PatchSiren

Red Hat CVE debriefs · Page 13

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Red Hat CVE published 2026-06-23

CVE-2026-12892

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker co [truncated]

MEDIUM Red Hat CVE published 2026-06-23

CVE-2026-12891

The GStreamer gst-plugins-bad package has a flaw that allows an attacker to craft a malicious H.266 video file or stream. When processed by a GStreamer-based application, it could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space. The flaw is caused by an out-of-bounds read of up to 8 bytes from adjacent memory when process [truncated]

HIGH Red Hat CVE published 2026-06-23

CVE-2026-12112

A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code e [truncated]

MEDIUM Red Hat CVE published 2026-06-23

CVE-2026-11820

The community.general Ansible collection's nexmo module has a flaw that causes API credentials to be sent via GET requests, exposing them in web server access logs, proxy logs, HTTP Referer headers, and network monitoring tools. Despite being marked as no_log in the Ansible argument specification, the credentials are visible. An attacker with access to these logs or monitoring points can obtain the full A [truncated]

CRITICAL Red Hat CVE published 2026-06-23

CVE-2026-11807

CVE-2026-11807 is a critical missing authorization vulnerability in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint fails to verify user permissions when processing Worker messages, allowing any authenticated user to send forged messages with arbitrary activation_id to receive plaintext credentials. These credentials include OAuth tokens, vault passwords, and SSH ke [truncated]

MEDIUM Red Hat CVE published 2026-06-23

CVE-2026-12969

CVE-2026-12969 is an out-of-bounds read vulnerability in dnsmasq's find_soa() function in src/rfc1035.c. The vulnerability occurs when parsing NS section records, where extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte [truncated]

MEDIUM Red Hat CVE published 2026-06-23

CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials. This allows a delegated editor to exfiltrate SA tokens and escalate privileges. The vulnerability has a CVSS score of 6.8 and is classified as medium s [truncated]

LOW Red Hat CVE published 2026-06-23

CVE-2026-55654

A heap out-of-bounds read vulnerability in OpenSSH can cause a denial of service (DoS) impacting SSH service availability under specific configurations involving GSSAPI authentication and a Kerberos environment. This vulnerability occurs during the cleanup of GSSAPI indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker could exploit this to cause the SSH au [truncated]

MEDIUM Red Hat CVE published 2026-06-23

CVE-2026-55653

CVE-2026-55653 is a medium-severity vulnerability in OpenSSH, allowing a malicious SSH server to exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Se [truncated]

MEDIUM Red Hat CVE published 2026-06-22

CVE-2026-12549

CVE-2026-12549 is a vulnerability caused by a regression in the fix for CVE-2026-2443. A subsequent rework commit replaced specific overflow checks with a general signed comparison, leading to improper clamping of negative start values when a client sends a Range request with a suffix length exceeding the content size. This results in malformed HTTP 206 responses and log flooding. The vulnerability has a [truncated]

HIGH Red Hat CVE published 2026-06-22

CVE-2026-54100

A flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform allows an adjacent-network attacker to capture credentials and compromise Windows node identities by intercepting or redirecting WMCO's SSH session. This vulnerability enables attackers to gain unauthorized access to Windows nodes in the cluster, potentially leading to lateral movement and further exploitation. D [truncated]

HIGH Red Hat CVE published 2026-06-22

CVE-2026-54099

A flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform allows a compromised Windows worker node to potentially gain cluster-administrator privileges by exploiting the WICD CSR auto-approver's validation weakness, which could lead to unauthorized access and control of the cluster. Defenders responsible for securing Red Hat OpenShift Container Platform 4 environments, [truncated]

HIGH Red Hat CVE published 2026-06-19

CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacke [truncated]

MEDIUM Red Hat CVE published 2026-06-19

CVE-2026-3196

CVE-2026-3196 is an integer overflow vulnerability in the virtio-snd device. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. The vulnerability was published on June 19, 2026, and no modifications have been made since then.

MEDIUM Red Hat CVE published 2026-06-18

CVE-2026-11791

CVE-2026-11791 is a medium-severity vulnerability in 389 Directory Server that can cause a denial of service (server crash) during schema reload with concurrent LDAP query traffic. The flaw occurs in the attr_syntax_swap_ht() function, which unconditionally frees attribute syntax information nodes, bypassing refcount-based deferred deletion. This can lead to use-after-free or double-free crashes. Administ [truncated]

HIGH Red Hat CVE published 2026-06-18

CVE-2026-12505

A high-severity vulnerability, CVE-2026-12505, was found in the cifs-utils package. The cifs.upcall helper fails to securely drop its root privileges before looking up user information in a user-controlled environment. This allows a local, low-privileged attacker to exploit the vulnerability using a crafted request_key payload, tricking the root-owned helper into entering a custom environment with a malic [truncated]

MEDIUM Red Hat CVE published 2026-06-17

CVE-2026-12515

CVE-2026-12515 is a medium-severity vulnerability in Red Hat Satellite's Katello component. It stems from insufficient authorization checks in the ContentUploadsController, allowing users with edit_products permission to query content information for repositories they shouldn't access. This issue, published on 2026-06-17, was modified on 2026-06-18. Exploitation requires authentication but doesn't permit [truncated]

MEDIUM Red Hat CVE published 2026-06-17

CVE-2026-12528

CVE-2026-12528 is a MEDIUM severity vulnerability in the 389 Directory Server, specifically in the __aclp__normalize_acltxt() function. An authenticated user with write access to the aci attribute can send a crafted ACI value, triggering a heap-buffer-overflow write and subsequent out-of-bounds reads. This flaw can silently corrupt heap memory in the directory server process. The CVSS score for this vulne [truncated]

MEDIUM Red Hat CVE published 2026-06-17

CVE-2026-12491

The CVE-2026-12491 vulnerability in vLLM, an open-source library for large language model inference, arises from improper handling of image metadata. Specifically, EXIF orientation and PNG transparency (tRNS) data are not correctly processed when images are converted to RGB. This can lead to unexpected rendering of transparent pixels and distortion of input content, potentially affecting the integrity of [truncated]

MEDIUM Red Hat CVE published 2026-06-16

CVE-2026-4367

CVE-2026-4367 is a MEDIUM-severity vulnerability in libXpm, a library for handling X PixMap (XPM) images. The vulnerability, with a CVSS score of 5.5, allows a local user with low privileges to exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function. This can be done by processing a specially crafted or very small XPM image file, which can cause an internal pointer to read beyond the f [truncated]

HIGH Red Hat CVE published 2026-06-16

CVE-2026-10649

CVE-2026-10649 is a high-severity vulnerability in Pacemaker, a software for managing cluster resources. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote l [truncated]

HIGH Red Hat CVE published 2026-06-16

CVE-2026-12398

CVE-2026-12398 is a HIGH severity vulnerability with a CVSS score of 7.5. A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with s [truncated]

MEDIUM Red Hat CVE published 2026-06-16

CVE-2026-42014

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

MEDIUM Red Hat CVE published 2026-06-16

CVE-2026-1767

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causin [truncated]

MEDIUM Red Hat CVE published 2026-06-16

CVE-2026-1766

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an ap [truncated]

MEDIUM Red Hat CVE published 2026-06-16

CVE-2026-1765

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from [truncated]

MEDIUM Red Hat CVE published 2026-06-16

CVE-2026-1764

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also [truncated]

HIGH Red Hat CVE published 2026-06-15

CVE-2026-53705

CVE-2026-53705 is a high-severity vulnerability in GStreamer's WavPack audio decoder. The flaw occurs when processing specially crafted WavPack files, leading to an integer overflow in buffer size calculation. This causes a small heap allocation, allowing the WavPack library to write decoded audio samples beyond the allocated buffer, resulting in heap memory corruption. The vulnerability affects both 32-b [truncated]

HIGH Red Hat CVE published 2026-06-15

CVE-2026-53704

A flaw in GStreamer's RealMedia demuxer can cause an application to crash, hang, or potentially read limited adjacent memory contents when processing a specially crafted RealMedia file. This vulnerability affects systems handling RealMedia files, particularly those using GStreamer's RealMedia demuxer, and may lead to application crashes, hangs, or memory exposure. Defenders should assess exposure and prio [truncated]

HIGH Red Hat CVE published 2026-06-15

CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first chec [truncated]