Red Hat Product Errata RHSA-2026:25251 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25251 - Security Advisory Overview Updated Packages Synopsis Important: containernetworking-plugins security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url CVEs CVE-2025-61726 CVE-2025-61729 CVE-2025-68121 CVE-2026-25679 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 x86_64 containernetworking-plugins-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: d3261c404b113b9eb7101e7e7c96b89f9d64f3dd87ed7d5a91f84f52d50278fd containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: 511ad7de9590c6fbd39f9634b44211ded781d1a56481be2442f84294d3bbdd55 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: 052655397086f65dfe44e8bc1b2dc8b4c9c71352b065a160b0ed8fff4763eff6 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 ppc64le containernetworking-plugins-1.2.0-3.el9_2.3.ppc64le.rpm SHA-256: bc942f1c94ff938d7b5a93d74ca917109cc3a52c87bc1fb996be055489473c5c containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.ppc64le.rpm SHA-256: cbf7d7e94897dafa9504ff72abc63db2802bf436a70946c1942992112aba470b containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.ppc64le.rpm SHA-256: 15d62115bcb3e415ce57033b98dc352eeeb46f1505ed79b9d869227c17644a37 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 x86_64 containernetworking-plugins-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: d3261c404b113b9eb7101e7e7c96b89f9d64f3dd87ed7d5a91f84f52d50278fd containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: 511ad7de9590c6fbd39f9634b44211ded781d1a56481be2442f84294d3bbdd55 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: 052655397086f65dfe44e8bc1b2dc8b4c9c71352b065a160b0ed8fff4763eff6 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 aarch64 containernetworking-plugins-1.2.0-3.el9_2.3.aarch64.rpm SHA-256: 2d51cb2d312ebeab4ac7c3bcf0587145437f0c63591c4ad80cff49727a8e5990 containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.aarch64.rpm SHA-256: 89a8600e15e7ef0a9a1f365525ea146adde3bb88b964a2606c6a4bf382a3de70 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.aarch64.rpm SHA-256: e99edd7c8c15caf21f80dee03a28fa210d7644ce982115530b8f32e46afd3795 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 s390x containernetworking-plugins-1.2.0-3.el9_2.3.s390x.rpm SHA-256: 54d92401d289b05566baef70628510926008efb8db3ee056b3cfac8e3412ae1b containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.s390x.rpm SHA-256: 9df60539e17f58f7fb1da31593122f8d88b14a9bbb2be49ed97b58c478112517 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.s390x.rpm SHA-256: ba207e1c346032fdeb866b62d538efcc57372c9afca584768b278cd4fedd717c Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 x86_64 containernetworking-plugins-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: d3261c404b113b9eb7101e7e7c96b89f9d64f3dd87ed7d5a91f84f52d50278fd containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: 511ad7de9590c6fbd39f9634b44211ded781d1a56481be2442f84294d3bbdd55 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.x86_64.rpm SHA-256: 052655397086f65dfe44e8bc1b2dc8b4c9c71352b065a160b0ed8fff4763eff6 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 aarch64 containernetworking-plugins-1.2.0-3.el9_2.3.aarch64.rpm SHA-256: 2d51cb2d312ebeab4ac7c3bcf0587145437f0c63591c4ad80cff49727a8e5990 containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.aarch64.rpm SHA-256: 89a8600e15e7ef0a9a1f365525ea146adde3bb88b964a2606c6a4bf382a3de70 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.aarch64.rpm SHA-256: e99edd7c8c15caf21f80dee03a28fa210d7644ce982115530b8f32e46afd3795 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 ppc64le containernetworking-plugins-1.2.0-3.el9_2.3.ppc64le.rpm SHA-256: bc942f1c94ff938d7b5a93d74ca917109cc3a52c87bc1fb996be055489473c5c containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.ppc64le.rpm SHA-256: cbf7d7e94897dafa9504ff72abc63db2802bf436a70946c1942992112aba470b containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.ppc64le.rpm SHA-256: 15d62115bcb3e415ce57033b98dc352eeeb46f1505ed79b9d869227c17644a37 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 SRPM containernetworking-plugins-1.2.0-3.el9_2.3.src.rpm SHA-256: 73c892bd0802205fad26c6eabb9cf50cb3377ebeda8b96f020f82e434b50d206 s390x containernetworking-plugins-1.2.0-3.el9_2.3.s390x.rpm SHA-256: 54d92401d289b05566baef70628510926008efb8db3ee056b3cfac8e3412ae1b containernetworking-plugins-debuginfo-1.2.0-3.el9_2.3.s390x.rpm SHA-256: 9df60539e17f58f7fb1da31593122f8d88b14a9bbb2be49ed97b58c478112517 containernetworking-plugins-debugsource-1.2.0-3.el9_2.3.s390x.rpm SHA-256: ba207e1c346032fdeb866b62d538efcc57372c9afca584768b278cd4fedd717c The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This update addresses four vulnerabilities in the containernetworking-plugins package, stemming from flaws in the underlying Go runtime, including a critical TLS session resumption bypass (CVE-2025-68121, CVSS 10.0) and high-severity issues causing resource exhaustion and parsing errors. The vulnerabilities affect systems running Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions with vulnerable versions of the Go-based CNI plugins. Administrators must apply the Red Hat-provided security update to the containernetworking-plugins package as detailed in the advisory.