Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8925 — curl: curl: Double-free vulnerability in SASL authentication CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8927 — libcurl: libcurl: Information disclosure due to uncleared proxy authentication state CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-9080 — libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback CVE-2026-9546 — libcurl: libcurl: Information disclosure due to persistent Referer header CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-11352 — curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability CVE-2026-11564 — libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse CVE-2026-11586 — curl: curl: Denial of Service via WebSocket PING flood CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse CVE-2026-12064 — curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP CVE-2026-14683 — HdrHistogram: HdrHistogram: Denial of Service via uncontrolled memory allocation CVE-2026-14684 — org.hdrhistogram/HdrHistogram: HdrHistogram: HdrHistogram: Denial of Service via uncontrolled memory allocation in decodeFromByteBuffer CVE-2026-14685 — HdrHistogram: HdrHistogram: Local state issue via 'Count' argument manipulation CVE-2026-14686 — HdrHistogram: HdrHistogram: Data integrity impact due to incorrect comparison CVE-2026-15187 — enquirer: Enquirer: Prototype pollution vulnerability allows remote attackers to modify object attributes CVE-2026-38969 — webrick: rubygem-webrick: WEBrick: Request smuggling via re-parsing of Content-Length header CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2026:34975
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-38969
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-12064
- externalhttps://access.redhat.com/security/cve/CVE-2026-8286
- externalhttps://access.redhat.com/security/cve/CVE-2026-11352
- externalhttps://access.redhat.com/security/cve/CVE-2026-11586
- externalhttps://access.redhat.com/security/cve/CVE-2026-9079
- externalhttps://access.redhat.com/security/cve/CVE-2026-8926
- externalhttps://access.redhat.com/security/cve/CVE-2026-9546
- externalhttps://access.redhat.com/security/cve/CVE-2026-8927
- externalhttps://access.redhat.com/security/cve/CVE-2026-8925
- externalhttps://access.redhat.com/security/cve/CVE-2026-11564
- externalhttps://access.redhat.com/security/cve/CVE-2026-9080
- externalhttps://access.redhat.com/security/cve/CVE-2026-8458
- externalhttps://access.redhat.com/security/cve/CVE-2026-11856
- externalhttps://access.redhat.com/security/cve/CVE-2026-8924
- externalhttps://access.redhat.com/security/cve/CVE-2026-14683
- externalhttps://access.redhat.com/security/cve/CVE-2026-14685
- externalhttps://access.redhat.com/security/cve/CVE-2026-14686
- externalhttps://access.redhat.com/security/cve/CVE-2026-8932
- externalhttps://access.redhat.com/security/cve/CVE-2026-9547
- externalhttps://access.redhat.com/security/cve/CVE-2026-14684
- externalhttps://access.redhat.com/security/cve/CVE-2026-59870
- externalhttps://access.redhat.com/security/cve/CVE-2026-59868
- externalhttps://access.redhat.com/security/cve/CVE-2026-15187
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_34975.json