HYCU 5.3.0-4138 security updates

This release contains fixes for the following vulnerabilities:

  • RHBA-2026:47115:

    • CVE-2026-56392: coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
  • RHSA-2024:1902:

    • CVE-2023-40546: shim: Out-of-bounds read printing error messages
    • CVE-2023-40547: shim: RCE in http boot support may lead to Secure Boot bypass
    • CVE-2023-40548: shim: Interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems
    • CVE-2023-40549: shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file
    • CVE-2023-40550: shim: Out-of-bound read in verify_buffer_sbat()
    • CVE-2023-40551: shim: out of bounds read when parsing MZ binaries
  • RHSA-2026:10741:

    • CVE-2026-5201: gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
  • RHSA-2026:11077:

    • CVE-2026-4786: python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API
    • CVE-2026-6100: python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules
  • RHSA-2026:11349:

    • CVE-2025-9714: libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c
  • RHSA-2026:11509:

    • CVE-2026-34982: vim: arbitrary command execution via modeline sandbox bypass
  • RHSA-2026:11521:

    • CVE-2026-35535: sudo: Sudo: Privilege escalation due to failure in privilege drop calls
  • RHSA-2026:13285:

    • CVE-2026-4878: libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
  • RHSA-2026:13383:

    • CVE-2026-35385: OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode
    • CVE-2026-35386: OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username
    • CVE-2026-35387: OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage
    • CVE-2026-35388: OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions
    • CVE-2026-35414: OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option
  • RHSA-2026:14087:

    • CVE-2026-5119: libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
  • RHSA-2026:15953:

    • CVE-2025-14087: glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
    • CVE-2025-14512: glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
  • RHSA-2026:16055:

    • CVE-2026-4775: libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
  • RHSA-2026:16252:

    • CVE-2026-39979: jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers
    • CVE-2026-40164: jq: jq: Denial of Service via crafted JSON object causing hash collisions
  • RHSA-2026:16799:

    • CVE-2026-40355: krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism
    • CVE-2026-40356: krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
  • RHSA-2026:17481:

    • CVE-2026-41035: rsync: Rsync: Use-after-free vulnerability in extended attribute handling
  • RHSA-2026:19559:

    • CVE-2026-37555: libsndfile: integer overflow in ima_reader_init()
  • RHSA-2026:20587:

    • CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets
  • RHSA-2026:20611:

    • CVE-2026-3833: gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
    • CVE-2026-5260: gnutls: gnutls: Information disclosure via heap overread in RSA key exchange
    • CVE-2026-33845: gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
    • CVE-2026-33846: gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly
    • CVE-2026-42009: gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
    • CVE-2026-42010: gnutls: gnutls: Authentication Bypass via NUL Character in Username
    • CVE-2026-42011: gnutls: gnutls: Security bypass due to incorrect name constraint handling
    • CVE-2026-42012: gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs
    • CVE-2026-42013: gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name
    • CVE-2026-42014: gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin
    • CVE-2026-42015: gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
  • RHSA-2026:22644:

    • CVE-2026-1933: samba: Missing access check on reparse point operations
    • CVE-2026-2340: samba: vfs_worm does not block directory modification
    • CVE-2026-3012: samba: group policy certificate enrollment uses http:// without validation
    • CVE-2026-4408: samba: Remote Code Execution in SAMR
    • CVE-2026-4480: samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
  • RHSA-2026:22721:

    • CVE-2026-45186: libexpat: denial of service via crafted XML input
  • RHSA-2026:24339:

    • CVE-2026-3039: bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
    • CVE-2026-5946: bind: BIND: Denial of Service via specially crafted DNS messages
  • RHSA-2026:26181:

    • CVE-2026-6472: postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
    • CVE-2026-6473: postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write
    • CVE-2026-6474: postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function
    • CVE-2026-6475: postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind
    • CVE-2026-6477: postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory
    • CVE-2026-6478: postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison
    • CVE-2026-6479: postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation
    • CVE-2026-6637: postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module
  • RHSA-2026:26275:

    • CVE-2024-4741: openssl: Use After Free with SSL_free_buffers
    • CVE-2026-45447: openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
  • RHSA-2026:26354:

    • CVE-2024-34459: libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c
  • RHSA-2026:26355:

    • CVE-2025-10911: libxslt: use-after-free with key data stored cross-RVT
  • RHSA-2026:26408:

    • CVE-2026-29518: rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot.
    • CVE-2026-43618: rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding
  • RHSA-2026:26534:

    • CVE-2026-6893: dracut: dracut: Root code execution via DHCP options command injection
    • CVE-2026-16445: dracut: dracut: Root code execution via DHCP options command injection in NetworkManager initrd module
  • RHSA-2026:28553:

    • CVE-2026-41411: vim: Command injection allows arbitrary code execution via malicious tag files
  • RHSA-2026:29898:

    • CVE-2026-33416: libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
  • RHSA-2026:33126:

    • CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width
  • RHSA-2026:36721:

    • CVE-2025-9230: openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
  • RHSA-2026:36728:

    • CVE-2025-13151: libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
  • RHSA-2026:36730:

    • CVE-2026-48864: libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
  • RHSA-2026:36732:

    • CVE-2026-44431: urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
  • RHSA-2026:36734:

    • CVE-2025-6170: libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
  • RHSA-2026:38503:

    • CVE-2026-28390: openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
  • RHSA-2026:39320:

    • CVE-2026-15308: python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations
  • RHSA-2026:3938:

    • CVE-2025-12801: nfs-utils: rpc.mountd in the nfs-utils privilege escalation
  • RHSA-2026:39575:

    • CVE-2026-12505: cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
  • RHSA-2026:4059:

    • CVE-2026-2003: postgresql: PostgreSQL oidvector discloses a few bytes of memory
    • CVE-2026-2004: postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
    • CVE-2026-2005: postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
    • CVE-2026-2006: postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code
  • RHSA-2026:42090:

    • CVE-2026-58016: glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
  • RHSA-2026:42733:

    • CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing
    • CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
    • CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
  • RHSA-2026:42877:

    • CVE-2026-41254: Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
    • CVE-2026-46968: openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
    • CVE-2026-47010: openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
    • CVE-2026-47021: openjdk: Enhance XBM image support (Oracle CPU 2026-07)
    • CVE-2026-47027: openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
    • CVE-2026-47057: openjdk: Improve Nashorn index handling (Oracle CPU 2026-07)
    • CVE-2026-47058: openjdk: Enhance Dataview Implementation (Oracle CPU 2026-07)
    • CVE-2026-47059: openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
    • CVE-2026-47063: openjdk: Enhance Jar handling (Oracle CPU 2026-07)
    • CVE-2026-60147: openjdk: Improve certification checking (Oracle CPU 2026-07)
  • RHSA-2026:43420:

    • CVE-2026-54369: acl: Symlink traversal privilege escalation via libacl functions
    • CVE-2026-54370: acl: TOCTOU Symlink Traversal via getfacl/setfacl
  • RHSA-2026:4442:

    • CVE-2026-25749: vim: Vim: Arbitrary code execution via 'helpfile' option processing
  • RHSA-2026:4648:

    • CVE-2025-61662: grub2: Missing unregister call for gettext command may lead to use-after-free
  • RHSA-2026:46990:

    • CVE-2026-14474: sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation
    • CVE-2026-14476: sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
  • RHSA-2026:47117:

    • CVE-2026-41989: Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
  • RHSA-2026:47184:

    • CVE-2026-12912: libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image
  • RHSA-2026:4728:

    • CVE-2026-22695: libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
    • CVE-2026-22801: libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
    • CVE-2026-25646: libpng: LIBPNG has a heap buffer overflow in png_set_quantize
  • RHSA-2026:4772:

    • CVE-2025-15281: glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
    • CVE-2026-0915: glibc: glibc: Information disclosure via zero-valued network query
  • RHSA-2026:47755:

    • CVE-2026-55653: openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service
    • CVE-2026-55655: openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions
  • RHSA-2026:53848:

    • CVE-2026-55995: open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder
  • RHSA-2026:54290:

    • CVE-2026-45409: python-idna: idna: Denial of Service via specially crafted long inputs
  • RHSA-2026:54575:

    • CVE-2026-15816: dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()
  • RHSA-2026:54654:

    • CVE-2026-10723: bind: bind9: Incorrect acceptance of NSEC3 records
    • CVE-2026-11622: bind: bind9: Potential memory usage beyond configured limits
    • CVE-2026-11721: bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards
    • CVE-2026-13204: bind: bind9: Unexpected exit with NSEC and NSEC3 both present
    • CVE-2026-13321: bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
  • RHSA-2026:55775:

