Skip to content
Red HatCVE-2026-16254

Red Hat claircore: denial of service

Medium4.3CVE-2026-16254 · Published Jul 20, 2026 · updated Jul 21, 2026

A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Advanced Cluster Security 4
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Quay 3
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-125

More Red Hat advisories

All Red Hat
Advisory
Red Hat libcupsfilters: denial of service
High7.5Jul 20
Red Hat Enterprise Linux 10: stack buffer overflow
Medium6.5Jul 20
Red Hat: path traversal
Critical9.0Jul 20
Red Hat Enterprise Linux 10: race condition
High7.3Jul 20
Red Hat: denial of service
Medium5.3Jul 20
Red Hat Enterprise Linux 10: out-of-bounds write
Medium6.5Jul 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.