PatchSiren

Red Hat CVE debriefs · Page 6

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Red Hat CVE published 2026-08-11

CVE-2026-72694

A flaw in MRTG allows local privilege escalation when the daemon is started as root and subsequently drops privileges. An attacker can exploit a symbolic link following vulnerability by influencing or pre-placing a symlink in the process ID file path, tricking the root process into changing the ownership of an arbitrary existing file to the daemon user.

HIGH Red Hat CVE published 2026-08-11

CVE-2026-72693

The `openvt -u` command is intended to identify the owner of the current VT and execute `login` as that user from a privileged context. However, due to a flaw in the ownership test in `authenticate_user()`, an unprivileged process can bypass this check if it has file descriptor 0 attached to a TTY previously owned by the privileged console owner. This can lead to a local privilege escalation vulnerability [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-71217

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T09:17:14.057Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects iperf3, allowing remote attackers to cause a Denial of Service (DoS) by sending crafted control-channel JSON with oversized numeric parameters, leading to excessive stream [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15565

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T09:17:13.370Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability, CVE-2026-15565, affects Undertow-based applications that utilize websockets, particularly those with @ServerEndpoint classes having @OnMessage methods. A remote attacker can cause [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15563

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations. This vulnerability exists due to a lack of authentication in the NameService, which could lead to potential security risks if not addressed. Administrators and users of [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15562

A flaw in EAP's jboss-remoting allows a remote unauthenticated attacker who can reach specific ports and complete a jboss-remoting handshake to cause OOM errors, degrading requests server-wide and leading to denial of service. This vulnerability affects Red Hat JBoss Enterprise Application Platform 7.4.25, particularly if exposed to untrusted networks. The impact is supported by the CVE record and NVD ent [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15561

A flaw in EAP's undertow http/1.1 chunked-transfer decoder allows an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service. This vulnerability is particularly concerning due to its potential for significant impact on system availability. Defenders should prioritize verifying exposure and assessing t [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15560

This CVE debrief is based on the supplied source corpus. The CVE record was published on 2026-08-11T09:17:12.823Z and has not been modified since then. CVE-2026-15560 is a high-severity vulnerability in Red Hat JBoss Enterprise Application Platform 7.4.25 that allows an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM. The openjdk-orb's JDKBridge honou [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15556

A flaw in Picketlink's SP signature validation allows an attacker to forge a SAML response and authenticate as any principal with any roles on the protected application. This issue is highly severe with a CVSS score of 8.1. Red Hat JBoss Enterprise Application Platform 7.4.25 is known to be affected. The CVE was published on 2026-08-11 and last modified on 2026-09-25.

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15555

A flaw in JBoss marshalling allows for remote code execution via deserialization gadget chains. Red Hat JBoss Enterprise Application Platform 7.4.25 is affected. Users should assess exposure and prioritize remediation. The vulnerability is caused by the Infinispan session replication path deserializing replicated session data via the JBoss Marshalling River unmarshaller with no class filtering. This allow [truncated]

HIGH Red Hat CVE published 2026-08-11

CVE-2026-15554

CVE-2026-15554 debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T09:17:12.400Z and has not been modified since then. This vulnerability affects Red Hat JBoss Enterprise Application Platform 7.4.25, allowing unauthenticated attackers with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol. De [truncated]

CRITICAL Red Hat CVE published 2026-08-11

CVE-2026-10579

A critical vulnerability was found in Picketlink Federation SAML, which allows an unauthenticated attacker to authenticate as any principal in any role due to the unsolicited response handler accepting forged assertions without verification or validation. This flaw could lead to information disclosure, access to restricted operations, or other security issues.

MEDIUM Red Hat CVE published 2026-08-10

CVE-2026-6426

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted incoming migration state with bit 31 set causes the value to be interpreted as negative and then implicitly converted to a very large size_t, leading qemu_get_buffer() to [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-63622

A local attacker could exploit a symlink-following vulnerability in libvirt to escalate privileges from the confined `swtpm` user to root-level file ownership control. This vulnerability, tracked as CVE-2026-63622, allows an attacker to plant a symbolic link within the `swtpm` state directory, tricking the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user, pote [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18982

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T21:17:21.833Z and has not been modified since then. The RHOAI training-operator vulnerability CVE-2026-18982 allows users with standard edit or admin roles in any Kubernetes namespace to escalate privileges by creating training jobs, potentially leading to impersonation of service accounts, acces [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18951

