PatchSiren

Red Hat CVE debriefs · Page 18

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Red Hat CVE published 2026-04-22

CVE-2026-6857

A vulnerability in camel-infinispan allows remote attackers with low privileges to exploit unsafe deserialization in the ProtoStream remote aggregation repository, potentially leading to arbitrary code execution. This vulnerability impacts systems using Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, and defenders should assess exposure and prioritize patching accordingly. The vulnerability i [truncated]

HIGH Red Hat CVE published 2026-04-22

CVE-2026-6855

CVE-2026-6855 is a high-severity path traversal issue in InstructLab’s chat session handler. By manipulating the `logs_dir` parameter, a local attacker with low privileges can cause the application to create directories or write files outside the intended location, which can lead to unauthorized data modification or disclosure.

MEDIUM Red Hat CVE published 2026-04-22

CVE-2026-6848

CVE-2026-6848 is a medium-severity authentication flaw in Red Hat Quay where password re-verification for sensitive operations can be bypassed. According to the published description, this can let a user with a timed-out session, or an attacker with access to an idle authenticated browser session, complete privileged actions such as token generation or robot account creation without re-entering valid cred [truncated]

HIGH Red Hat CVE published 2026-04-22

CVE-2026-6846

CVE-2026-6846 is a high-severity heap-buffer-overflow in GNU binutils while processing a specially crafted XCOFF object file during linking. If a user is tricked into handling a malicious file, the flaw could corrupt memory and may lead to arbitrary code execution or a denial of service. NVD’s analysis lists GNU binutils up to 2.46 as affected, and also includes Red Hat-linked platform entries that should [truncated]

MEDIUM Red Hat CVE published 2026-04-22

CVE-2026-6845

CVE-2026-6845 is a denial-of-service issue in GNU binutils' readelf utility. According to the CVE/NVD data, a local attacker can cause a crash or excessive resource consumption by getting a user to process a specially crafted ELF file. The reported impact is availability only, with no confidentiality or integrity impact listed.

MEDIUM Red Hat CVE published 2026-04-22

CVE-2026-6843

CVE-2026-6843 describes a format string vulnerability in nano’s statusline() function. If a directory name contains printf-style specifiers, nano may attempt to render that name and crash with a segmentation fault, resulting in denial of service for the application. The issue is publicly documented in CVE/NVD and mapped by NVD to multiple affected CPEs, including nano 8.7 and several Red Hat platform entries.

CRITICAL Red Hat CVE published 2026-04-15

CVE-2026-6388

CVE-2026-6388 is a critical vulnerability in ArgoCD Image Updater that allows an attacker with permissions to create or modify an ImageUpdater resource in a multi-tenant environment to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting [truncated]

MEDIUM Red Hat CVE published 2026-04-15

CVE-2026-6245

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read when processed by functions like snprintf(). A local attacker could potentially trigger [truncated]

HIGH Red Hat CVE published 2026-04-10

CVE-2026-5483

CVE-2026-5483 is a high-severity vulnerability in the odh-dashboard component of Red Hat OpenShift AI (RHOAI). The flaw allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint, potentially enabling an attacker to gain unauthorized access to Kubernetes resources. The vulnerability has a CVSS score of 8.5 and is considered HIGH severity. Red Hat has released advisories and p [truncated]

MEDIUM Red Hat CVE published 2026-04-09

CVE-2026-4878

A flaw in libcap allows a local unprivileged user to exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This enables an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file, potentially leading to privilege escalation. The vulnerability affects Red Hat Enterprise Linux 10 and other products that ut [truncated]

MEDIUM Red Hat CVE published 2026-04-08

CVE-2026-32591

A flaw in Red Hat Quay's Proxy Cache configuration feature allows an organization administrator to force the Quay server to make requests to internal network services or other resources that should not be accessible from the Quay application. This issue requires verification of affected versions, exploitation, and remediation from official sources.

HIGH Red Hat CVE published 2026-04-08

CVE-2026-32590

A flaw in Red Hat Quay's handling of resumable container image layer uploads could allow an attacker to execute arbitrary code on the Quay server if the upload process data is tampered with. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. Red Hat has released several errata to address this issue, including RHSA-2026:19375, RHSA-2026:21017, and others.

HIGH Red Hat CVE published 2026-04-08

CVE-2026-32589

A flaw in Red Hat Quay's container image upload process allows an authenticated user with push access to interfere with image uploads by other users, potentially allowing them to read, modify, or cancel those uploads. This vulnerability, tracked as CVE-2026-32589, is a high-severity issue that defenders should prioritize verifying exposure and assessing compensating controls for. The vulnerability affects [truncated]

MEDIUM Red Hat CVE published 2026-04-08

CVE-2026-2377

A Server-Side Request Forgery (SSRF) vulnerability in Red Hat's Mirror Registry for Red Hat OpenShift allows authenticated attackers to abuse the log export feature by supplying a crafted URL, forcing the backend to make unauthorized requests to internal network resources. Published 2026-04-08 and modified 2026-05-20, this flaw carries a CVSS 3.1 score of 6.5 (Medium severity) with a vector of AV:N/AC:L/P [truncated]

MEDIUM Red Hat CVE published 2026-04-08

CVE-2025-14243

A vulnerability was found in the OpenShift Mirror Registry. This flaw allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation. The vulnerability is classified under CWE-209 and has a CVSS score of 5.3, categorized as MEDIUM severity.

MEDIUM Red Hat CVE published 2026-04-08

CVE-2025-57847

A container privilege escalation flaw was found in certain Red Hat Ansible Automation Platform images due to the /etc/passwd file being created with group-writable permissions. An attacker who can execute commands within an affected container as a non-root user can leverage their membership in the root group to modify the /etc/passwd file, adding a new user with arbitrary UID, including UID 0, gaining ful [truncated]

CRITICAL Red Hat CVE published 2026-04-07

CVE-2026-4631

CVE-2026-4631 is a critical vulnerability in Cockpit's remote login feature. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes [truncated]

HIGH Red Hat CVE published 2026-04-07

CVE-2025-14821

CVE-2025-14821 is a high-severity vulnerability in libssh that allows local man-in-the-middle attacks, security downgrades of SSH connections, and manipulation of trusted host information. The vulnerability poses a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems. The library automatically loads configuratio [truncated]

MEDIUM Red Hat CVE published 2026-04-07

CVE-2026-5745

A flaw was found in libarchive, specifically within the archive_acl_from_text_nl() function, where a NULL pointer dereference vulnerability exists in the ACL parsing logic. This issue can cause an application utilizing the libarchive API, such as bsdtar, to crash when processing a malformed ACL string, resulting in a Denial of Service (DoS). The vulnerability is triggered by a malformed ACL string, such a [truncated]

HIGH Red Hat CVE published 2026-04-07

CVE-2026-4740

A flaw in Open Cluster Management (OCM) allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller, enabling cross-cluster privilege escalation. This issue affects Red Hat Advanced Cluster Management (ACM). The vulnerability allows an attacker to potentially gain control over other managed clusters, including the hub cluster, by exploiting improper vali [truncated]

MEDIUM Red Hat CVE published 2026-04-06

CVE-2026-5704

A flaw in tar allows remote attackers to inject hidden files with arbitrary content by crafting a malicious archive, bypassing pre-extraction inspection mechanisms. This could potentially allow attackers to introduce malicious files onto a system without detection. The CVE record was published on 2026-04-06T16:16:42.140Z and has not been modified since then. The NVD entry is currently Modified.

LOW Red Hat CVE published 2026-04-03

CVE-2026-3184

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain na [truncated]

MEDIUM Red Hat CVE published 2026-04-03

CVE-2026-2625

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the [truncated]

HIGH Red Hat CVE published 2026-04-02

CVE-2026-4634

CVE-2026-4634 is a high-severity vulnerability in Keycloak that can lead to a Denial of Service (DoS) condition. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a DoS for [truncated]

HIGH Red Hat CVE published 2026-04-02

CVE-2026-4282

A flaw was found in Keycloak's SingleUseObjectProvider, a global key-value store, which lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation. The Common Vulnerability Scoring System (CVSS) score for this vulnerability i [truncated]

HIGH Red Hat CVE published 2026-04-02

CVE-2026-3872

A flaw was found in Keycloak, which allows an attacker controlling another path on the same web server to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. This issue, CVE-2026-3872, has a CVSS score of 7.3 and is considered high severity. A successful attack could lead to the theft of an access token, resulting in information disclosure. The vulnerability was pu [truncated]

HIGH Red Hat CVE published 2026-04-01

CVE-2026-35093

A flaw was found in libinput, which allows a local attacker to bypass security restrictions by placing specially crafted Lua bytecode files in certain system or user configuration directories. This could lead to the attacker monitoring keyboard input and sending that information to an external location. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The CVE was published on Apr [truncated]

HIGH Red Hat CVE published 2026-04-01

CVE-2026-35092

An integer overflow vulnerability in Corosync's join message validation allows remote, unauthenticated attackers to crash the service via crafted UDP packets. The flaw specifically affects deployments using totemudp/totemudpu transport mode. The vulnerability was disclosed in April 2026 and modified in May 2026 with additional advisory information. Red Hat has issued multiple security advisories addressin [truncated]

HIGH Red Hat CVE published 2026-04-01

CVE-2026-35091

A vulnerability in Corosync's membership commit token sanity check allows remote unauthenticated attackers to trigger an out-of-bounds read via a crafted UDP packet, leading to denial of service and potential limited memory disclosure. The flaw stems from an incorrect return value in the sanity check logic. Red Hat has issued multiple security advisories addressing this issue across OpenShift and Enterpri [truncated]

HIGH Red Hat CVE published 2026-03-31

CVE-2026-5201

CVE-2026-5201 affects gdk-pixbuf's JPEG image loader and can be triggered by a specially crafted JPEG. The flaw is a heap-based buffer overflow caused by improper validation of color component counts. Because exploitation does not require user interaction and can occur through image-processing paths such as thumbnail generation, the main impact is application crash and denial of service.