PatchSiren

Red Hat CVE debriefs · Page 9

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Red Hat CVE published 2026-07-30

CVE-2026-16524

The CVE-2026-16524 vulnerability is a command injection flaw in PCP's linux_sockets PMDA, allowing malicious shell metacharacters via the network.persocket.filter metric. This flaw lets attackers execute arbitrary commands as the PMDA user when metrics refresh. The vulnerability affects systems using PCP's linux_sockets PMDA and requires patching to prevent potential command injection attacks. Organizatio [truncated]

HIGH Red Hat CVE published 2026-07-29

CVE-2026-18255

A flaw in Red Hat Quay allows a read-only superuser to view robot account tokens for repositories they are not a member of. This could enable impersonation of any robot account, potentially leading to unauthorized access and other security issues. Defenders should assess exposure and impact, and review access controls to prevent unauthorized access to robot account tokens. The CVE record and NVD entry pro [truncated]

MEDIUM Red Hat CVE published 2026-07-29

CVE-2026-18207

A flaw in Keycloak's client policy enforcement mechanism allows an attacker with client management privileges to potentially bypass security policies. The issue arises from group membership checks by name instead of a unique identifier, enabling an attacker to join a group with a matching name in a different part of the group hierarchy. This could allow unauthorized client registration or updates without [truncated]

MEDIUM Red Hat CVE published 2026-07-29

CVE-2026-18201

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T10:16:40.620Z and has not been modified since then. Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without [truncated]

HIGH Red Hat CVE published 2026-07-28

CVE-2026-18107

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical [truncated]

HIGH Red Hat CVE published 2026-07-28

CVE-2026-16313

A flaw in sg3_utils allows an attacker to inject arbitrary properties into the udev device database when a crafted SCSI device is presented, potentially leading to arbitrary command execution as root when the device is disconnected. This vulnerability, CVE-2026-16313, is a high-severity issue that system administrators and security teams should prioritize for mitigation, especially in Red Hat Enterprise L [truncated]

HIGH Red Hat CVE published 2026-07-28

CVE-2026-49332

A flaw in openshift/oauth-proxy allows an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. This issue is specific to the handling of dash-variant and underscore-variant keys in headers. The vulnerability can be exploited by an attacker with low privileges, potentially leading to unauthorized access or privile [truncated]

MEDIUM Red Hat CVE published 2026-07-27

CVE-2026-15003

A flaw was found in the GNU Binutils linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due [truncated]

HIGH Red Hat CVE published 2026-07-27

CVE-2026-17527

A vulnerability in containerized-data-importer (CDI) allows unauthorized data exfiltration from any PVC in a cluster. Users or service accounts with the aggregated cdi.kubevirt.io:view ClusterRole and write access to any single namespace can bypass namespace isolation and the read-only guarantee of the view role. This vulnerability stems from the cdi.kubevirt.io:view ClusterRole including a rule granting [truncated]

HIGH Red Hat CVE published 2026-07-27

CVE-2026-17523

A flaw was found in the kernel that allows an unprivileged local user to execute arbitrary code within the kernel, leading to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected Linux-based system. The vulnerability is caused by a flaw in the kernel that allows an unprivileged local user to execute arbitrary code. The affected product [truncated]

MEDIUM Red Hat CVE published 2026-07-24

CVE-2026-66339

A flaw was found in libsoup, a library used for HTTP communication. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure. The vulnerability has a CVSS score of [truncated]

MEDIUM Red Hat CVE published 2026-07-24

CVE-2026-66337

CVE-2026-66337 is a MEDIUM severity vulnerability in libsoup, caused by an unsigned integer underflow in the soup_filter_input_stream_read_until() function. This flaw can cause a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory. [truncated]

MEDIUM Red Hat CVE published 2026-07-24

CVE-2026-17059

A flaw was found in the role-users endpoint of the keycloak-services library, a core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users t [truncated]

MEDIUM Red Hat CVE published 2026-07-24

CVE-2026-17048

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T14:16:26.493Z and has not been modified since then. This vulnerability affects Keycloak deployments using the Admin REST API for client secret management. The issue allows a delegated administrator with view-only permissions to retrieve actual resolved secrets from a secure vault due to improper [truncated]

MEDIUM Red Hat CVE published 2026-07-24

CVE-2026-16730

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T12:16:47.717Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects dbus-broker, causing it to exit when the process file-descriptor limit is reached, leading to potential service denial to the desktop session. Local attackers can exploit t [truncated]

