These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-19843 flaw in 389-ds-base allows LDAP users with delegated privileges to execute shell commands with root privileges on the directory server host when a Cockpit administrator views the entry in the 389 Console. This vulnerability is particularly concerning because it can be exploited by crafting a malicious DN containing shell metacharacters, potentially leading to privilege escalation and un [truncated]
A critical vulnerability was found in Red Hat Directory Server 11, allowing an attacker to gain Directory Manager authority without valid credentials through a SASL PLAIN authentication flaw. This issue arises from a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt, which can be installed on a connection following a subsequent, unrelated successful bind.
A flaw was found in 389 Directory Server, a missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service. This issue affects Red Hat Directory Server 11 instances, which defenders should assess for exposure and [truncated]
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv [truncated]
A flaw in 389 Directory Server allows an unauthenticated client to bypass access control checks, potentially leading to unauthorized directory entry modifications. This vulnerability, identified as CVE-2026-76560, affects the SELFDN ACI bind-rule evaluator, which incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value. System administrators and security teams s [truncated]
A flaw in FreeIPA's idp-add command allows authenticated IPA principals to enumerate and read environment variables of the affected server process and cause denial of service via memory exhaustion. This vulnerability impacts FreeIPA deployments, particularly those with exposed idp-add functionality. Defenders should assess the vulnerability's impact on their environments and prioritize mitigation efforts [truncated]
CVE-2026-76578 debrief based on CVE Program and NVD records. The vulnerability is a critical flaw in FreeIPA's self-managed OTP token ACI, allowing unauthenticated LDAP clients to create arbitrary Kerberos principals and add them to the administrators group. This could lead to unauthorized administrative access and lateral movement within deployments. FreeIPA administrators and security teams should asses [truncated]
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 contains a deserialization vulnerability in EAP's Artemis configuration. The default deserialization setup allows all classes to be deserialized, posing a significant security risk. Defenders should assess exposure and prioritize remediation. The vulnerability is caused by the EAP's Artemis deserialization configuration permitting deserializa [truncated]
A flaw in odh-dashboard in Red Hat OpenShift AI allows authenticated dashboard users to retrieve Kubernetes Secrets, including the cluster NVIDIA NGC API key Secret and the NIM image pull secret, without authorization. This vulnerability, CVE-2026-86332, is characterized by missing authorization checks on the backend-for-frontend route GET /api/nim-serving/:nimResource, which reads Kubernetes Secrets usin [truncated]
A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component of Flatpak. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipul [truncated]
A flaw in libtpms, a library providing software TPM 2.0 emulation, can cause a denial of service when a malformed state blob is supplied during TPM 2.0 state restoration. This issue may impact virtual machines relying on the emulated TPM device. The vulnerability is caused by an oversized skip-block length that is not validated against the remaining size of the input buffer, leading to a negative internal [truncated]
A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images. This MEDIUM-severity vulnerability, with a CVSS score of 5.3, affects Red Hat Enterprise Linux 7, 8, [truncated]
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. This vulnerability can be triggered by processing malicious GFS2 filesystem images, potentially allowing attacke [truncated]
A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. This vulnerability affects systems using gfs2-utils, particularly those processing GFS2 filesystem images [truncated]
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:33.560Z and has not been modified since then. The vulnerability is a command injection issue in rpm, particularly relevant in automated build or CI workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of [truncated]
A local unprivileged user can exploit a flaw in util-linux to redirect SUID mount(8) to bind another host directory, potentially changing ownership or mode on the redirected inode. This vulnerability involves restricted bind mounts taking the source path from fstab but not pinning that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancesto [truncated]
A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint due to a detached-tree fast path issue in Linux 6.15 and later. This issue arises from the X-mount.subdir option using a detached-tree fast path on Linux 6.15 and later, passing the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. However, this flag does not prevent int [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:23.687Z and has not been modified since then. The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the crede [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T02:17:19.750Z and has not been modified since then. This vulnerability affects Keycloak identity management service, especially those integrating social identity providers. The verification proof generated is not strictly bound to the specific upstream identity being verified, which allows an att [truncated]
A flaw in Ansible Automation Platform's automation-controller (AWX) allows a principal with read permission on an instance group and execute permission on a job template to launch bulk jobs onto unauthorized instance groups, bypassing execution-placement isolation. This could lead to unauthorized bulk job launches on instance groups and bypassing of execution-placement isolation. Defenders should verify i [truncated]
CVE-2026-53682 debrief based on CVE Program and NVD records. The vulnerability allows unauthenticated clients to query internal PKI/CA hosts and roles, potentially leading to information disclosure. Red Hat Certificate System 9 administrators should assess exposure, verify inventory, and monitor for unauthorized queries. This issue is related to the Security Domain hosts inventory, which can be queried vi [truncated]
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function [truncated]
A vulnerability in RESTEasy's SourceProvider allows an unauthenticated attacker to perform a remote file read by sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource. This vulnerability can lead to exposure of sensitive information. Defenders should assess the potential impact and verify [truncated]
CVE-2026-79654 debrief based on CVE Program and NVD records. The vulnerability affects Katello's Content View History API, allowing unauthorized access to Content View lifecycle information. Red Hat Satellite 6 administrators should assess exposure and apply patches or restrict API access to mitigate the issue. The CVE record and NVD entry provide details on the authorization flaw. Red Hat has provided re [truncated]
A flaw in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the consent requirement and obtain unauthorized access to a user account at a consent-gated client. This issue arises from the JWT Bearer grant's failure to check if [truncated]
A flaw in 389-ds-base allows a remote, authenticated attacker to cause a Denial of Service (DoS) by exploiting a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. This vulnerability can lead to resource exhaustion due to stalled connections, affecting authentication and security services. Defenders should assess exposure and prioritize remediation based on the potential [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T14:17:04.767Z and has not been modified since then. This vulnerability, CVE-2026-78367, affects RPM's rpmbuild tarball processing, specifically in the getTarSpec() function in tools/rpmbuild.cc. A crafted source archive can inject RPM macros, including Lua expressions, resulting in arbitrary code [truncated]
The multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) is vulnerable to a flaw that allows tenants with HelmRelease create permissions to manipulate the `secretRef.Namespace` field. This manipulation can lead to the `GetSecret()` function in the HelmRelease controller fetching sensitive credentials from any namespace. These credentials are then sent to an attacker-c [truncated]