RHSA-2026:79357HighCVSS 8.5

Red Hat Security Advisory: Red Hat Cost Management On-Premise container image update

Published
October 8, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (55)

📋 Description

CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse CVE-2026-13221 — perl: Perl: Incorrect regular expression processing via large regular expressions CVE-2026-13732 — gdb: gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server CVE-2026-15028 — libarchive: heap overflow OOB read while parsing a tar archive contains a PAX extended header CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-34743 — xz: XZ Utils: Denial of Service via buffer overflow in index decoding CVE-2026-40467 — gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c CVE-2026-40468 — gawk: gawk: Memory corruption via integer overflow CVE-2026-40553 — gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service CVE-2026-42533 — nginx: NGINX: Arbitrary code execution via crafted HTTP requests CVE-2026-42784 — sequoia-openpgp: sequoia-openpgp: Cryptographic integrity compromise via key flag confusion CVE-2026-50219 — expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking CVE-2026-53783 — rsync: rsync: Directory escape via TOCTOU race condition in rrsync CVE-2026-53784 — rsync: rsync: Unauthorized File Access via Symlink Module Root CVE-2026-53785 — rsync: rsync: Arbitrary file write via path traversal in --relative mode CVE-2026-53789 — rsync: rsync: Arbitrary file deletion via malicious file list CVE-2026-53790 — rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths CVE-2026-53791 — rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header CVE-2026-53793 — rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode CVE-2026-53795 — rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options CVE-2026-53802 — rsync: rsync: Arbitrary File Read via Symlink Following CVE-2026-53803 — rsync: rsync: Local Privilege Escalation via Symlink Following CVE-2026-56392 — coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg CVE-2026-66046 — expat: Expat: Denial of Service via quadratic complexity in attribute processing CVE-2026-70452 — rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure CVE-2026-70453 — rsync: rsync: Denial of Service via Algorithmic Complexity CVE-2026-70454 — rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions CVE-2026-70455 — rsync: rsync: Denial of Service via Zstandard compression thread exhaustion CVE-2026-70456 — rsync: rsync: Heap Out-of-Bounds Write via crafted argument list CVE-2026-70457 — rsync: rsync: Memory corruption via out-of-bounds write in size parsing CVE-2026-70458 — rsync: rsync: Memory corruption via crafted file entries CVE-2026-70460 — rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink CVE-2026-70461 — rsync: rsync: Information disclosure and denial of service via crafted files-from entry CVE-2026-70463 — rsync: rsync: Authorization bypass via auth users directive parsing CVE-2026-70464 — rsync: rsync: Denial of Service via handshake stall CVE-2026-74860 — libxml2: double-free/UAF in libxml2 Python bindings CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-86138 — libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow CVE-2026-86140 — libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements CVE-2026-86142 — libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation CVE-2026-86143 — libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks CVE-2026-86144 — libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. CVE-2026-93749 — source-map-js: source-map-js: Denial of Service via malformed indexed source maps CVE-2026-93990 — expat: Expat: XML Injection via Malformed UTF-16 Input

🎯 Affected products2

  • Red Hat Cost Management On-Premise 1
  • registry.redhat.io/costmanagement/costmanagement-ui-rhel10@sha256:39700faac93e613fdd8139aed7b6dbb79a4d542f3f3cca6be04c4edce72eaf5d_amd64 as a component of Red Hat Cost Management On-Premise 1

