PatchSiren

Red Hat CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Red Hat CVE published 2026-08-13

CVE-2026-19730

The 'podman quadlet install --replace' command does not properly truncate the destination file when the initial reflink copy attempt fails, potentially preserving security-related options from the original Quadlet file. This could lead to undesirable behavior if the preserved options are valid and used by the new Quadlet file. The command opens the existing destination file with O_CREATE|O_WRONLY but omit [truncated]

HIGH Red Hat CVE published 2026-08-13

CVE-2026-73266

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:35.713Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects the clusterclaims-controller component of Multicluster Engine (MCE), allowing authenticated tenants to manipulate ClusterClaim labels and potentially inject policies and wo [truncated]

MEDIUM Red Hat CVE published 2026-08-13

CVE-2026-73585

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disruptin [truncated]

MEDIUM Red Hat CVE published 2026-08-13

CVE-2026-73584

A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

MEDIUM Red Hat CVE published 2026-08-13

CVE-2026-73583

A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended inf [truncated]

MEDIUM Red Hat CVE published 2026-08-13

CVE-2026-18728

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T04:17:19.340Z and has not been modified since then. CVE-2026-18728 is an integer underflow vulnerability in the `iscsiuio` component of open-iscsi, occurring during IPv4 DHCP parsing. A remote attacker on the same local network segment can exploit this by sending a specially crafted IPv4/UDP DHCP [truncated]

MEDIUM Red Hat CVE published 2026-08-12

CVE-2026-71846

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T22:17:16.143Z and has not been modified since then. The insights-client ServiceAccount has excessive privileges, allowing read access to all Secrets across the hub cluster if compromised. This could lead to unauthorized access to sensitive credentials and managed-cluster kubeconfigs. The componen [truncated]

HIGH Red Hat CVE published 2026-08-12

CVE-2026-71469

The CVE-2026-71469 record describes a flaw in search-v2-api that allows an unauthenticated attacker to cause memory exhaustion by sending requests with unique random bearer tokens, leading to a Denial of Service (DoS). The CVE record was published on 2026-08-12T22:17:15.760Z and has not been modified since then. Organizations using search-v2-api should be aware of this vulnerability and take steps to miti [truncated]

MEDIUM Red Hat CVE published 2026-08-12

CVE-2026-18727

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment c [truncated]

MEDIUM Red Hat CVE published 2026-08-12

CVE-2026-18726

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unrespon [truncated]

HIGH Red Hat CVE published 2026-08-12

CVE-2026-19654

A flaw in the rsyslog imptcp module can cause rsyslogd to crash due to a crafted input sequence during oversize-frame recovery. This high-severity vulnerability has no identified confidentiality, integrity, privilege escalation, or code execution impacts. System administrators and security teams should prioritize verifying exposure and applying patches or mitigations to prevent potential service disruptio [truncated]

MEDIUM Red Hat CVE published 2026-08-12

CVE-2026-19130

An authorization bypass vulnerability was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster and knowledge of a prior credential value could exploit this vulnerability by manipulating `copiedFrom` labels to intercept newly rotated provider credentials, leading to unauthorized information disclosure.

HIGH Red Hat CVE published 2026-08-12

CVE-2026-13622

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replac [truncated]

CRITICAL Red Hat CVE published 2026-08-12

CVE-2026-73269

A local user can create a ClusterCurator resource to escalate privileges from namespace-local access to cluster-wide control, granting broad permissions. This vulnerability affects the cluster-curator-controller component, allowing privilege escalation through a specific naming convention. It has a critical CVSS score of 9.9 and requires immediate attention. Defenders should verify affected product deploy [truncated]

CRITICAL Red Hat CVE published 2026-08-12

CVE-2026-73268

The cluster-curator-controller component of multicluster engine (MCE) is vulnerable to arbitrary Job specification injection due to insufficient validation of user-controlled input. This flaw allows a tenant with create or update permissions on ClusterCurator resources to potentially inject malicious Job specifications. Successful exploitation could lead to arbitrary code execution and privilege escalatio [truncated]

