PatchSiren

Red Hat CVE debriefs · Page 17

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Red Hat CVE published 2026-05-19

CVE-2026-7307

CVE-2026-7307 describes a network-reachable denial-of-service condition in Keycloak’s SAML handling. A remote, unauthenticated attacker can send specially crafted XML to the SAML endpoint and trigger high CPU usage plus worker thread starvation, making the service unavailable. The supplied record also shows low-confidence vendor attribution, with Red Hat references present in the source metadata.

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-4630

CVE-2026-4630 is an IDOR weakness in Keycloak’s Authorization Services Protection API. An authenticated client that knows or can obtain another Resource Server’s UUID within the same realm may bypass authorization checks and issue unauthorized GET, PUT, and DELETE requests against protected resources. The result can be information disclosure, unauthorized modification, or deletion of data. The vulnerabili [truncated]

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-37982

CVE-2026-37982 describes an authentication weakness in Keycloak's WebAuthn flow where an `ExecuteActionsActionToken` can be replayed. If an attacker intercepts the execute-actions email link, they may be able to register their own authenticator to a victim account, creating a path to unauthorized credential enrollment and persistent account takeover. The supplied NVD snapshot lists the issue as CVSS 3.1 6.8 (Medium).

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-37981

CVE-2026-37981 describes a broken access control flaw in Keycloak’s Account Resources user lookup endpoint. A remote authenticated user who owns at least one User-Managed Access (UMA) resource can send crafted requests with arbitrary usernames or email values and receive full profile objects for unrelated realm users. The result is broad disclosure of personally identifiable information (PII) across the realm.

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-37979

CVE-2026-37979 is a medium-severity access control issue in Keycloak's OpenID Connect token introspection flow. A confidential client with valid credentials may be able to bypass audience restrictions and retrieve sensitive token claims intended for other resource servers, creating a confidentiality exposure for lightweight access tokens.

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-37978

CVE-2026-37978 describes a Keycloak issue where a low-privilege administrator with the 'view-clients' role can call the 'evaluate-scopes' Admin API endpoints with an arbitrary userId. That can expose personally identifiable information and authorization details for users beyond the caller’s intended scope, enabling cross-role information disclosure across the realm. The CVE was published on 2026-05-19 and [truncated]

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-8922

A flaw in Keycloak's OpenID Connect (OIDC) Introspection feature causes the realm-level `notBefore` revocation policy to be improperly honored when a client-level `notBefore` policy is also configured. This allows tokens that should have been revoked to remain active, potentially enabling unauthorized access or continued session validity. The vulnerability affects systems using Keycloak for identity and a [truncated]

MEDIUM Red Hat CVE published 2026-05-19

CVE-2026-8830

CVE-2026-8830 describes a weakness in Keycloak's credential registration flow where an authenticated user may bypass configured WebAuthn policy enforcement by manipulating client-side JavaScript. The supplied NVD metadata says the server-side processAction() path does not validate that the newly created credential matches the realm's WebAuthn policy parameters, which can result in credentials that do not [truncated]

HIGH Red Hat CVE published 2026-05-18

CVE-2026-42009

A vulnerability in GnuTLS's Datagram Transport Layer Security (DTLS) implementation allows remote attackers to cause denial of service through malformed packet handling. The flaw exists in the comparator function responsible for ordering DTLS packets by sequence numbers, which fails to properly handle packets with duplicate sequence numbers. This can result in unstable packet ordering or undefined behavio [truncated]

HIGH Red Hat CVE published 2026-05-11

CVE-2026-4802

CVE-2026-4802 is a high-severity remote command execution issue associated with Cockpit’s system logs UI. According to the supplied sources, crafted links containing unsanitized user-controlled parameters can let an attacker inject shell metacharacters or command substitutions, resulting in arbitrary shell command execution on the affected host. The CVSS vector shows the attack requires network access, lo [truncated]

HIGH Red Hat CVE published 2026-05-07

CVE-2026-42011

A vulnerability in GnuTLS allows remote attackers to bypass certificate name constraint validation when previous Certificate Authorities (CAs) only had excluded name constraints. The flaw causes permitted name constraints to be incorrectly ignored in this specific chain configuration, potentially enabling certificate spoofing or man-in-the-middle attacks. The vulnerability carries a HIGH severity CVSS 3.1 [truncated]

HIGH Red Hat CVE published 2026-05-07

CVE-2026-42010

A flaw in gnutls allows authentication bypass via specially crafted usernames with NUL characters, impacting servers configured with RSA-PSK. This vulnerability enables attackers to gain unauthorized access by exploiting the weakness in username validation, potentially leading to system compromise. System administrators and security teams should assess exposure and apply patches or updates to prevent expl [truncated]

MEDIUM Red Hat CVE published 2026-05-06

CVE-2026-6420

CVE-2026-6420 is a medium-severity vulnerability in the Keylime verifier. An attacker with root access on an enrolled monitored machine can exploit this flaw to stockpile valid TPM quotes and replay them to evade detection. The verifier uses a hardcoded challenge nonce for TPM quote attestation instead of a cryptographically random value. This issue affects only the push model deployment. The Common Vulne [truncated]

MEDIUM Red Hat CVE published 2026-05-05

CVE-2026-34956

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T16:16:11.927Z and has not been modified since then. Open vSwitch has a flaw that can cause a Denial of Service (DoS) condition. A remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters, triggering a heap access error and resulting in a crash. System [truncated]

