See how red hat compares to other vendors in security performance
Moderate: Red Hat Certificate System 10.4.4 security and bug fix update for RHEL 8
Moderate: gstreamer1-plugins-base security update
A denial-of-service vulnerability was discovered in skupper-router within the AMQP field parser. The flaw is caused by unbounded recursion when processing deeply nested or specially crafted AMQP messages, leading to a stack overflow. An attacker who can send messages to the router can trigger this crash. Exploitation requires the attacker to possess a valid x.509 certificate signed by the Red Hat Service Interconnect network's certificate authority. Successful exploitation results in the skupper-router process crashing, terminating all active connections and preventing new traffic from being routed through the affected node.
A denial-of-service vulnerability was discovered in skupper-router within the AMQP field parser. The flaw is caused by unbounded recursion when processing deeply nested or specially crafted AMQP messages, leading to a stack overflow. An attacker who can send messages to the router can trigger this crash. Exploitation requires the attacker to possess a valid x.509 certificate signed by the Red Hat Service Interconnect network's certificate authority. Successful exploitation results in the skupper-router process crashing, terminating all active connections and preventing new traffic from being routed through the affected node.
Moderate: gstreamer1-plugins-good security update
Moderate: gstreamer1-plugins-good security update
A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.
Moderate: glib2 security update
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
Reported privately by Dmitry Maranik (Sectum AI) via PSIRTSUPT-22896. Confirmed by source review of opendatahub-io/odh-dashboard at HEAD (backend/src/routes/api/nim-serving/index.ts). Not reproduced against a live RHOAI + NGC deployment. Preconditions: authenticated dashboard access and a NIM Account CR with the referenced Secrets present.
PCS (Pacemaker Configuration System) has an arbitrary file read vulnerability in the pcs host auth --token <path> command path. When a non-root user in the 'haclient' group runs this command, the nonrootrun() function in pcs/app.py forwards it to the locally running pcsd daemon via HTTP POST to /runpcs. The pcsd daemon (running as root) matches the command against its allowedcommands list in pcsd/pcsd.rb (['host', 'auth', '...']) with no restriction on --token, and re-executes PCS as root. This causes utils.gettokenfromfile() in pcs/utils.py to open and read the attacker-specified file path with root privileges, reading up to 256 bytes. The file contents are base64-encoded and stored as a token in the known-hosts configuration file. The attacker can exfiltrate the file contents by triggering node communication (e.g., pcs pcsd status) and intercepting the HTTP Cookie header containing the base64-encoded token.
Affected: PCS versions from 0.10.8 onwards (introduced in commit 9178b78d11baa70e700a5c0d9fc1c17f27d452fa). RHEL 8.4+, RHEL 9.0+, and RHEL 10.0+ ship affected PCS versions.
Fix: Upstream patch attached to PSIRTSUPT-22935 (commit b41eaf3c6e2ecfc575c42442fb02b8ef05b4dd6a, not yet on public GitHub main). Blocks pcs host auth --token for non-root users in both pcs/app.py and pcsd/pcsd.rb.
Reporter: Peter Romancik (PCS upstream developer, Red Hat). PSIRT ticket: PSIRTSUPT-22935
Moderate: gstreamer1-plugins-good security update
Moderate: wget security, bug fix, and enhancement update
Moderate: wget security, bug fix, and enhancement update
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.Security Fix(es): libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843) libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844) libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845) libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846) libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847) libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848) libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: pam security update
Moderate: pam security update
Moderate: pam security update
Moderate: pam security update
Moderate: pam security update
Moderate: pam security update
Moderate: pam security update
Moderate: libxml2 security update