CoreOS Security Update (MINDBREEZE42044)
ID: MINDBREEZE42044
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: 7.4 High
Status: Final
First published: August 5, 2026
CVEs: CVE-2025-13151, CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965, CVE-2026-3836, CVE-2026-35535
Summary
- libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
- curl: use after free in SMB connection reuse
- curl: wrong proxy connection reuse with credentials
- curl: token leak with redirect and netrc
- curl: bad reuse of HTTP Negotiate connection
- dnf: crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client
- sudo: Privilege escalation due to failure in privilege drop
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.3 Release
- Mindbreeze InSpire SaaS 26.3 Release