MEDIUM Red Hat CVE published 2026-05-05

CVE-2026-34002

A medium-severity out-of-bounds read vulnerability in the X.Org X server's XKB (X Keyboard Extension) modifier map handling allows an attacker with local access to the X11 server to trigger memory disclosure or denial of service via malformed requests. The vulnerability was published on 2026-05-05 and last modified on 2026-05-28. Red Hat has issued multiple security advisories addressing this flaw across [truncated]

MEDIUM Red Hat CVE published 2026-05-05

CVE-2026-34000

CVE-2026-34000 is a medium-severity out-of-bounds read vulnerability in the X.Org X server, specifically within the XKB geometry processing functions `CheckSetGeom()` and `XkbAddGeomKeyAlias`. The flaw allows an attacker with a connection to the X11 server—whether local or remote—to read uninitialized or out-of-bounds memory without requiring user interaction. This can result in information disclosure or [truncated]

HIGH Red Hat CVE published 2026-05-04

CVE-2026-6266

A flaw was found in the AAP gateway's user auto-link strategy, introduced in AAP 2.6. This strategy automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or gain unauthorized access to other accounts, including administrative accounts, [truncated]

HIGH Red Hat CVE published 2026-05-04

CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS [truncated]

MEDIUM Red Hat CVE published 2026-04-30

CVE-2026-3833

A flaw in gnutls allows for case-sensitive comparisons of nameConstraints labels, which can be exploited by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN). This leads to a policy bypass where a certificate that should be rejected is instead accepted, potentially resulting in unauthorized access or information disclosure.

HIGH Red Hat CVE published 2026-04-30

CVE-2026-33845

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service. The vulnerability affects systems using GnuTLS, especially those with DTLS enabled, and defenders should assess exposur [truncated]

MEDIUM Red Hat CVE published 2026-04-30

CVE-2026-7500

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permi [truncated]

MEDIUM Red Hat CVE published 2026-04-30

CVE-2026-7163

CVE-2026-7163 is a vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allowing an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The vulnerability affects Red Hat Advanced Cluster Management (ACM) deployments that i [truncated]

HIGH Red Hat CVE published 2026-04-24

CVE-2026-5367

A high-severity out-of-bounds read vulnerability in OVN (Open Virtual Network) allows remote attackers to leak heap memory via crafted DHCPv6 SOLICIT packets. The flaw stems from insufficient validation of the Client ID option length in DHCPv6 packet parsing within ovn-controller. By sending a SOLICIT packet with an inflated Client ID length field, an attacker can cause the controller to read beyond packe [truncated]

MEDIUM Red Hat CVE published 2026-04-24

CVE-2026-5265

A vulnerability in OVN (Open Virtual Network) ovn-controller allows a virtual machine to trigger an out-of-bounds heap read that leaks memory into ICMP error responses. When ovn-controller generates ICMP Destination Unreachable or Packet Too Big messages, it copies a portion of the original packet into the ICMP body using the IP header's self-declared total length field without validating that length agai [truncated]

MEDIUM Red Hat CVE published 2026-04-23

CVE-2026-6732

CVE-2026-6732 is a denial of service (DoS) vulnerability in libxml2, a widely used XML parsing library. The vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. Thi [truncated]

HIGH Red Hat CVE published 2026-04-23

CVE-2026-34003

A local out-of-bounds memory access vulnerability exists in the X.Org X server's XKB key types request validation. An attacker with local access can send a crafted request to trigger the flaw, potentially causing information disclosure, server crash (DoS), or higher impact outcomes in certain configurations. The vulnerability was published on 2026-04-23 and last modified on 2026-05-20. Multiple Red Hat se [truncated]

HIGH Red Hat CVE published 2026-04-23

CVE-2026-34001

A use-after-free vulnerability in the X.Org X server's XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function, was disclosed on 2026-04-23 and last modified on 2026-05-28. The flaw allows an attacker with access to the X11 server to trigger a server crash and potentially achieve memory corruption without requiring user interaction. The vulnerability is rated HIGH severity with [truncated]

HIGH Red Hat CVE published 2026-04-23

CVE-2026-33999

A HIGH severity integer underflow vulnerability in the X.Org X server's XKB compatibility map handling allows attackers with local or remote X11 server access to trigger buffer read overruns, potentially causing denial of service or memory-safety violations. The vulnerability was published on 2026-04-23 and last modified on 2026-05-20. Multiple Red Hat Security Advisories have been issued addressing this [truncated]

MEDIUM Red Hat CVE published 2026-04-22

CVE-2026-6862

A flaw in libefiboot, part of efivar, allows a local user to cause a denial of service (DoS) by providing a specially crafted device path node, leading to infinite recursion and stack exhaustion. The vulnerability arises from the device path node parser in libefiboot failing to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI device path node header. This is [truncated]

HIGH Red Hat CVE published 2026-04-22

CVE-2026-6859

CVE-2026-6859 is a high-severity vulnerability in InstructLab, a project by Red Hat, that allows remote attackers to execute arbitrary Python code. The flaw is caused by the `linux_train.py` script hardcoding `trust_remote_code=True` when loading models from HuggingFace. This enables a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ilab train/download/generate` wit [truncated]