✅ Remediation

The container image provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not use trailing-dot hostnames in URLs passed to curl. Trailing dots are uncommon and incompatible with TLS SNI. Upgrade to curl 8.21.0 to resolve Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Correct usage of the library: Create a fresh handle for a different origin, or explicitly clear authentication-related state before reuse: ```c // req.A curl = curl_easy_init(); ... curl_easy_cleanup(curl); // req.B curl = curl_easy_init(); ... curl_easy_cleanup(curl); ``` Fixed in libcurl 8.21.0; affected range: 7.10.6 – 8.20.0 Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Do not open untrusted or unknown ELF binaries in GDB without first stripping debug sections. Use `objcopy --remove-section=.stab --remove-section=.stabstr <binary>` before debugging. - Use `readelf -S <binary> | grep stab` to check for the presence of STABS sections before opening a binary in GDB. Legitimate modern binaries use DWARF, not STABS. - Consider using LLDB or other debuggers that do not support STABS for analysis of untrusted binaries. - For automated environments (CI, test farms) that invoke GDB on potentially untrusted binaries, run GDB in a sandboxed or containerized environment with restricted filesystem access. - GDB 17+ deprecates STABS support but still parses it. GDB 18 (expected late 2026/2027) will remove STABS support entirely. - GCC removed STABS emitting in GCC 13 (2023), so legitimately compiled binaries from recent GCC versions will not contain STABS data. Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: To mitigate this issue, avoid processing untrusted or unverified tar archives. Users should exercise caution when handling archives from unknown sources or those with unexpected content, as processing a specially crafted archive could trigger the vulnerability. Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: To mitigate this issue, users should avoid processing untrusted or maliciously crafted input with `gawk`. Exercise caution when executing `gawk` scripts or commands that process data from unknown or unverified sources. Workaround: Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c. Workaround: Do not run gawk against untrusted scripts, files, or directories to prevent triggering these vulnerabilities. If an attack is attempted, Red Hat's built-in memory protections will safely crash the program, preventing malicious code execution. Workaround: To mitigate this vulnerability, do not use unnamed captures. Use named captures instead and only use them in the same block with the regex match. Red Hat recommends updating nginx to the latest version when a fix is available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Do not use the rrsync SSH forced-command wrapper until patched packages are applied. If restricted rsync over SSH is strictly required, grant access only to SSH identities that are fully trusted with the host account's entire filesystem privileges, as rrsync cannot safely enforce directory boundaries. Note that standard rsync daemon firewall controls (TCP 873) do not mitigate this flaw, as execution occurs entirely over SSH (TCP 22). Workaround: To mitigate this vulnerability, ensure that the `use chroot` option is enabled in the rsync daemon configuration. If `use chroot` cannot be enabled, avoid using symlinks as the module root path or any of its components in the rsync daemon configuration. After modifying the rsync configuration, restart the rsync service for the changes to take effect. Workaround: To mitigate this issue, avoid using the rsync --relative (-R) option when synchronizing with untrusted senders. Because kernel-level symlink protections cannot prevent rsync from following malicious destination-tree symlinks created by the same executing user, strict sender verification is required. Restricting --relative operations to fully trusted sources prevents attackers from exploiting implied relative paths to achieve path traversal. Workaround: To reduce the risk of arbitrary file deletion, ensure that rsync operations using the `--delete` option are only performed with trusted remote sources. If rsync is configured as a daemon (`rsyncd`), restrict network access to the rsync service (port 873/tcp) to only trusted clients using firewall rules. For example, using `firewall-cmd` on Red Hat Enterprise Linux: `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_ADDRESS>" port port="873" protocol="tcp" accept'` `firewall-cmd --reload` This may impact legitimate rsync operations from untrusted networks. A service reload or restart may be required for changes to take effect. Workaround: Do not set RSYNC_CONNECT_PROG or pass untrusted hostnames/paths into rsync / rsync-ssl. If rsyncd is required, omit pre-xfer/post-xfer/early exec unless the command ignores client-controlled RSYNC_* values, and restrict TCP/873 to trusted clients Workaround: Restrict rsync daemon TCP/873 to the trusted proxy only (CME-202). If PROXY protocol is unused, leave proxy protocol disabled (the default). Workaround: To mitigate this issue, avoid configuring rsync modules with a /./ boundary marker in their root path when operating in chroot mode. Review existing rsync configurations to ensure that module root paths do not contain /./ when chroot is enabled. If chroot mode is not strictly required for a given rsync module, consider disabling it. If changes are made to the rsync configuration, a restart of the rsync service may be required for the changes to take effect. Workaround: Do not pass untrusted values into --temp…

🔗 References (61)