PatchSiren

Red Hat CVE debriefs · Page 15

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Red Hat CVE published 2026-06-09

CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

LOW Red Hat CVE published 2026-06-09

CVE-2026-11786

CVE-2026-11786 is a low-severity vulnerability affecting 389 Directory Server. The issue arises from the LDIF parser reading past the end of a heap buffer when processing attribute types with trailing semicolons during database import, leading to an out-of-bounds read. This vulnerability is detectable under memory instrumentation.

MEDIUM Red Hat CVE published 2026-06-09

CVE-2026-11785

CVE-2026-11785 is a medium-severity vulnerability in Red Hat Directory Server. A type confusion in the SSO token extended operation handler discloses partial stack address information in LDAP responses to authenticated users. The vulnerability has a CVSS score of 4.3 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11785).

MEDIUM Red Hat CVE published 2026-06-09

CVE-2026-52902

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using 'awx --conf.format yaml import'. This is a client-side vulnerability requiring user interaction.

MEDIUM Red Hat CVE published 2026-06-08

CVE-2026-11611

CVE-2026-11611 is a medium-severity vulnerability in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or shutdown.

HIGH Red Hat CVE published 2026-06-08

CVE-2026-11577

A flaw was found in Keycloak, which allows a limited administrator to exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This enables them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm administrator by importing users with realm-admin role mappings.

MEDIUM Red Hat CVE published 2026-06-08

CVE-2026-11569

CVE-2026-11569 is a MEDIUM severity vulnerability in Quay's filedrop endpoint. The endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when a victim visits the archive URL. The CVSS score for this vulnera [truncated]

HIGH Red Hat CVE published 2026-06-08

CVE-2026-3238

CVE-2026-3238 is a HIGH severity vulnerability in Samba's WINS server component. An unauthenticated remote attacker can trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets. The vulnerability has a CVSS score of 7.5 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-3238).

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50264

CVE-2026-50264 is a HIGH severity vulnerability with a CVSS score of 7.8. An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

MEDIUM Red Hat CVE published 2026-06-05

CVE-2026-50263

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM.

MEDIUM Red Hat CVE published 2026-06-05

CVE-2026-50262

CVE-2026-50262 is a medium-severity vulnerability in the X.Org X server and Xwayland. An out-of-bounds read flaw was found in __glXDisp_ChangeDrawableAttributes, allowing a client-controlled number of bytes to be read, exceeding the request buffer, and leading to information disclosure. A write path also exists but requires byte-swapped clients, which is disabled by default. The vulnerability has a CVSS s [truncated]

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50261

CVE-2026-50261 is a HIGH severity vulnerability in X.Org X server and Xwayland. A use-after-free flaw was found in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50260

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50259

CVE-2026-50259 is a HIGH severity vulnerability in X.Org X server and Xwayland. A stack-based buffer overflow flaw was found in _XkbSetMapChecks(), which declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege [truncated]

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50258

CVE-2026-50258 is a HIGH severity vulnerability in X.Org X server and Xwayland, with a CVSS score of 7.8. A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift l [truncated]

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50257

CVE-2026-50257 is a HIGH severity vulnerability in X.Org X server and Xwayland. A use-after-free flaw was found in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used [truncated]

HIGH Red Hat CVE published 2026-06-05

CVE-2026-50256

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that [truncated]

LOW Red Hat CVE published 2026-06-05

CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

HIGH Red Hat CVE published 2026-06-04

CVE-2026-10843

CVE-2026-10843 is a HIGH severity vulnerability with a CVSS score of 7.2. The flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise. The CVE was published on [cvePublishedAt] [truncated]

HIGH Red Hat CVE published 2026-06-04

CVE-2026-10840

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other t [truncated]

HIGH Red Hat CVE published 2026-06-01

CVE-2026-10118

A high-severity integer overflow vulnerability in Poppler's Splash backend allows remote attackers to achieve arbitrary code execution, information disclosure, or denial of service through maliciously crafted PDF files. The flaw resides in the `tilingPatternFill` function, where an integer overflow during rendering leads to an undersized heap allocation and subsequent out-of-bounds write. The vulnerabilit [truncated]