CRITICAL Red Hat CVE published 2026-08-12

CVE-2026-72508

The multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) is affected by a vulnerability that allows a namespace-admin tenant to perform a confused-deputy attack. This attack enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster. Organizations should be aware of this vu [truncated]

MEDIUM Red Hat CVE published 2026-08-12

CVE-2026-19548

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The vulnerability is triggered when LTO plugins are active and the input object has abfd->my_archive == NULL. This flaw can cause a denial of service (linker crash via segmentation fault) and potentially allow for arbitrary code execution through heap manip [truncated]

HIGH Red Hat CVE published 2026-08-12

CVE-2026-73122

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T02:16:38.330Z and has not been modified since then. The vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information, specifically reading all Secrets and ConfigMaps within any Channel namespace on the hub. This could expose credentials for [truncated]

CRITICAL Red Hat CVE published 2026-08-12

CVE-2026-72526

The CVE-2026-72526 flaw was found in the multicloud-integrations component's Application propagation controller, which processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. This allows a tenant with permissions to create Applications on the hub cluster to target arbitrary managed clusters, potentially forcing ArgoCD on the spoke clusters to sync [truncated]

CRITICAL Red Hat CVE published 2026-08-12

CVE-2026-70398

A critical vulnerability, CVE-2026-70398, was found in the multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM). This flaw allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller, potentially redirecting sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead t [truncated]

HIGH Red Hat CVE published 2026-08-12

CVE-2026-66878

The CVE-2026-66878 vulnerability was published on 2026-08-12T02:16:37.937Z. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability by manipulating the Channel.Spec.SecretRef.Namespace field, potentially leading to information disclosure. The CVSS score for this vulnerability is 7.7, indicating a high severity level. [truncated]

MEDIUM Red Hat CVE published 2026-08-12

CVE-2026-64927

The multicloud-operators-channel component is vulnerable to unauthorized sensitive information manipulation due to a flaw that allows users with specific permissions to modify Secrets across different namespaces. This could lead to unauthorized access to information or elevated privileges within the system. Organizations using this component should assess their exposure and take necessary precautions. The [truncated]

MEDIUM Red Hat CVE published 2026-08-11

CVE-2026-71845

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T20:18:45.800Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Red Hat's insights-client, particularly in disconnected cluster deployments. The setDefault() function logs environment variables, including the CCX_TOKEN bearer credential, in clea [truncated]

MEDIUM Red Hat CVE published 2026-08-11

CVE-2026-71475

A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path due to improper validation or URL encoding of the ClusterID. This flaw in insights-client allows potential redirection of authenticated requests to unintended API endpoints, which may lead to information disclosure or unauthorized access. Organizations using Red Hat Advanced Cluster Management [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-71474

A local user with access to pod logs on the hub could read the long-lived credential for cloud.openshift.com, potentially granting unauthorized access to Red Hat cloud services. This vulnerability in insights-client logs request headers, including the cloud.openshift.com pull-secret token, in case of a non-200 response. The exposure of sensitive credentials in logs poses a significant risk to Red Hat clou [truncated]

MEDIUM Red Hat CVE published 2026-08-11

CVE-2026-71468

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.

HIGH Red Hat CVE published 2026-08-11

CVE-2026-71467

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T20:18:45.260Z and has not been modified since then. The vulnerability affects search-v2-api, specifically its authentication middleware which unconditionally skips authentication when a request includes an 'Upgrade: websocket' header. An unauthenticated attacker can exploit this by sending a spec [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-19546

A flaw was found in DBI, described as a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. The CVE-2026-19546 record was published on 2026-08-11T16:17:31.767Z and was last modified on 2026-09-09T22:17:11.767Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects DBI installations on RHEL systems, particularly versions 9.8.z and 10.2.z. The high CVSS score of 8.8 indicates signif [truncated]

MEDIUM Red Hat CVE published 2026-08-11

CVE-2026-14180

A flaw in the ChunkReader component of the Undertow HTTP server, used by WildFly and JBoss EAP, allows an attacker to bypass security controls by sending a specially crafted request with an extremely large chunk size. This issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags, which can overlap and trick the parser into thinking a request ha [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-50236

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position. This vulnerability may impact OpenShift Console administrators and users with access to webhook helpers [truncated]