VDB
RHSA-2026%3A4943
RHSA-2026%3A4943
PUBLISHED
CVSS 5.5 MEDIUM
An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64 as a component of Red Hat Update Infrastructure 5 | *, *, registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64 |
| Red Hat | registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64 as a component of Red Hat Update Infrastructure 5 | *, *, * |
| Red Hat | registry.redhat.io/rhui5/installer-rhel9@sha256:2c50c87906a1abebf427a70f401c409f1258cb55d2096f517db870ec991cfd7f_amd64 as a component of Red Hat Update Infrastructure 5 | *, *, * |
| Red Hat | Red Hat Update Infrastructure 5 | |
| Red Hat | registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64 | |
| Red Hat | registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64 as a component of Red Hat Update Infrastructure 5 | *, *, registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64 |
| Red Hat | registry.redhat.io/rhui5/rhua-rhel9@sha256:5f1fbf66fb349a7baf066a1216d39989c3b89f18ec5108b96d9643baf4856778_amd64 as a component of Red Hat Update Infrastructure 5 | registry.redhat.io/rhui5/rhua-rhel9@sha256:5f1fbf66fb349a7baf066a1216d39989c3b89f18ec5108b96d9643baf4856778_amd64, registry.redhat.io/rhui5/rhua-rhel9@sha256:5f1fbf66fb349a7baf066a1216d39989c3b89f18ec5108b96d9643baf4856778_amd64, * |
| GnuTLS | GnuTLS | |
| Red Hat | registry.redhat.io/rhui5/rhua-rhel9@sha256:5f1fbf66fb349a7baf066a1216d39989c3b89f18ec5108b96d9643baf4856778_amd64 as a component of Red Hat Update Infrastructure 5 | *, *, * |
| Red Hat | registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64 as a component of Red Hat Update Infrastructure 5 | registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64, registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64, registry.redhat.io/rhui5/haproxy-rhel9@sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3_amd64 |
| Red Hat | registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64 as a component of Red Hat Update Infrastructure 5 | |
| Red Hat | registry.redhat.io/rhui5/installer-rhel9@sha256:2c50c87906a1abebf427a70f401c409f1258cb55d2096f517db870ec991cfd7f_amd64 as a component of Red Hat Update Infrastructure 5 | registry.redhat.io/rhui5/installer-rhel9@sha256:2c50c87906a1abebf427a70f401c409f1258cb55d2096f517db870ec991cfd7f_amd64, registry.redhat.io/rhui5/installer-rhel9@sha256:2c50c87906a1abebf427a70f401c409f1258cb55d2096f517db870ec991cfd7f_amd64, registry.redhat.io/rhui5/installer-rhel9@sha256:2c50c87906a1abebf427a70f401c409f1258cb55d2096f517db870ec991cfd7f_amd64 |
| GnuTLS | gnutls |
Timeline
- Mar 18, 2026 CVE Published
- Sep 5, 2026 CVE Updated
- Sep 5, 2026 Distribution Patch
- Sep 5, 2026 Distribution Patch
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
- Sep 5, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:4943 advisory
- https://access.redhat.com/products/red-hat-update-infrastructure advisory
- https://access.redhat.com/security/cve/CVE-2025-11187 advisory
- https://access.redhat.com/security/cve/CVE-2025-12084 advisory
- https://access.redhat.com/security/cve/CVE-2025-13836 advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 advisory
- https://access.redhat.com/security/cve/CVE-2025-14831 advisory
- https://access.redhat.com/security/cve/CVE-2025-15281 advisory
- https://access.redhat.com/security/cve/CVE-2025-15366 advisory
- https://access.redhat.com/security/cve/CVE-2025-15367 advisory
- https://access.redhat.com/security/cve/CVE-2025-15467 advisory
- https://access.redhat.com/security/cve/CVE-2025-15468 advisory
- https://access.redhat.com/security/cve/CVE-2025-15469 advisory
- https://access.redhat.com/security/cve/CVE-2025-61726 advisory
- https://access.redhat.com/security/cve/CVE-2025-66199 advisory
- https://access.redhat.com/security/cve/CVE-2025-68160 advisory
- https://access.redhat.com/security/cve/CVE-2025-69418 advisory
- https://access.redhat.com/security/cve/CVE-2025-69419 advisory
- https://access.redhat.com/security/cve/CVE-2025-69420 advisory
- https://access.redhat.com/security/cve/CVE-2025-69421 advisory
…and 154 more