Red Hat Cost Management On Premise
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Cost Management On Premise.
By the Year
In 2026 there have been 5 vulnerabilities in Red Hat Cost Management On Premise with an average score of 6.8 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 5 | 6.78 |
It may take a day or so for new Cost Management On Premise vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Cost Management On Premise Security Vulnerabilities
sequoia-openpgp Key Flag Flaw Allows Subkey Bypass & Signature Forgery
CVE-2026-42784
7.4 - High
- September 16, 2026
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Improper Verification of Cryptographic Signature
libxml2 Python SAX Binding Double-Free DoS CVE-2026-74860
CVE-2026-74860
8.5 - High
- September 08, 2026
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Release of Invalid Pointer or Reference
GDB STABS Debug Format Parser Buffer Overflow in read_member_functions
CVE-2026-13732
7 - High
- August 31, 2026
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
Memory Corruption
XDGMIME Heap Buffer Overflow via MIME Magic File (CVE-2026-16118)
CVE-2026-16118
7.1 - High
- July 17, 2026
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.
Heap-based Buffer Overflow
Heap Overflow in libarchive PAX Header Parsing
CVE-2026-15028
3.9 - Low
- July 10, 2026
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.
Buffer Access with Incorrect Length Value
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Cost Management On Premise or by Red Hat? Click the Watch button to subscribe.