Red Hat Hardened Images

66 known vulnerabilities in Red Hat Hardened Images, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105326 CVSS 2.5 low An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription…
  • CVE-2026-95512 CVSS 5.5 medium A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a…
  • CVE-2026-103242 CVSS 7.1 high A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared…
  • CVE-2026-95520 CVSS 7.1 high A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared…
  • CVE-2026-102010 CVSS 7.0 high A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library…
  • CVE-2026-95521 CVSS 7.8 high A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro…
  • CVE-2026-95519 CVSS 7.8 high A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or…
  • CVE-2026-88840 CVSS 5.3 medium BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
  • CVE-2026-88839 CVSS 6.7 medium BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
  • CVE-2026-88837 CVSS 6.5 medium BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
  • CVE-2026-88835 CVSS 6.1 medium BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.
  • CVE-2026-88831 CVSS 5.3 medium BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no…
  • CVE-2026-88832 CVSS 7.3 high BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing…
  • CVE-2026-88830 CVSS 7.5 high A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a…
  • CVE-2026-96512 CVSS 7.8 high A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the…
  • CVE-2026-95619 CVSS 7.7 high A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library…
  • CVE-2026-93653 CVSS 5.5 medium A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary…
  • CVE-2026-76781 CVSS 5.5 medium A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference…
  • CVE-2026-92925 CVSS 7.1 high A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to…
  • CVE-2026-42784 CVSS 7.4 high A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is…
  • CVE-2025-11395 CVSS 5.5 medium A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host…
  • CVE-2026-85234 CVSS 7.5 high A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom…
  • CVE-2026-79705 CVSS 4.5 medium A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing…
  • CVE-2026-79699 CVSS 4.4 medium A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can…
  • CVE-2026-85013 CVSS 7.3 high A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a…
  • CVE-2026-18495 CVSS 6.1 medium A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when…
  • CVE-2026-88265 CVSS 5.6 medium A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio…
  • CVE-2026-88264 CVSS 5.6 medium A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console…
  • CVE-2026-84042 CVSS 7.8 high A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun…
  • CVE-2026-87876 CVSS 3.0 low Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL…