PatchSiren

Red Hat CVE debriefs · Page 11

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Red Hat CVE published 2026-07-16

CVE-2026-3842

A high-severity flaw was found in QEMU, denoted as CVE-2026-3842, which allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, pot [truncated]

HIGH Red Hat CVE published 2026-07-15

CVE-2026-12382

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary even [truncated]

HIGH Red Hat CVE published 2026-07-15

CVE-2026-15809

A flaw was found in CRI-O, where an incorrect fix for a previous vulnerability (CVE-2022-4318) allowed it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable, potentially adding arbitrary lines into /etc/passwd using a specially crafted environment variable.

HIGH Red Hat CVE published 2026-07-15

CVE-2026-14251

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service. This HIGH severity vulnerability has a CVSS score of 7.7 and can be mitiga [truncated]

HIGH Red Hat CVE published 2026-07-14

CVE-2026-15711

CVE-2026-15711 is a high-severity vulnerability in libsoup's WebSocket frame parsing implementation. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame, triggering an internal processing crash and resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets. The vulnerability is caused by libsoup's failure to validate leng [truncated]

HIGH Red Hat CVE published 2026-07-14

CVE-2026-15709

A flaw in libsoup's WebSocket implementation can cause a Denial of Service (DoS) via a decompression bomb. This issue is relevant to defenders of Red Hat Enterprise Linux 10 systems using libsoup. The CVE record was published on 2026-07-14T20:16:57.027Z and was last modified on 2026-09-17T19:16:40.420Z. The NVD entry is currently Deferred. The vulnerability has a high CVSS score of 7.5 and is classified a [truncated]

MEDIUM Red Hat CVE published 2026-07-14

CVE-2026-12478

CVE-2026-12478 is a medium-severity vulnerability in libsoup, a popular open-source HTTP client library. The fix for CVE-2026-0716 introduced an integer overflow guard, but it was placed inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup- [truncated]

HIGH Red Hat CVE published 2026-07-13

CVE-2026-15584

A high-severity privilege escalation vulnerability was found in OpenShift's incluster-checks tool. The tool creates privileged debug pods with host filesystem access in the shared default namespace. Any user with the standard edit role can exec into these pods and obtain root access on cluster nodes, potentially leading to a complete compromise of the cluster. The vulnerability has a CVSS score of 7.5 and [truncated]

MEDIUM Red Hat CVE published 2026-07-13

CVE-2026-62147

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of Tempo Operator should review their configurations to ensure proper namespace-s [truncated]

HIGH Red Hat CVE published 2026-07-13

CVE-2026-15574

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information dis [truncated]

CRITICAL Red Hat CVE published 2026-07-10

CVE-2026-15143

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access [truncated]

CRITICAL Red Hat CVE published 2026-07-10

CVE-2026-15378

A critical vulnerability was found in the `guardrails-detectors` component, allowing a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoin [truncated]

LOW Red Hat CVE published 2026-07-10

CVE-2026-15028

A flaw in libarchive allows remote attackers to trigger a heap overflow via a specially crafted tar archive, potentially leading to denial of service or arbitrary code execution. The issue arises during parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to system unavailability or attacker control. Defenders should assess exposur [truncated]

HIGH Red Hat CVE published 2026-07-09

CVE-2026-59692

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

HIGH Red Hat CVE published 2026-07-09

CVE-2026-59691

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) [truncated]

MEDIUM Red Hat CVE published 2026-07-08

CVE-2026-15154

A Regular Expression Denial of Service (ReDoS) vulnerability was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability allows a remote attacker to provide specially crafted regular expressions to the public detection API, causing catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guar [truncated]

MEDIUM Red Hat CVE published 2026-07-08

CVE-2026-15044

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T15:16:26.120Z and has not been modified since then. This vulnerability affects the TrustyAI Service Operator, specifically services like gorch or NemoGuardrails. When a specific security setting is not enabled, these services can expose their communication channels without requiring users to prov [truncated]

MEDIUM Red Hat CVE published 2026-07-07

CVE-2025-12799

A PatchSiren debrief of CVE-2025-12799 based on the supplied source corpus. The CVE record was published on 2026-07-07T17:16:34.640Z and has not been modified since then. Jastow is vulnerable to Cross-Site Scripting (XSS) attack if using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow. This could lead to improper input handling. Users of Jastow should [truncated]

MEDIUM Red Hat CVE published 2026-07-07

CVE-2026-14969

CVE-2026-14969 is a MEDIUM severity vulnerability in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations. This allows an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks. The vulnerability affects 389-ds-base deployments, and users should revi [truncated]

LOW Red Hat CVE published 2026-07-07

CVE-2026-14935

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. This vulnerability affects GStreamer deployments utilizing WebRTC functionality, particularly those prioritizing se [truncated]

MEDIUM Red Hat CVE published 2026-07-07

CVE-2026-14940

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An unauthenticated remote attacker can trigger this condition by sending an LDAP operation [truncated]

HIGH Red Hat CVE published 2026-07-07

CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authenticati [truncated]

HIGH Red Hat CVE published 2026-07-07

CVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts. This vulnerability has a high CVSS score of 8.8 and is considered a high p [truncated]

HIGH Red Hat CVE published 2026-07-07

CVE-2026-11610

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attack [truncated]

HIGH Red Hat CVE published 2026-07-07

CVE-2026-58384

CVE-2026-58384 is an integer overflow vulnerability in GIMP's PSD parser. The flaw can cause memory corruption, potentially leading to denial of service or code execution. This vulnerability affects users of GIMP, especially those processing PSD files from untrusted sources. The vulnerability has a high severity score of 7.3 and is classified as HIGH. There is currently no information on known ransomware [truncated]

MEDIUM Red Hat CVE published 2026-07-06

CVE-2026-59089

A flaw was found in GIMP. The PlayStation TIM loader incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short integers, resulting in a value exceeding the maximum integer limit. An attacker could exploit this by providing a specially crafted image file, leading to undefined behavior and c [truncated]

HIGH Red Hat CVE published 2026-07-06

CVE-2026-58380

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. The vulnerability affects users of GIMP [truncated]

HIGH Red Hat CVE published 2026-07-06

CVE-2026-9165

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane. This issue affects users of Red Hat Advanced Clu [truncated]

MEDIUM Red Hat CVE published 2026-07-05

CVE-2026-14781

A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the userinfo response but retrieves the email_verified status exclusively from the id_token.

HIGH Red Hat CVE published 2026-07-03

CVE-2026-58379

A high-severity vulnerability was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows remote attackers to cause arbitrary code execution or a denial of service (DoS) by tricking users into opening specially crafted PSP image files. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, lead [truncated]