    • CVE-2026-60589: OpenJDK: Improve Resource Resolving (2026-08 Security Update)
    • CVE-2026-61308: OpenJDK: Enhance HTTP Connections (2026-08 Security Update)
    • CVE-2026-70907: OpenJDK: Enhance TLS server (2026-08 Security Update)
  • RHSA-2026:55804:

    • CVE-2026-58055: nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests
  • RHSA-2026:5585:

    • CVE-2025-9820: gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function
    • CVE-2025-14831: gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
  • RHSA-2026:5588:

    • CVE-2025-0938: python: cpython: URL parser allowed square brackets in domain names
  • RHSA-2026:56130:

    • CVE-2026-16313: sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
  • RHSA-2026:56131:

    • CVE-2026-54411: linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module
  • RHSA-2026:56133:

    • CVE-2026-54371: attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr
  • RHSA-2026:56219:

    • CVE-2026-11940: python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory
  • RHSA-2026:57462:

    • CVE-2026-8286: curl: curl: Insecure connection establishment due to TLS configuration mismatch
  • RHSA-2026:58555:

    • CVE-2026-10805: NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend
  • RHSA-2026:58562:

    • CVE-2026-9323: urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure
  • RHSA-2026:58938:

    • CVE-2026-11822: sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
    • CVE-2026-11824: sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5
  • RHSA-2026:61248:

    • CVE-2026-11979: libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow
  • RHSA-2026:61257:

    • CVE-2026-71217: iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion
  • RHSA-2026:61766:

    • CVE-2026-15588: GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering
    • CVE-2026-58010: glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
    • CVE-2026-58011: glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
    • CVE-2026-58012: glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
    • CVE-2026-58013: glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
    • CVE-2026-58014: glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
    • CVE-2026-58015: glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
  • RHSA-2026:62144:

    • CVE-2026-58469: wget: GNU Wget: Memory corruption via crafted Metalink URL
    • CVE-2026-58471: wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
    • CVE-2026-58472: wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
  • RHSA-2026:62218:

    • CVE-2026-59843: libssh: libssh: denial of service via zero advertised channel packet size
    • CVE-2026-59844: libssh: libssh: denial of service via oversized SFTP read length
    • CVE-2026-59845: libssh: libssh: denial of service via unchecked ProxyCommand fork() failure
    • CVE-2026-59846: libssh: libssh: information disclosure via ProxyCommand %r username expansion
    • CVE-2026-59847: libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification
    • CVE-2026-59848: libssh: libssh: denial of service via SFTP responses with unknown request IDs
    • CVE-2026-59850: libssh: libssh: use-after-free via data callbacks on closed channels
  • RHSA-2026:6436:

    • CVE-2025-10158: rsync: Rsync: Out of bounds array access via negative index
  • RHSA-2026:6461:

    • CVE-2026-3497: openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables
  • RHSA-2026:6473:

    • CVE-2026-4519: python: Python: Command-line option injection in webbrowser.open() via crafted URLs
  • RHSA-2026:64809:

    • CVE-2026-50219: expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
    • CVE-2026-56132: expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
  • RHSA-2026:65147:

    • CVE-2025-31936: kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege escalation via improper memory range handling in SMM
    • CVE-2025-35973: kernel: hypervisor: Intel Processors: Privilege escalation in Ring 0 via improper value handling
  • RHSA-2026:65897:

    • CVE-2026-9499: qt: Qt: Denial of Service via out-of-bounds read in text codec handling
  • RHSA-2026:65998:

    • CVE-2026-41991: gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility
    • CVE-2026-41992: gzip: gzip: Information disclosure via global buffer overflow in LZH decompression
  • RHSA-2026:66451:

    • CVE-2026-16118: xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
  • RHSA-2026:67162:

    • CVE-2026-13221: perl: Perl: Incorrect regular expression processing via large regular expressions
  • RHSA-2026:67266:

    • CVE-2026-71225: libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
    • CVE-2026-71226: libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path
    • CVE-2026-71227: libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
  • RHSA-2026:67908:

    • CVE-2026-63382: libevent: libevent: Multiple HTTP Parser Bugs Enable Request Smuggling
    • CVE-2026-63383: libevent: Libevent: Denial of Service via malformed RPC data
    • CVE-2026-63384: libevent: Libevent: Denial of Service via integer conversion error in evtag_unmarshal_header
    • CVE-2026-63385: libevent: Libevent: HTTP header handling bugs create risk of access control bypass.
    • CVE-2026-63387: libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption
    • CVE-2026-63388: libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
  • RHSA-2026:68266:

    • CVE-2026-15711: libsoup: SoupWebsocketConnection: libsoup: WebSocket remote denial of service via oversized control frame protocol violation
  • RHSA-2026:69095:

    • CVE-2026-52490: libtiff: libtiff: Arbitrary code execution via process_command_opts() function
  • RHSA-2026:69113:

    • CVE-2025-49506: apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
    • CVE-2026-32327: apr-util: Apache Portable Runtime Utility: Denial of Service via XML stack recursion attack
    • CVE-2026-34501: apr-util: Apache Portable Runtime Utility: Heap buffer overflow in redis client
    • CVE-2026-34502: apr-util: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
  • RHSA-2026:69266:

    • CVE-2026-59995: openssh: OpenSSH: sftp client allows attacker to control downloaded file location
    • CVE-2026-59999: openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
    • CVE-2026-73282: openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client
  • RHSA-2026:69655:

    • CVE-2026-6653: libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
  • RHSA-2026:69923:

    • CVE-2026-6464: postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN
    • CVE-2026-6471: postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin
    • CVE-2026-14662: postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions
    • CVE-2026-14664: postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp
    • CVE-2026-14668: postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator
    • CVE-2026-14669: postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation
    • CVE-2026-14670: postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow
    • CVE-2026-14671: postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module
    • CVE-2026-14677: postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl
    • CVE-2026-14679: postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation
    • CVE-2026-14680: postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments
    • CVE-2026-15741: postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse
    • CVE-2026-15742: postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound
    • CVE-2026-16239: postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle
    • CVE-2026-18408: postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump
    • CVE-2026-19385: postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists
  • RHSA-2026:69964:

    • CVE-2025-5278: coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification
  • RHSA-2026:70390:

    • CVE-2025-45582: tar: Tar path traversal
    • CVE-2026-5704: tar: tar: Hidden file injection via crafted archives
    • CVE-2026-18477: tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
    • CVE-2026-18508: tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
  • RHSA-2026:71641:

    • CVE-2026-74860: libxml2: double-free/UAF in libxml2 Python bindings
    • CVE-2026-86138: libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
    • CVE-2026-86140: libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements
    • CVE-2026-86143: libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
    • CVE-2026-86144: libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.
  • RHSA-2026:72448:

    • CVE-2026-66046: expat: Expat: Denial of Service via quadratic complexity in attribute processing
    • CVE-2026-93990: expat: Expat: XML Injection via Malformed UTF-16 Input
  • RHSA-2026:73425:

    • CVE-2026-13732: gdb: gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF
  • RHSA-2026:73511:

    • CVE-2026-40467: gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c
    • CVE-2026-40468: gawk: gawk: Memory corruption via integer overflow
  • RHSA-2026:7667:

    • CVE-2026-27135: nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
  • RHSA-2026:8339:

    • CVE-2026-21710: Node.js: Node.js: Denial of Service due to crafted HTTP __proto__ header
    • CVE-2026-26996: minimatch: minimatch: Denial of Service via specially crafted glob patterns
    • CVE-2026-27135: nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
    • CVE-2026-27904: minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
  • RHSA-2026:8352:

    • CVE-2026-1519: bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
  • RHSA-2026:8534:

    • CVE-2026-4424: libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
    • CVE-2026-5121: libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
  • RHSA-2026:9683:

    • CVE-2026-22007: openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)
    • CVE-2026-22013: openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04)
    • CVE-2026-22016: openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04)
    • CVE-2026-22018: openjdk: Enhance Zip file reading (Oracle CPU 2026-04)
    • CVE-2026-22021: openjdk: Enhance certificate chain validation (Oracle CPU 2026-04)
    • CVE-2026-22695: libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
    • CVE-2026-22801: libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
    • CVE-2026-23865: freetype: Information disclosure or denial of service via specially crafted font files
    • CVE-2026-26740: giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
    • CVE-2026-33416: libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
    • CVE-2026-33636: libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
    • CVE-2026-34268: openjdk: Enhance key generation (Oracle CPU 2026-04)
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.

Articles in this section

See more