PatchSiren

Red Hat CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Red Hat CVE published 2026-08-10

CVE-2026-19404

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T10:17:32.250Z and has not been modified since then. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations in 389 Directory Server perform no authorization check. This allows an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enable [truncated]

HIGH Red Hat CVE published 2026-08-10

CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. This CVE record was published on 2026-08-10T03:16:40.380Z and has not been modified since then. Users and administrators of GStreamer-based applications, especially those processing untrusted media files, should be awar [truncated]

HIGH Red Hat CVE published 2026-08-08

CVE-2026-42170

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T16:16:49.093Z and has not been modified since then. This CVE-2026-42170 vulnerability involves a heap-based buffer overflow in the GIMP DDS file parser. A crafted DDS file can declare a D3D9 pixel format with a lower bits-per-pixel value, leading to an undersized heap buffer allocation. Subsequen [truncated]

HIGH Red Hat CVE published 2026-08-07

CVE-2026-15816

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T11:17:05.100Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects dracut, specifically its die() error-handling function which writes messages to shell scripts under the initramfs emergency-hook directory without proper shell quoting. An [truncated]

MEDIUM Red Hat CVE published 2026-08-07

CVE-2026-19079

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory c [truncated]

HIGH Red Hat CVE published 2026-08-06

CVE-2026-18649

A flaw in the GStreamer gst-plugins-good package's rtph264depay and rtph265depay RTP depayloader elements allows remote, unauthenticated attackers to cause a denial of service through process termination by sending a continuous stream of RTP fragments without an end-of-fragment marker, exhausting process memory. This vulnerability highlights the importance of validating and sanitizing RTP packets in GStre [truncated]

MEDIUM Red Hat CVE published 2026-08-06

CVE-2026-18967

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:29.413Z and has not been modified since then. The SAML broker component of Keycloak fails to enforce the OneTimeUse condition in SAML assertions, allowing an attacker to replay valid, unused assertions. This flaw could enable session hijacking and unauthorized access as the victim user. Key [truncated]

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-44605

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-44605 was published on 2026-08-05T18:17:11.173Z. This CVE record details a heap buffer overflow vulnerability in RPM Package Manager (RPM) when processing a specially crafted NDB database file. The vulnerability, which arises from an error in how RPM handles certain calculations during file parsing, leading to [truncated]

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-49331

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:16:57.330Z and has not been modified since then. This vulnerability affects openshift/oauth-proxy, specifically paths configured to bypass authentication (skip-auth-regex). An unauthenticated attacker can inject forged identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-T [truncated]

HIGH Red Hat CVE published 2026-08-05

CVE-2026-16442

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:16:52.027Z and has not been modified since then. The CVE-2026-16442 vulnerability is related to the SAML broker component of Keycloak. The issue arises from the IdP-initiated Single Sign-On endpoint not checking if a provider is restricted to account linking only. This oversight allows an atta [truncated]

HIGH Red Hat CVE published 2026-08-05

CVE-2026-15572

The CVE-2026-15572 flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The 'Allowed Protocol Mapper Types' policy restricts which types of data mappers a client can use but fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. This allows an attacker with client registration privileges to exploit the vulnerabilit [truncated]

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-16100

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T15:16:37.573Z and has not been modified since then. This vulnerability affects Keycloak instances with metrics enabled, allowing authenticated users with low privileges to potentially exploit this flaw and cause a denial-of-service condition by creating a massive number of unique metric entries, [truncated]

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-16071

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information f [truncated]

HIGH Red Hat CVE published 2026-08-05

CVE-2026-15573

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T15:16:36.397Z and has not been modified since then. This vulnerability affects Keycloak instances, particularly those with administrative or restricted areas. The PathMatcher component in Keycloak's Authorization Services does not properly normalize URIs before comparison, allowing attackers to t [truncated]

HIGH Red Hat CVE published 2026-08-05

CVE-2026-16443

A flaw in the SAML metadata import functionality of the keycloak-services component in Red Hat Build of Keycloak allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier. The issue arises when importing identity provider metadata lacking specific usage attributes for keys, causing the system to incorrectly disable signa [truncated]

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-71227

A flaw in libkcapi allows a local attacker to influence an application using the Asynchronous Input/Output (AIO) interface, potentially leading to a persistent denial of service. The vulnerability arises from the _kcapi_aio_read_all() function entering a non-terminating wait loop when reusing an AIO-enabled handle after a prior completion error. System administrators and security teams should assess expos [truncated]

HIGH Red Hat CVE published 2026-08-05

CVE-2026-71226

A memory corruption vulnerability exists in libkcapi's one-shot AIO path. When an error occurs, the path may return before all submitted IOCBs are drained, potentially allowing later kernel writes into caller-owned output buffers. This issue affects multiple Red Hat products, including Red Hat Enterprise Linux 10, and has been assigned a CVSS score of 7.3.

