Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-19519

PUBLISHED 13.08.2026

CNA: redhat

Claircore: claircore: denial of service via unchecked type assertion in rpm header parser

Обновлено: 13.08.2026
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.

CWE

Идентификатор Описание
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

CVSS

Оценка Severity Версия Базовый вектор
4.3 MEDIUM 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.27% LOW 19.17 30.08.2026

Доп. Информация

Product Status

Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Advanced Cluster Security 4
Product: Red Hat Advanced Cluster Security 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:advanced_cluster_security:4
Red Hat Quay 3
Product: Red Hat Quay 3
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:quay:3
Red Hat Quay 3
Product: Red Hat Quay 3
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:quay:3
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 11.08.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no partial 2.0.3 11.08.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.