The Red Hat OpenShift AI (RHOAI) overlay for the training operator contains a flaw that incorrectly aggregates 'trainjobs' management permissions into the native Kubernetes 'edit ClusterRole'. This allows users with 'edit ClusterRole' permissions in a namespace to create, modify, and delete 'TrainJobs'. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remot [truncated]

CRITICAL Red Hat CVE published 2026-08-10

CVE-2026-18948

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T21:17:21.290Z and has not been modified since then. CVE-2026-18948 is a critical vulnerability in Feast that allows unauthenticated remote code execution via improperly deserialized user-defined functions (UDFs). The flaw exists due to insecure deserialization using the 'dill' library. An attacke [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18621

CVE-2026-18621 is a high-severity vulnerability in Red Hat OpenShift AI 2.25, allowing an attacker with namespace editor privileges to bypass security hardening and create pods with elevated privileges. This flaw, found in Data Science Pipelines (DSP), enables the attacker to gain node-root access and execute arbitrary code. The vulnerability has a CVSS score of 7.6 and is considered high severity.

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18620

A flaw in Data Science Pipelines allows a restricted user to exploit an improper authorization vulnerability. This could lead to disclosure of sensitive information and execution of commands within other users' pods. The vulnerability is caused by an improper authorization issue in the setDefaultServiceAccount function of Data Science Pipelines. A restricted user can exploit this by specifying a more priv [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18618

A flaw in ml-metadata's statically-linked gRPC stack makes it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker with network access to the MLMD pod could exploit these vulnerabilities by sending specially crafted HTTP/2 requests, potentially disrupting pipeline runs in the affected namespace. This issue could lead to a denial of service by crashing the MLMD pod. Kubernetes [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18617

A vulnerability in the Data Science Pipelines Operator (DSPO) allows a namespace editor to inject dangerous parameters into the MySQL Data Source Name (DSN) string via the spec.database.customExtraParams field. This can enable LOCAL INFILE functionality, potentially leading to the exfiltration of sensitive files, such as the service account token, from the operator pod, and resulting in privilege escalati [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18611

A flaw in the Data Science Pipelines Operator allows an unauthenticated attacker to derive sensitive credentials if they can access the MinIO Route or MariaDB Service. The operator uses a weak pseudo-random number generator to generate these credentials, making them predictable. This could lead to unauthorized access to pipeline artifacts and metadata, resulting in significant information disclosure.

HIGH Red Hat CVE published 2026-08-10

CVE-2026-18608

A flaw in the Data Science Pipelines Operator (DSPO) allows for excessive privileges, potentially leading to full administrative control over a Kubernetes cluster if exploited. The DSPO's ClusterRole includes extensive privileges beyond what is necessary for its operation, such as the ability to execute commands within pods and manage cluster-wide roles. This could allow an attacker to gain full administr [truncated]

CRITICAL Red Hat CVE published 2026-08-10

CVE-2026-14450

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T21:17:19.487Z and has not been modified since then. The MaaS API vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`. This enables an attacker to gain unauthorized access and escalate [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-59091

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. This vulnerability could allow a remote attacker to exploit it by tricking a user into opening a specially crafted image file, potentially leading to unexpected application behavior or other security impacts without requiring further user interaction. GIMP users should prioritize patching to prevent potential security i [truncated]

MEDIUM Red Hat CVE published 2026-08-10

CVE-2026-71577

A flaw in multicluster-global-hub allows a compromised managed hub to intercept sensitive bootstrap kubeconfigs during a ManagedClusterMigration, granting unauthorized access and information disclosure. This issue arises from the system incorrectly granting all managed hubs read access to a shared communication topic. As a result, defenders managing multicluster-global-hub deployments should assess exposu [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-71576

A flaw in multicluster-global-hub allows a remote attacker to manipulate source identity of incoming CloudEvents on Kafka status topics after compromising a managed hub. This enables falsification or deletion of critical data such as compliance, inventory, and cluster health information belonging to other hubs. The vulnerability impacts defenders responsible for securing multicluster-global-hub deployment [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-59090

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code o [truncated]

MEDIUM Red Hat CVE published 2026-08-10

CVE-2026-59088

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote attacker could exploit this by tricking a user into opening a specially crafted FLI file, l [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-59087

The GIMP image manipulation program is affected by a heap overflow vulnerability within its Seattle Filmworks file loader. This vulnerability, tracked as CVE-2026-59087, could allow a remote attacker to execute arbitrary code or cause a denial of service by tricking a user into opening a specially crafted Seattle Filmworks file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. [truncated]