Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:27076: Important: Satellite 6.16.9 Async Update

This Important update for Red Hat Satellite 6.16 addresses multiple vulnerabilities, including a denial-of-service flaw in python-pillow via crafted FITS images (CVE-2026-40192), privilege escalation through symlink traversal in yggdrasil-worker-forwarder and dynflow-utils (CVE-2026-32282), and an authorization bypass in gRPC-Go due to improper HTTP/2 path validation (CVE-2026-33186). The advisory applies to Satellite 6.16 running on RHEL 8 and RHEL 9, and it is resolved by applying the Satellite 6.16.9 async update.
Read Full Article →

Red Hat Product Errata RHSA-2026:27076 - Security Advisory Issued: 2026-06-18 Updated: 2026-06-18 RHSA-2026:27076 - Security Advisory Overview Updated Packages Synopsis Important: Satellite 6.16.9 Async Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Satellite 6.16 for RHEL 8 and RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): python-pillow: Pillow: Denial of Service via decompression bomb in FITS image processing (CVE-2026-40192) yggdrasil-worker-forwarder: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) dynflow-utils: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) satellite:el8/yggdrasil-worker-forwarder: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) yggdrasil-worker-forwarder: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) yggdrasil-worker-forwarder: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) satellite:el8/yggdrasil-worker-forwarder: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) satellite:el8/yggdrasil-worker-forwarder: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) satellite:el8/yggdrasil-worker-forwarder: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) yggdrasil-worker-forwarder: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) yggdrasil-worker-forwarder: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) satellite:el8/yggdrasil-worker-forwarder: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) satellite:el8/yggdrasil-worker-forwarder: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) yggdrasil-worker-forwarder: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) Bug Fix(es): orphan cleanup triggers CapsuleContent::UpdateContentCounts regardless of automatic_content_count_updates setting (SAT-45906) The custom repository fails to sync with the Capsule server, resulting in an error (SAT-44720) Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Satellite Extended Update Support 6.16 for RHEL 9 x86_64 Red Hat Satellite Extended Update Support 6.16 for RHEL 8 x86_64 Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 9 x86_64 Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 8 x86_64 Fixes BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2449833 - CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2458856 - CVE-2026-40192 Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing SAT-44720 - The custom repository fails to sync with the Capsule server, resulting in an error. [satellite_6.16] SAT-45906 - orphan cleanup triggers CapsuleContent::UpdateContentCounts regardless of automatic_content_count_updates setting [satellite_6.16] CVEs CVE-2025-61729 CVE-2026-25679 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-33186 CVE-2026-40192 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM rubygem-foreman_maintain-1.7.14-1.el9sat.src.rpm SHA-256: 0ff13ce544947065613a8c736c4e5d9474aba9c6cd8495bac234708f4e65ace9 satellite-6.16.9-1.el9sat.src.rpm SHA-256: 7fa8f94548d08d520648bdc950b26c9d496bb0cb83bea5355d19caabdce6897a x86_64 rubygem-foreman_maintain-1.7.14-1.el9sat.noarch.rpm SHA-256: 9f10fc0dc95d35465d8f169effc38f161d688f6c1417cb46c8131b3c18fe9cda satellite-cli-6.16.9-1.el9sat.noarch.rpm SHA-256: 12cdcf13152a3e076c733702bcec6ef71458db691f4dac06308cc73bbe08fc4e Red Hat Enterprise Linux for x86_64 8 SRPM rubygem-foreman_maintain-1.7.14-1.el8sat.src.rpm SHA-256: 02a7f139f1a04ecfe844e01dc9f39ab7caa0bf36d560ed08f6311061055fe672 satellite-6.16.9-1.el8sat.src.rpm SHA-256: b62a038ec8c75c6b49d8b913d49310c5ebb3d0815f88ac0daf4ade593fa4938f x86_64 rubygem-foreman_maintain-1.7.14-1.el8sat.noarch.rpm SHA-256: 7c6d846ea6581d310c3ba3628cd412b9f6241e38bb0a65eeabea03d700144a76 satellite-cli-6.16.9-1.el8sat.noarch.rpm SHA-256: 2cd6e9608fc2826fe5e7ec986c8bf6bdaa52b69865f7e43baaf8aa4be6585db7 Red Hat Satellite Extended Update Support 6.16 for RHEL 9 SRPM dynflow-utils-1.6.3-1.1.el9sat.src.rpm SHA-256: 37bba5e0cce43ccfbed82c8a4e50e216a897fdc121a4b72e671ffdee4f0f2f37 python-pillow-12.2.0-1.el9pc.src.rpm SHA-256: 610c66c93245660b1e54060d2ae029ec7372bdacf8f6c0252a637c7d722c7624 python-pulp-ansible-0.21.10-4.el9pc.src.rpm SHA-256: 9f966831a96bc9c76eccc88f6caff74b19fa9e1d886a4566e32c31086c8e564d python-pulp-rpm-3.26.8-1.el9pc.src.rpm SHA-256: 0a10771aa3319cb7be47d4a2b614c832566faca3b58fe33c5abdea321b6ede85 rubygem-foreman_maintain-1.7.14-1.el9sat.src.rpm SHA-256: 0ff13ce544947065613a8c736c4e5d9474aba9c6cd8495bac234708f4e65ace9 rubygem-katello-4.14.0.20-1.el9sat.src.rpm SHA-256: faf90b42a21c77fc154a7c85abf8fcf9c92fd9948ad41df05327aacba005c397 satellite-6.16.9-1.el9sat.src.rpm SHA-256: 7fa8f94548d08d520648bdc950b26c9d496bb0cb83bea5355d19caabdce6897a satellite-lifecycle-6.16.0-3.el9sat.src.rpm SHA-256: 02e4e5cda9984f4282ccac5f166b0e79e1421d92199d44ef910c17808ca21acc yggdrasil-worker-forwarder-0.0.3-5.el9sat.src.rpm SHA-256: c5acc8c634c5e0716829c648395035fb570d835225d53f738d4193a63a8d8dd5 x86_64 dynflow-utils-1.6.3-1.1.el9sat.x86_64.rpm SHA-256: ee54f2e4c239b978f6030e4bcf72e2503919271f8f5e84ca299686e504ad0863 python3.11-pillow-12.2.0-1.el9pc.x86_64.rpm SHA-256: 215e6cec5eef2ba3e45ded4f3224bf6f23bfa44a0958a7a4cce1a266e4eaa0de python3.11-pulp-ansible-0.21.10-4.el9pc.noarch.rpm SHA-256: 1f971093883f73592276cf49aeaafed4796fcd40ed78b9648c790f9a9660af9b python3.11-pulp-rpm-3.26.8-1.el9pc.noarch.rpm SHA-256: 662697ed8a912db92846117bec0ef17df1e79108524564b988d611fe7c620a1e rubygem-foreman_maintain-1.7.14-1.el9sat.noarch.rpm SHA-256: 9f10fc0dc95d35465d8f169effc38f161d688f6c1417cb46c8131b3c18fe9cda rubygem-katello-4.14.0.20-1.el9sat.noarch.rpm SHA-256: 205a944fe88dd8b4ec2bbc6f37b860cef3659a228079f44d91f94959ef8b374c satellite-6.16.9-1.el9sat.noarch.rpm SHA-256: d5a081cdefed63f930f1a42329334a7fdb8b2eb265b734a210cecb62b2a3b39d satellite-cli-6.16.9-1.el9sat.noarch.rpm SHA-256: 12cdcf13152a3e076c733702bcec6ef71458db691f4dac06308cc73bbe08fc4e satellite-common-6.16.9-1.el9sat.noarch.rpm SHA-256: 31c1d0482dba924bf493543c1c050c53c23ff72678a5c9be50b6cef5b23669d2 satellite-lifecycle-6.16.0-3.el9sat.noarch.rpm SHA-256: c6f7dcf91cc28b319c9d46595b2a752031bb3e538cd918baa74ca5fd42ab79ee yggdrasil-worker-forwarder-0.0.3-5.el9sat.x86_64.rpm SHA-256: b60c37bfd0f45f36d8c673c4bb71f919a874cb8e66e463e7add4ce55d1a80226 Red Hat Satellite Extended Update Support 6.16 for RHEL 8 SRPM dynflow-utils-1.6.3-1.1.el8sat.src.rpm SHA-256: 888d8845807b7e55a55489a4420ed7b8e57d2e1326cd9e9fd3584b765ebc843f python-pillow-12.2.0-1.el8pc.src.rpm SHA-256: 53ac63b0edda2d117aa3fb22a37df132b867163fbc73465f70ab4f3961c12238 python-pulp-ansible-0.21.10-4.el8pc.src.rpm SHA-256: ac75469a4af7f9bd3bc5f1e0eb9028e20e55ddec13a19a46f726d44370116a37 python-pulp-rpm-3.26.8-1.el8pc.src.rpm SHA-256: 17e342525abf75425f0b8bceddd1e184e52654e295cfe9e6be322fbe7e4a59b1 rubygem-foreman_maintain-1.7.14-1.el8sat.src.rpm SHA-256: 02a7f139f1a04ecfe844e01dc9f39ab7caa0bf36d560ed08f6311061055fe672 rubygem-katello-4.14.0.20-1.el8sat.src.rpm SHA-256: 253adcebc6c5c41053d757f959336bc4782d4fd4477cad9906fe835651be430d satellite-6.16.9-1.el8sat.src.rpm SHA-256: b62a038ec8c75c6b49d8b913d49310c5ebb3d0815f88ac0daf4ade593fa4938f satellite-lifecycle-6.16.0-3.el8sat.src.rpm SHA-256: 9dc5ed798108f1c4613cf1f94cb71b8b94ec3c22d998838af8a4ef7b86ec24fd yggdrasil-worker-forwarder-0.0.3-5.el8sat.src.rpm SHA-256: a24cbc1d560b5cb98f872ef0e316d2cd2aa766a494e113a1b80a4c433133cfd4 x86_64 dynflow-utils-1.6.3-1.1.el8sat.x86_64.rpm SHA-256: f88b845931ac7e31c574600791c8f90771a62fa7cb00413573444635d43d1413 python3.11-pillow-12.2.0-1.el8pc.x86_64.rpm SHA-256: 950f86941dd8185018a93100ef395e9807157cc2f99af58e9fc508691c5046c4 python3.11-pulp-ansible-0.21.1

Share this article