Red Hat Security Advisory: OpenShift Container Platform 4.19.39 bug fix and security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-4890 — dnsmasq: NSEC bitmap parsing infinite loop
CVE-2026-4891 — dnsmasq: RRSIG rdlen underflow leading to heap OOB read
CVE-2026-4892 — dnsmasq: DHCPv6 CLID buffer overflow in helper process
CVE-2026-4893 — dnsmasq: Broken ECS source validation bypass
CVE-2026-5260 — gnutls: gnutls: Information disclosure via heap overread in RSA key exchange
CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width
CVE-2026-42009 — gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-42010 — gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-42011 — gnutls: gnutls: Security bypass due to incorrect name constraint handling
CVE-2026-42013 — gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:40762
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458516
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2459853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467279
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467437
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467450
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40762.json