MEDIUM Red Hat CVE published 2026-06-01

CVE-2026-10533

A flaw in OpenShift Container Platform allows non-privileged users to degrade cluster-wide API server performance by exploiting a gap between pod lifecycle behavior and ResourceQuota enforcement. Completed pods configured with restartPolicy: Never are not counted toward ResourceQuota pod limits, and Kubernetes events are not subject to quota scoping. A user with pod creation permissions in a namespace can [truncated]

MEDIUM Red Hat CVE published 2026-06-01

CVE-2026-10517

A Server-Side Request Forgery (SSRF) vulnerability exists in Clair's fetcher component. The flaw allows unauthenticated attackers to induce outbound HTTP requests to attacker-supplied URIs derived from manifest layer descriptors, without IP address or URI scheme filtering. When Pre-Shared Key (PSK) authentication is not configured—a state that is opt-in and not enforced by default—an attacker can submit a [truncated]

MEDIUM Red Hat CVE published 2026-05-29

CVE-2026-10101

A vulnerability in the ACM/MCE assisted-service component allows unauthorized disclosure of pull-secret credentials through Kubernetes Custom Resource status fields. When pull-secret validation fails, the service writes the raw referenced Secret contents—including `.dockerconfigjson` data containing registry authentication credentials—into the `InfraEnv.status.conditions[].message` field. This creates an [truncated]

MEDIUM Red Hat CVE published 2026-05-29

CVE-2026-10052

A medium-severity vulnerability in Quay's config-tool allows authenticated attackers with config editor privileges to conduct internal network reconnaissance. The LDAP and SMTP validation functions make outbound connections to attacker-supplied endpoints without adequate IP or host filtering, enabling Server-Side Request Forgery (SSRF) from the Quay pod's network position. This flaw was disclosed on 2026- [truncated]

MEDIUM Red Hat CVE published 2026-05-28

CVE-2026-10028

A vulnerability in glib-networking allows remote attackers to cause denial of service through certificate chain manipulation. When an application using glib-networking with the GnuTLS backend performs certificate verification, a specially crafted certificate chain containing circular issuer relationships triggers an infinite loop during verification. This unbounded traversal consumes excessive CPU resourc [truncated]

HIGH Red Hat CVE published 2026-05-28

CVE-2026-9804

A flaw in KubeVirt's virt-exportserver component allows an attacker with specific namespace-level access to exploit a path traversal vulnerability in the VMExport directory endpoint. This vulnerability can potentially expose sensitive data. The attacker can read arbitrary files from the exporter pod's filesystem by placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PV [truncated]

CRITICAL Red Hat CVE published 2026-05-28

CVE-2026-4408

A flaw in Samba allows remote attackers to execute commands on affected systems. This issue primarily affects non-standard configurations using the 'check password script' feature with the %u substitution character. The vulnerability is considered critical with a CVSS score of 9. Affected product deployments should be identified and prioritized for patching. The 'check password script' feature, when used [truncated]

HIGH Red Hat CVE published 2026-05-28

CVE-2026-44604

A command injection vulnerability exists in the `rpmuncompress` utility of RPM, affecting extraction of ZIP, 7z, and GEM archive formats. The tool constructs shell commands using the archive's top-level folder name without proper sanitization, allowing shell metacharacters in crafted archive names to execute arbitrary commands as the extracting user. The vulnerability requires local access with user inter [truncated]

MEDIUM Red Hat CVE published 2026-05-28

CVE-2026-9803

A vulnerability in Keycloak's ClientRegistrationAuth component allows remote unauthenticated attackers to cause a Denial of Service (DoS) condition. The flaw stems from improper handling of malformed 'Authorization: Bearer' headers in POST requests to client registration endpoints, triggering an ArrayIndexOutOfBoundsException that results in HTTP 500 errors. This vulnerability was published on May 28, 202 [truncated]