Do not run gawk against untrusted scripts, files, or directories to prevent triggering these vulnerabilities. If an attack is attempted, Red Hat's built-in memory protections will safely crash the program, preventing malicious code execution. Workaround: To mitigate this vulnerability, do not use unnamed captures. Use named captures instead and only use them in the same block with the regex match. Red Hat recommends updating nginx to the latest version when a fix is available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Do not use the rrsync SSH forced-command wrapper until patched packages are applied. If restricted rsync over SSH is strictly required, grant access only to SSH identities that are fully trusted with the host account's entire filesystem privileges, as rrsync cannot safely enforce directory boundaries. Note that standard rsync daemon firewall controls (TCP 873) do not mitigate this flaw, as execution occurs entirely over SSH (TCP 22). Workaround: To mitigate this vulnerability, ensure that the `use chroot` option is enabled in the rsync daemon configuration. If `use chroot` cannot be enabled, avoid using symlinks as the module root path or any of its components in the rsync daemon configuration. After modifying the rsync configuration, restart the rsync service for the changes to take effect. Workaround: To mitigate this issue, avoid using the rsync --relative (-R) option when synchronizing with untrusted senders. Because kernel-level symlink protections cannot prevent rsync from following malicious destination-tree symlinks created by the same executing user, strict sender verification is required. Restricting --relative operations to fully trusted sources prevents attackers from exploiting implied relative paths to achieve path traversal. Workaround: To reduce the risk of arbitrary file deletion, ensure that rsync operations using the `--delete` option are only performed with trusted remote sources. If rsync is configured as a daemon (`rsyncd`), restrict network access to the rsync service (port 873/tcp) to only trusted clients using firewall rules. For example, using `firewall-cmd` on Red Hat Enterprise Linux: `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_ADDRESS>" port port="873" protocol="tcp" accept'` `firewall-cmd --reload` This may impact legitimate rsync operations from untrusted networks. A service reload or restart may be required for changes to take effect. Workaround: Do not set RSYNC_CONNECT_PROG or pass untrusted hostnames/paths into rsync / rsync-ssl. If rsyncd is required, omit pre-xfer/post-xfer/early exec unless the command ignores client-controlled RSYNC_* values, and restrict TCP/873 to trusted clients Workaround: Restrict rsync daemon TCP/873 to the trusted proxy only (CME-202). If PROXY protocol is unused, leave proxy protocol disabled (the default). Workaround: To mitigate this issue, avoid configuring rsync modules with a /./ boundary marker in their root path when operating in chroot mode. Review existing rsync configurations to ensure that module root paths do not contain /./ when chroot is enabled. If chroot mode is not strictly required for a given rsync module, consider disabling it. If changes are made to the rsync configuration, a restart of the rsync service may be required for the changes to take effect. Workaround: Do not pass untrusted values into --temp…
🔗 References (61)
- selfhttps://access.redhat.com/errata/RHSA-2026:79357
- externalhttps://access.redhat.com/articles/7148128
- externalhttps://access.redhat.com/security/cve/CVE-2026-11856
- externalhttps://access.redhat.com/security/cve/CVE-2026-13221
- externalhttps://access.redhat.com/security/cve/CVE-2026-13732
- externalhttps://access.redhat.com/security/cve/CVE-2026-14456
- externalhttps://access.redhat.com/security/cve/CVE-2026-15028
- externalhttps://access.redhat.com/security/cve/CVE-2026-16118
- externalhttps://access.redhat.com/security/cve/CVE-2026-18798
- externalhttps://access.redhat.com/security/cve/CVE-2026-34743
- externalhttps://access.redhat.com/security/cve/CVE-2026-40467
- externalhttps://access.redhat.com/security/cve/CVE-2026-40468
- externalhttps://access.redhat.com/security/cve/CVE-2026-40553
- externalhttps://access.redhat.com/security/cve/CVE-2026-42533
- externalhttps://access.redhat.com/security/cve/CVE-2026-42784
- externalhttps://access.redhat.com/security/cve/CVE-2026-50219
- externalhttps://access.redhat.com/security/cve/CVE-2026-53783
- externalhttps://access.redhat.com/security/cve/CVE-2026-53784
- externalhttps://access.redhat.com/security/cve/CVE-2026-53785
- externalhttps://access.redhat.com/security/cve/CVE-2026-53789
- externalhttps://access.redhat.com/security/cve/CVE-2026-53790
- externalhttps://access.redhat.com/security/cve/CVE-2026-53791
- externalhttps://access.redhat.com/security/cve/CVE-2026-53793
- externalhttps://access.redhat.com/security/cve/CVE-2026-53795
- externalhttps://access.redhat.com/security/cve/CVE-2026-53802
- externalhttps://access.redhat.com/security/cve/CVE-2026-53803
- externalhttps://access.redhat.com/security/cve/CVE-2026-56392
- externalhttps://access.redhat.com/security/cve/CVE-2026-63072
- externalhttps://access.redhat.com/security/cve/CVE-2026-63076
- externalhttps://access.redhat.com/security/cve/CVE-2026-66046
- externalhttps://access.redhat.com/security/cve/CVE-2026-70452
- externalhttps://access.redhat.com/security/cve/CVE-2026-70453
- externalhttps://access.redhat.com/security/cve/CVE-2026-70454
- externalhttps://access.redhat.com/security/cve/CVE-2026-70455
- externalhttps://access.redhat.com/security/cve/CVE-2026-70456
- externalhttps://access.redhat.com/security/cve/CVE-2026-70457
- externalhttps://access.redhat.com/security/cve/CVE-2026-70458
- externalhttps://access.redhat.com/security/cve/CVE-2026-70460
- externalhttps://access.redhat.com/security/cve/CVE-2026-70461
- externalhttps://access.redhat.com/security/cve/CVE-2026-70463
- externalhttps://access.redhat.com/security/cve/CVE-2026-70464
- externalhttps://access.redhat.com/security/cve/CVE-2026-74860
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-8458
- externalhttps://access.redhat.com/security/cve/CVE-2026-86138
- externalhttps://access.redhat.com/security/cve/CVE-2026-86140
- externalhttps://access.redhat.com/security/cve/CVE-2026-86142
- externalhttps://access.redhat.com/security/cve/CVE-2026-86143
- externalhttps://access.redhat.com/security/cve/CVE-2026-86144
- externalhttps://access.redhat.com/security/cve/CVE-2026-8924
- externalhttps://access.redhat.com/security/cve/CVE-2026-8926
- externalhttps://access.redhat.com/security/cve/CVE-2026-8932
- externalhttps://access.redhat.com/security/cve/CVE-2026-9079
- externalhttps://access.redhat.com/security/cve/CVE-2026-93749
- externalhttps://access.redhat.com/security/cve/CVE-2026-93990
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/cost_management_service/1-latest/html/getting_started_with_cost_management/steps-to-cost-management
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_79357.json