Openshift Red Hat Openshift

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Red Hat Openshift.

Recent Red Hat Openshift Security Advisories

Advisory Title Published
RHSA-2026:67856 (RHSA-2026:67856) Important: OpenShift Container Platform 4.15.69 packages and security update September 24, 2026
RHSA-2026:67837 (RHSA-2026:67837) Moderate: OpenShift Container Platform 4.14.74 bug fix and security update September 24, 2026
RHSA-2026:67935 (RHSA-2026:67935) Important: OpenShift Container Platform 4.16.71 bug fix and security update September 24, 2026
RHSA-2026:70870 (RHSA-2026:70870) Logging for Red Hat OpenShift - 6.5.3 September 23, 2026
RHSA-2026:68534 (RHSA-2026:68534) Important: OpenShift Container Platform 4.19.48 packages and security update September 23, 2026
RHSA-2026:70593 (RHSA-2026:70593) Network Observability 1.12.3 for OpenShift September 23, 2026
RHSA-2026:69945 (RHSA-2026:69945) Red Hat OpenShift Builds 1.8.2 September 22, 2026
RHSA-2026:69942 (RHSA-2026:69942) Red Hat OpenShift Builds 1.9.1 September 22, 2026
RHSA-2026:68550 (RHSA-2026:68550) Important: OpenShift Container Platform 4.22.15 packages and security update September 22, 2026
RHSA-2026:69928 (RHSA-2026:69928) Red Hat OpenShift Builds 1.8.2 September 22, 2026

By the Year

In 2026 there have been 415 vulnerabilities in Red Hat Openshift with an average score of 7.1 out of ten. Last year, in 2025 Openshift had 99 security vulnerabilities published. That is, 316 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.97.




Year Vulnerabilities Average Score
2026 415 7.10
2025 99 6.13
2024 48 6.70
2023 7 6.34
2022 14 6.42
2021 6 5.90
2020 12 6.77
2019 6 6.13
2018 14 6.16

It may take a day or so for new Openshift vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Openshift Security Vulnerabilities

Use-after-Free in QEMU 9pfs Enables VM Escape
CVE-2026-93834 8.8 - High - September 25, 2026

A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.

Dangling pointer

OpenShift Console Path Traversal via lng/ns on /locales/resource.json
CVE-2026-75887 7.5 - High - September 23, 2026

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.

Directory traversal

OpenShift Console CatalogdHandler Auth Bypass & Cookie Forwarding
CVE-2026-75886 7.2 - High - September 23, 2026

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the disclosure of the internal operator-catalog index and providing a relay into the openshift-catalogd namespace.

Confused Deputy

SSSD LDAP ppolicy failopen: Deleted user retains access
CVE-2026-90462 5.4 - Medium - September 22, 2026

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.

Improper Handling of Insufficient Permissions or Privileges

rpcbind DoS via unbounded memory growth
CVE-2026-94640 7.5 - High - September 22, 2026

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.

Resource Exhaustion

Integer Overflow in libstdc++ New Operator Causing Memory Corruption
CVE-2026-95619 7.7 - High - September 22, 2026

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

Integer Overflow or Wraparound

Heap Overflow in libslirp DHCPv6/TFTP Builders Arbitrary Code Exec
CVE-2026-95508 7.4 - High - September 22, 2026

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

Memory Corruption

OpenShift oc-mirror PGP Signature Bypass via Intercepted Signature Endpoint
CVE-2026-75939 7.4 - High - September 21, 2026

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.

Improper Verification of Cryptographic Signature

CRI-O Privilege Escalation via Malicious Checkpoint Restore (before 1.34)
CVE-2026-92574 8.8 - High - September 21, 2026

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.

Execution with Unnecessary Privileges

CRIO chkrestore metadata flaw enabling host FS ops
CVE-2026-15801 8 - High - September 21, 2026

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.

Directory traversal

OpenShift Console Unauth devfile API SSRF/DoS
CVE-2026-75885 9.3 - Critical - September 18, 2026

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).

SSRF

Privilege Escalation via VAPIC Alias Overflow in QEMU
CVE-2026-81627 8.2 - High - September 18, 2026

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRAM, bypassing chipset D_LCK protection and injecting code into System Management Mode memory.

Memory Corruption

libxml2 NULL Pointer Deref in XML Catalog Parsing (DoS)
CVE-2026-76781 5.5 - Medium - September 17, 2026

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).

NULL Pointer Dereference

Redis Community Cluster Bus OOB Read via Unchecked Null-Termination
CVE-2026-92925 7.1 - High - September 17, 2026

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).

Out-of-bounds Read

A flaw was found in sequoia-openpgp
CVE-2026-42784 7.4 - High - September 16, 2026

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.

Improper Verification of Cryptographic Signature

Podman tar load RCE: crafted archive writes files with user privileges
CVE-2025-11395 5.5 - Medium - September 15, 2026

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

Insecure Inherited Permissions

A flaw was found in the containers/storage library
CVE-2026-79699 4.4 - Medium - September 15, 2026

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.

insecure temporary file

A flaw was found in the buildah/copier Go package
CVE-2026-79705 4.5 - Medium - September 15, 2026

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.

Directory traversal

SSSD NSS Responder DoS via Zero-Length Body (CVE-2026-90996)
CVE-2026-90996 4 - Medium - September 14, 2026

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.

Integer underflow

SSSD PAM Responder NULL Deref DoS via Omitted Service Item
CVE-2026-90995 5.5 - Medium - September 14, 2026

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.

NULL Pointer Dereference

Local DoS via Empty PAM Request in sssd v1 Parser
CVE-2026-90994 4 - Medium - September 14, 2026

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.

