VDB

ESB-2026.3268

ESB-2026.3268 PUBLISHED CVSS 9.800000190734863 CRITICAL

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.3268 Updated service-interconnect rhel9 container images for 1.8 7 April 2026 =========================================================================== AUSCERT Security Bulletin Summary --------------------------------- Product: service-interconnect rhel9 container images Publisher: Red Hat Operating System: Red Hat Resolution: Patch/Upgrade CVE Names: CVE-2026-4111 CVE-2025-68973 CVE-2025-6965 CVE-2025-15467 Original Bulletin: https://access.redhat.com/errata/RHSA-2026:6481 Comment: CVSS (Max): 9.8 CVE-2025-15467 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVSS Source: Red Hat Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H EPSS (Max): 0.8% (74th) CVE-2025-15467 2026-04-02 - --------------------------BEGIN INCLUDED TEXT-------------------- RHSA-2026:6481 - Security Advisory Issued: 2026-04-02 Updated: 2026-04-02 Synopsis Updated service-interconnect rhel9 container images for 1.8 Type/Severity Security Advisory: Important Topic Updated service-interconnect container images are now available for Service Interconnect 1.8 for RHEL 9. Description Users of service-interconnect 1.8 rhel9 container images are advised to upgrade to these updated images, which contain backported patches to correct security issues and fix bugs. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory in the Red Hat Container Catalog Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products o Red Hat Service Interconnect 1 for RHEL 9 x86_64 o Red Hat Service Interconnect 1 for RHEL 9 s390x o Red Hat Service Interconnect 1 for RHEL 9 aarch64 Fixes o BZ - 2380149 - CVE-2025-6965 sqlite: Integer Truncation in SQLite o BZ - 2425966 - CVE-2025-68973 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write o BZ - 2430376 - CVE-2025-15467 openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing o BZ - 2446453 - CVE-2026-4111 libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive CVEs o CVE-2025-6965 o CVE-2025-15467 References o https://access.redhat.com/security/updates/classification/#important - --------------------------END INCLUDED TEXT---------------------- You have received this e-mail bulletin as a result of your organisation's registration with AUSCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AUSCERT's members. As AUSCERT did not write the document quoted above, AUSCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AUSCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://portal.auscert.org.au/bulletins/ =========================================================================== AUSCERT The University of Queensland, Brisbane QLD 4072 Australia e: auscert@auscert.org.au t: +61 (0)7 3365 4417 Allies in Cyber Security ===========================================================================

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatservice-interconnect rhel9 container images

Timeline

  • Apr 7, 2026 CVE Published
  • Apr 7, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›