These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A flaw in libssh can cause clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. This issue affects multiple Red Hat Enterprise Linux versions and has a CVSS score of 3.1. The CVE was published on 2026-07-21T15:16:37.647Z and last modified on 2026-09-22T19:48:05.513Z.
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. This issue affects libssh clients and could lead to a denial-of-service condition. Users should review their libssh client deployments and consider mitigation strategies. The vulnerability is related [truncated]
A flaw was found in libssh, specifically in the incorrect AES-GCM finalization checks when using the OpenSSL backend. This vulnerability can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. The affected product is libssh with OpenSSL backend. The vulnerability class is related to cryptographic weaknesses. The likely operational impact [truncated]
A flaw in libssh allows malicious usernames to inject shell metacharacters through %r in ProxyCommand handling, exposing environment variables and causing unintended shell behavior. This issue affects users of libssh who should review and apply patches to mitigate potential risks. The vulnerability has a CVSS score of 3.9 and is considered LOW severity. Users of libssh, operators, platform administrators, [truncated]
A flaw was found in dracut, a tool for creating initramfs images. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without prop [truncated]
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability exists in libssh when the ProxyCommand feature is used. An unchecked for [truncated]
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. This issue affects libssh SFTP servers, potentially impacting confidentiality and availability. Users should review vendor guidance for affected versions and apply patches [truncated]
CVE-2026-59843 is a denial of service vulnerability in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU. This vulnerability has a CVSS score of 6.5 and a severity rating of MEDIUM. The vulnerability exists because libssh does not properly handle the maximum packet size advertisement in SS [truncated]
A flaw in libssh allows a remote unauthenticated attacker to disclose small amounts of server memory during server-side GSSAPI key exchange. The vulnerability is caused by improper length validation of a client-supplied Curve25519 public key, leading to an out-of-bounds heap read. This issue affects Red Hat Enterprise Linux 10 systems using libssh. Defenders should assess exposure and prioritize patching. [truncated]
CVE-2026-16461 is a stack-based buffer overflow in rpcbind's rpcinfo utility. The vulnerability occurs in rpcbdump() short mode, used by `rpcinfo -s`, where version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. This could lead to a crash or denial of service of the rpcinfo client when a user or administrator runs `rpcinfo -s` against a malici [truncated]
A flaw in libssh's SFTP server directory listing allows for stack buffer overflows when handling long filenames, potentially leading to server crashes or code execution. This vulnerability, CVE-2026-15370, affects libssh and can be exploited by clients requesting directory listings with sufficiently long filenames, causing a buffer overflow. The vulnerability has a medium severity and defenders should ass [truncated]
A flaw in Red Hat Quay's repository-level mirror configuration feature allows repository administrators to supply crafted hostnames, potentially causing the Quay mirror worker to make unintended requests to internal network services or cloud metadata endpoints via Skopeo. This could lead to unauthorized access or exposure of sensitive information. Defenders should prioritize verifying and restricting acce [truncated]
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can [truncated]
A vulnerability was found in kronosnet's cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this f [truncated]
The CVE-2026-64612 record describes a flaw in libcupsfilters and cups-filters that causes the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. Organizations should review their exposure and plan for patching. The CVE record was pub [truncated]
CVE-2026-16277 is a stack-based buffer overflow vulnerability in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat [truncated]
A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned fi [truncated]
A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service. This issue affects users of ClairCore, particularly those relying on it for vulnerability scanning in container layers. The vulnerability has [truncated]
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of sy [truncated]
A critical vulnerability was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert and without token-based agent authentication, allowing client certificates to not be validated. This flaw enables a remote attacker who can reach the Konnectivity cluster endpoint to connect as an unauthenticated agent, join the routin [truncated]
A flaw in xdgmime can cause a heap-based buffer overflow when parsing a malicious MIME magic file, potentially leading to application crashes or memory corruption on little-endian systems. This vulnerability is particularly concerning for defenders and administrators of systems using xdgmime, especially those with user-writable XDG data locations. The vulnerability can be triggered by an attacker-controll [truncated]
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and admini [truncated]
A flaw in the authentication configuration endpoint of Red Hat Build of Keycloak can expose sensitive configuration values, such as reCAPTCHA secret keys, to administrators with view-only permissions. This issue arises from the system's failure to mask these sensitive values when requested by administrators with view-only permissions, potentially leading to the exposure of third-party service credentials [truncated]
CVE-2026-16103 is a medium-severity vulnerability in Keycloak's keycloak-services component. It's an incomplete fix for CVE-2026-9798, allowing attackers with valid client credentials to obtain access and refresh tokens for a user account locked due to brute-force protection if the authentication request was started before the lockout and approved by the user. This issue affects users of Keycloak, especia [truncated]
A flaw in Keycloak's Client Policies allows an attacker with valid client credentials to bypass security requirements, including the use of signed JWTs for authentication, and authenticate using simpler methods. This vulnerability can lead to potential authentication bypass and exposure of sensitive information. Defenders should verify client configurations, review authentication methods, and ensure the u [truncated]
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity. This vulnerability has si [truncated]
A flaw in Keycloak's organization management allows delegated administrators to create user accounts without required permissions by exploiting an invitation link for a non-existent email address. This vulnerability enables administrators to bypass security boundaries and add unauthorized members to an organization, potentially leading to privilege escalation. Keycloak administrators should assess exposur [truncated]
A flaw was found in the Keycloak keycloak-services component, which handles identity provider management. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect a [truncated]
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. This vulnerability leads to the disclosure of sensitive group attributes and configuration. The issue arises when a delegated administrator sea [truncated]
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system. The vulner [truncated]