Out-of-bounds Read

SSSD NSS Responder OOB Read DoS via Crafted Lookups
CVE-2026-90463 4 - Medium - September 14, 2026

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.

Out-of-bounds Read

Red Hat multipathd IPC DoS via blocked listener thread
CVE-2026-89329 6.2 - Medium - September 11, 2026

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.

Use of Blocking Code in Single-threaded, Non-blocking Context

PCS: Local File Disclosure via pcs host auth --token
CVE-2026-84828 6.5 - Medium - September 10, 2026

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.

Incorrect Permission Assignment for Critical Resource

CVE-2026-88265: crun 1.29.1 and below pivot_root stdio symlink issue
CVE-2026-88265 5.6 - Medium - September 10, 2026

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

insecure temporary file

crun 1.29.1: /dev Console Redirect via Terminal Setup Insecure Bind-Mount
CVE-2026-88264 5.6 - Medium - September 10, 2026

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

insecure temporary file

crun 1.29+ Priv Esc via PassNet (libkrun)
CVE-2026-84042 7.8 - High - September 10, 2026

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29

Improper Privilege Management

CUPS Username ACL Bypass via Case-Insensitive Comparisons
CVE-2026-87876 3 - Low - September 09, 2026

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.

Improper Handling of Case Sensitivity

CUPS UTF32ToUTF8 Heap OOB Read via SNMP
CVE-2026-87875 4.3 - Medium - September 09, 2026

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.

Out-of-bounds Read

SSSD IdP OIDC Subject Prefix Auth Flaw
CVE-2026-87853 7.5 - High - September 09, 2026

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

Partial String Comparison

DPDK lib/vhost OOB read in virtio-net controlqueue crash
CVE-2026-86564 3.3 - Low - September 08, 2026

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

Out-of-bounds Read

libxml2 Python SAX Binding Double-Free DoS CVE-2026-74860
CVE-2026-74860 8.5 - High - September 08, 2026

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Release of Invalid Pointer or Reference

Race Condition in GLib2 g_file_replace() Enables File Redirect
CVE-2026-86469 5.3 - Medium - September 07, 2026

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

insecure temporary file

Corosync Int Overflow in Membership Commit Token Msg (CVE-2026-81666)
CVE-2026-81666 6.5 - Medium - September 04, 2026

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.

Integer Overflow or Wraparound

Corosync TotemPG Heap Overflow (CVE-2026-81665)
CVE-2026-81665 7.5 - High - September 04, 2026

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.

Heap-based Buffer Overflow

Linux Kernel 6.15+ X-mount.subdir Symlink Traversal Local PrivEsc
CVE-2026-78409 7 - High - September 02, 2026

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

insecure temporary file

util-linux Local Privilege Escalation via Redirected Restricted Bind Mount
CVE-2026-78410 7.8 - High - September 02, 2026

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

TOCTTOU

CVE-2026-78408: nsenter --join-cgroup root-FD leak allows cgroup migration
CVE-2026-78408 7.9 - High - September 02, 2026

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

Missing Release of File Descriptor or Handle after Effective Lifetime

OpenShift OAuth Server DoS via Crafted Accept-Language Header
CVE-2026-49329 7.5 - High - September 01, 2026

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users.

Inefficient Algorithmic Complexity

popt ConfigFileToString Realloc Heap Corruption (CVE-2026-18743)
CVE-2026-18743 2.5 - Low - September 01, 2026

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

Incorrect Calculation of Buffer Size

OOB Write in libsolv .solv Cache Rewrite Causing DoS
CVE-2026-82327 5.5 - Medium - August 28, 2026

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.

out-of-bounds array index

CRI-O Env Variable Crash via Nil Envs Causes Go Runtime Panic
CVE-2026-17113 6 - Medium - August 24, 2026

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls back to using the target OCI image's `config.Env` entries unfiltered, in contrast to the normal merge path, which validates each entry for a `key=value` form before use. An OCI image whose `config.Env` contains an entry with no `=` character (e.g. a bare `NOEQUALS` string) causes CRI-O to split that entry into a single-element slice and then index its second element, which is out of range. This triggers an unrecovered Go runtime panic in the `crio` daemon process, crashing it and terminating the container-runtime service for all workloads on the node until it is restarted.

Improper Validation of Specified Type of Input

NetworkManager Vulnerable 802-1x.ca-path CA Path Bypass (CVE-2026-19685)
CVE-2026-19685 9.8 - Critical - August 24, 2026

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

AuthZ

rpmbuild Macro Injection via Tar Member Name
CVE-2026-78367 7 - High - August 24, 2026

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).

Code Injection

Kata Containers: Host Operator Elevates Priv via CreateContainer Mount Validation
CVE-2026-77176 8.1 - High - August 20, 2026

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

External Control of File Name or Path

libsoup HTTP Range Header Partial Content Bug (CVE-2026-77014)
CVE-2026-77014 5.3 - Medium - August 20, 2026

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

Numeric Truncation Error

Vim netrw Arbitrary Vimscript via Quote Breakout in Mark/Unmark
CVE-2026-43961 7.8 - High - August 19, 2026

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.

Code Injection

Red Hat Multi-Cloud Operators Subscription PrivEsc via Crafted Annotations
CVE-2026-66792 9.9 - Critical - August 17, 2026

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

AuthZ

dnsmasq dnssec.c infinite loop DoS (CVE-2026-13002)
CVE-2026-13002 4.4 - Medium - August 14, 2026

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.

Infinite Loop

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Red Hat Openshift or by Red Hat? Click the Watch button to subscribe.

Red Hat
Vendor

subscribe