CoreOS Security Update (MINDBREEZE42044)

ID: MINDBREEZE42044 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 7.4 High 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2025-13151, CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965, CVE-2026-3836, CVE-2026-35535 

Summary 

  • libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string 
  • curl: use after free in SMB connection reuse 
  • curl: wrong proxy connection reuse with credentials 
  • curl: token leak with redirect and netrc 
  • curl: bad reuse of HTTP Negotiate connection 
  • dnf: crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client 
  • sudo: Privilege escalation due to failure in privilege drop 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.3 Release
  • Mindbreeze InSpire SaaS 26.3 Release