CoreOS Security Update (MINDBREEZE43016)
ID: MINDBREEZE43016
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: Critical
Status: Final
First published: September 9, 2026
CVEs: CVE-2026-34040,CVE-2026-33997,CVE-2026-33747,CVE-2026-33748,CVE-2026-35535,CVE-2026-5450,CVE-2026-5928,CVE-2026-5435,CVE-2026-40355,CVE-2026-40356,CVE-2026-41163,CVE-2026-42014,CVE-2026-42013,CVE-2026-42012,CVE-2026-42011,CVE-2026-3833,CVE-2026-42010,CVE-2026-33845,CVE-2026-42009,CVE-2026-5419,CVE-2026-3832,CVE-2026-42015,CVE-2026-5260,CVE-2026-33846,CVE-2026-40170,CVE-2026-34986,CVE-2026-4878,CVE-2026-6238,CVE-2026-4046,CVE-2026-34180,CVE-2026-42766,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076,CVE-2026-34181,CVE-2026-34182,CVE-2026-34183,CVE-2026-35188,CVE-2026-42764,CVE-2026-42765,CVE-2026-42767,CVE-2026-42768,CVE-2026-42769,CVE-2026-42770,CVE-2026-45445,CVE-2026-45446,CVE-2026-46243,CVE-2025-10263,CVE-2026-4426,CVE-2026-5121,CVE-2026-46242,CVE-2026-53359,CVE-2026-64600,FEDORA-2026-7ae597d1d2,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,FEDORA-2026-bc20b091a8,FEDORA-2026-2b07c67f06,FEDORA-2026-4ef690dc30,FEDORA-2026-75599531db,CVE-2026-2291,CVE-2026-4890,CVE-2026-4891,CVE-2026-4892,CVE-2026-4893,CVE-2026-5172,CVE-2026-4111,CVE-2026-41989,CVE-2026-32316,CVE-2026-39956,CVE-2026-33947,CVE-2026-40164,CVE-2026-39979,CVE-2026-6842,CVE-2026-6843,FEDORA-2026-2dd8b600bb,CVE-2026-53362,CVE-2026-53366,FEDORA-2026-2b94d8d05c
Summary
- bubblewrap: Privilege escalation if setuid root via ptrace
- BuildKit: Arbitrary file write and code execution via untrusted frontend
- BuildKit: Unauthorized file access via Git URL fragment subdir components
- dnsmasq: Broken ECS source validation bypass
- dnsmasq: DHCPv6 CLID buffer overflow in helper process
- dnsmasq: dnsmasq: heap buffer overflow in cache via NAME_ESCAPE expansion
- dnsmasq: extract_addresses() OOB read via malformed rdlen
- dnsmasq: NSEC bitmap parsing infinite loop
- dnsmasq: RRSIG rdlen underflow leading to heap OOB read
- glibc: Application crash or uninitialized memory read via crafted DNS response
- glibc: Denial of Service via iconv() function with specific character sets
- glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width
- glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
- glibc: Out-of-bounds write via TSIG record processing
- gnutls: authentication bypass
- gnutls: certificate misuse
- gnutls: heap overread
- gnutls: heap overrun
- gnutls: heap overwrite
- gnutls: name constraint bypass
- gnutls: out of bounds write
- gnutls: revocation bypass
- gnutls: timing side-channel
- gnutls:undefined behaviour
- gnutls: use-after-free
- jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow
- jq: Denial of Service via crafted JSON object causing hash collisions
- jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure
- jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted()
- kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources
- kernel builds contain a fix for an unprivileged container / jail escape.
- kernel: CIFS Upcall Privilege Escalation
- kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
- kernel: local privilege escalation (bad epoll)
- libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
- libarchive: Denial of Service via malformed ISO file processing
- libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive
- libcap: Local Privilege Escalation (LPE) via TOCTOU race condition in cap_set_file() through file capability injection
- libmount: fd_target TOCTOU prevention
- libmount: SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy\
- libmount: TOCTOU attack via ancestor directory swap during\
- lLibgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
- MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism
- MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
- moby-engine: Off-by-one error in its plugin privilege validation
- moby-engine: AuthZ plugin bypass when provided oversized request bodies
- nano: Format string vulnerability leads to Denial of Service
- nano: Local attacker can inject malicious .desktop launcher due to insecure directory permissions
- ngtcp2: qlog_parameters_set_transport_params_stack_overflow
- OpenSSL: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension triggering a double-free in the client's certificate verification path.
- OpenSSL: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.
- OpenSSL: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.
- OpenSSL: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.
- OpenSSL: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.
- OpenSSL: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.
- OpenSSL: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers leading to various potential compromises.
- OpenSSL: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.
- OpenSSL: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.
- OpenSSL: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.
- OpenSSL: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.
- OpenSSL: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.
- OpenSSL: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.
- OpenSSL: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface the application-supplied initialisation vector (IV) is silently discarded.
- OpenSSL: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor crashing the process.
- OpenSSL: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().
- OpenSSL: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key the peer key is not properly checked for the subgroup membership.
- Sudo: Privilege escalation due to failure in privilege drop
- xfs: resample the data fork mapping after cycling ILOCK
- kernel: ipv6 frag escape
- kernel: ipv4: account for fraggap on the paged allocation path
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.5 Release
- Mindbreeze InSpire SaaS 26.5 Release