Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (15)
📋 Description
CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8925 — curl: curl: Double-free vulnerability in SASL authentication CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8927 — curl: Information disclosure due to uncleared proxy authentication state CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-9080 — libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback CVE-2026-9546 — libcurl: libcurl: Information disclosure due to persistent Referer header CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-11352 — curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability CVE-2026-11564 — libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse CVE-2026-11586 — curl: curl: Denial of Service via WebSocket PING flood CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse CVE-2026-12064 — curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:29017
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-12064
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-8286
- externalhttps://access.redhat.com/security/cve/CVE-2026-11352
- externalhttps://access.redhat.com/security/cve/CVE-2026-11586
- externalhttps://access.redhat.com/security/cve/CVE-2026-9079
- externalhttps://access.redhat.com/security/cve/CVE-2026-8926
- externalhttps://access.redhat.com/security/cve/CVE-2026-9546
- externalhttps://access.redhat.com/security/cve/CVE-2026-8927
- externalhttps://access.redhat.com/security/cve/CVE-2026-8925
- externalhttps://access.redhat.com/security/cve/CVE-2026-11564
- externalhttps://access.redhat.com/security/cve/CVE-2026-9080
- externalhttps://access.redhat.com/security/cve/CVE-2026-8458
- externalhttps://access.redhat.com/security/cve/CVE-2026-11856
- externalhttps://access.redhat.com/security/cve/CVE-2026-8924
- externalhttps://access.redhat.com/security/cve/CVE-2026-8932
- externalhttps://access.redhat.com/security/cve/CVE-2026-9547
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_29017.json