RHSA-2026:25044HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.16.64 bug fix and security update

Published
June 18, 2026
Last Modified
July 19, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-35385 — OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode CVE-2026-39979 — jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers CVE-2026-40164 — jq: jq: Denial of Service via crafted JSON object causing hash collisions CVE-2026-41035 — rsync: Rsync: Use-after-free vulnerability in extended attribute handling CVE-2026-43503 — kernel: net: skbuff: propagate shared-frag marker through frag-transfer helpers CVE-2026-46037 — kernel: ipv4: icmp: validate reply type before using icmp_pointers CVE-2026-46300 — kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel

🔗 References (10)