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-71225

A flaw in libkcapi allows remote attackers to weaken data confidentiality by reusing Initialization Vectors (IVs) for large inputs in stateful cipher modes. This issue affects various Red Hat products, including Red Hat Enterprise Linux 10. The vulnerability can lead to a significant weakening of data confidentiality and may also affect data integrity. Defenders of Red Hat Enterprise Linux 10 and other af [truncated]

CRITICAL Red Hat CVE published 2026-08-05

CVE-2026-10090

A critical vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes 2, allowing a user with namespace-scoped 'edit' privileges to escalate privileges to full cluster-admin. This issue arises from the Application Subscription controller's failure to verify role and restrict resources, enabling an attacker to include cluster-scoped resources in a Helm chart.

CRITICAL Red Hat CVE published 2026-08-05

CVE-2026-10059

A flaw in the Multicluster Engine for Kubernetes ClusterCurator controller allows a tenant administrator with namespace-scoped privileges to create a namespaced ClusterCurator, inadvertently granting the ability to mint a token for a ServiceAccount with cluster-wide administrative authority, leading to privilege escalation. This vulnerability can have significant impacts on Kubernetes deployments, particu [truncated]

MEDIUM Red Hat CVE published 2026-08-05

CVE-2026-18103

A buffer overflow vulnerability exists in dhcp-server, which could allow a remote attacker to cause a persistent denial of service (DoS). The vulnerability is triggered by a specially crafted lease creation request containing an overly long InfiniBand MAC address, which causes the `print_hw_addr()` function to overflow. This results in the `dhcpd` service crashing and prevents it from restarting without m [truncated]

MEDIUM Red Hat CVE published 2026-08-04

CVE-2026-68743

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

LOW Red Hat CVE published 2026-08-04

CVE-2026-68744

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T06:16:30.490Z and has not been modified since then. The vulnerability affects SSSD, specifically the sss_nss_protocol_fill_initgr() function in the NSS responder, which pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped. This causes uninitialize [truncated]

LOW Red Hat CVE published 2026-08-04

CVE-2026-18739

The CVE-2026-18739 record indicates an off-by-one error in the poptStuffArgs function of the popt library, which can lead to internal program data corruption. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data. The CVSS score is 2.5, with a LOW severity. Red Hat has a reference for this CVE. Affected product [truncated]

LOW Red Hat CVE published 2026-08-04

CVE-2026-18569

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T06:16:30.140Z and has not been modified since then. The keycloak-services component of Red Hat Build of Keycloak has a flaw in its backchannel logout endpoint. When an OIDC identity provider is configured to skip signature validation, the system incorrectly accepts logout requests without cryptog [truncated]

HIGH Red Hat CVE published 2026-08-04

CVE-2026-42169

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specia [truncated]

MEDIUM Red Hat CVE published 2026-08-04

CVE-2026-17614

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T03:16:25.537Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This CVE-2026-17614 vulnerability involves a path traversal flaw in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods do not validate that the [truncated]

MEDIUM Red Hat CVE published 2026-08-03

CVE-2026-18477

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T17:16:33.897Z and has not been modified since then. This CVE-2026-18477 vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows local attackers with write access to influence the restore process. During restoration, files or directories may be created, renamed, or overwritten ou [truncated]

MEDIUM Red Hat CVE published 2026-08-03

CVE-2026-18651

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account th [truncated]

MEDIUM Red Hat CVE published 2026-08-03

CVE-2026-18508

A flaw in GNU tar allows crafted archives to create hardlinks that escape the intended boundary when extracting with the --one-top-level option, potentially allowing writing outside that boundary during a single extraction. This vulnerability, CVE-2026-18508, occurs when hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A [truncated]