RHSA-2026:32974HighCVSS 8.2
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-47262 — github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing CVE-2026-53489 — github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:32974
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-47262
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-53492
- externalhttps://access.redhat.com/security/cve/CVE-2026-53489
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_32974.json