HIGH Red Hat CVE published 2026-07-23

CVE-2026-64611

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T11:16:40.680Z and has not been modified since then. The vulnerability affects libcupsfilters, specifically the cfIEEE1284NormalizeMakeModel() function, which enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field. This leads to sustained CPU con [truncated]

HIGH Red Hat CVE published 2026-07-23

CVE-2026-16745

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T11:16:40.043Z and has not been modified since then. The vulnerability, identified as CVE-2026-16745, affects the odh-dashboard component of Red Hat OpenShift AI (RHOAI). It allows a malicious actor within the cluster to bypass authentication and impersonate any user by providing an arbitrary acce [truncated]

MEDIUM Red Hat CVE published 2026-07-23

CVE-2026-6390

CVE-2026-6390 is a medium-severity vulnerability in GNU nano's multi-buffer error message handling. A specially crafted filename can lead to stack information disclosure, denial of service, or potential arbitrary memory writes. This flaw occurs when a user opens multiple files at startup and one triggers an ALERT-level error. The vulnerability is caused by reinterpretation of printf format specifiers in filenames.

MEDIUM Red Hat CVE published 2026-07-22

CVE-2026-16560

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation. This flaw has a medium severity and users of Directory Server (389-ds-base) should be aware of this vulnerability and take s [truncated]

HIGH Red Hat CVE published 2026-07-22

CVE-2026-44191

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing [truncated]

MEDIUM Red Hat CVE published 2026-07-22

CVE-2026-44192

A path traversal vulnerability was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This flaw allows an attacker to manipulate an AI agent through indirect prompt injection, potentially leading to sensitive host information exposure and malicious command execution. The vulnerability has a CVSS score of 6.6 and is classified as medium severity. Users of Ansible Lightspeed Model Context [truncated]

HIGH Red Hat CVE published 2026-07-22

CVE-2026-44190

A Command Injection vulnerability was found in the Ansible Lightspeed Visual Studio Code extension. The issue arises from the `ansible.python.activationScript` setting, which does not properly validate user input as a file path. This allows a remote attacker to execute unauthorized commands on a user's system by exploiting a specially crafted project. The vulnerability has a CVSS score of 7.8 and is class [truncated]

HIGH Red Hat CVE published 2026-07-22

CVE-2026-44189

A high-severity command injection vulnerability was found in the Visual Studio Code Ansible Lightspeed extension. The flaw exists in the AnsiblePlaybookRunProvider, allowing an attacker to craft a malicious playbook filename with special characters. These characters are not properly sanitized when a victim runs the playbook, leading to arbitrary code execution with the privileges of the user running VS Co [truncated]

LOW Red Hat CVE published 2026-07-22

CVE-2026-44187

The Ansible Lightspeed extension for Visual Studio Code contains a flaw that allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. This is due to the insecure storage of the API key in plain text within the user's configuration file and its writing to output log files. The vulnerability has a CVSS score of 3.3 and a sever [truncated]

MEDIUM Red Hat CVE published 2026-07-22

CVE-2026-16544

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe [truncated]

LOW Red Hat CVE published 2026-07-21

CVE-2026-16517

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potentia [truncated]

MEDIUM Red Hat CVE published 2026-07-21

CVE-2026-12548

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application using libsoup or potentially disclose heap memory contents.

HIGH Red Hat CVE published 2026-07-21

CVE-2026-16493

CVE-2026-16493 is a HIGH severity vulnerability in ansible-core. The _extract_collection_from_git() function constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user run [truncated]

HIGH Red Hat CVE published 2026-07-21

CVE-2026-59851

CVE-2026-59851 is a HIGH severity vulnerability in libssh that allows authenticated clients to log in as arbitrary users. The flaw is found in the gssapi-keyex path when GSSAPIKeyExchange is enabled, and it does not verify whether the authenticated Kerberos principal is authorized for the requested local user. This vulnerability has significant implications for system administrators and security teams res [truncated]

MEDIUM Red Hat CVE published 2026-07-21

CVE-2026-59850

A flaw was found in libssh, a popular SSH library. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed. This can lead to crashes or possible use-after-free conditions, potentially impacting confidentiality, integrity, or availability. Users should review libssh configurations and apply patches or updates provided b [truncated]