Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:39005: Important: rhc security update

This update addresses two vulnerabilities in the `rhc` client: CVE-2026-39821, a critical (CVSS 9.6) privilege escalation via incorrect Punycode processing in the golang `net` library, and CVE-2026-27145, a medium-severity (CVSS 6.5) denial of service via excessive DNS SAN processing in `crypto/x509`. The affected component is `golang net` library versions prior to 0.55.0. Red Hat has provided patched packages for Red Hat Enterprise Linux 10 to remediate these issues.
Read Full Article →

Red Hat Product Errata RHSA-2026:39005 - Security Advisory Issued: 2026-07-13 Updated: 2026-07-13 RHSA-2026:39005 - Security Advisory Overview Updated Packages Synopsis Important: rhc security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rhc is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description rhc is a client tool and daemon that connects the system to Red Hat hosted services enabling system and subscription management. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVEs CVE-2026-27145 CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 x86_64 rhc-0.3.8-6.el10_2.x86_64.rpm SHA-256: d429680c3405901367143fd664475fa349ff884604e620c09f23c450420e39a4 rhc-debuginfo-0.3.8-6.el10_2.x86_64.rpm SHA-256: cf5990fdb239e205aa9f51547fa68fc32063a8f7c0458f745c8cfa3ac9758997 rhc-debugsource-0.3.8-6.el10_2.x86_64.rpm SHA-256: a98c3caa8312ffc573dfdff311aceffa88ce67d27722465418e0f3dcf428fc72 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 x86_64 rhc-0.3.8-6.el10_2.x86_64.rpm SHA-256: d429680c3405901367143fd664475fa349ff884604e620c09f23c450420e39a4 rhc-debuginfo-0.3.8-6.el10_2.x86_64.rpm SHA-256: cf5990fdb239e205aa9f51547fa68fc32063a8f7c0458f745c8cfa3ac9758997 rhc-debugsource-0.3.8-6.el10_2.x86_64.rpm SHA-256: a98c3caa8312ffc573dfdff311aceffa88ce67d27722465418e0f3dcf428fc72 Red Hat Enterprise Linux for IBM z Systems 10 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 s390x rhc-0.3.8-6.el10_2.s390x.rpm SHA-256: 29f6016e843af34a3df408aac0ee73cfffa80d1467fcb30f1c0c3a5f51e78d4e rhc-debuginfo-0.3.8-6.el10_2.s390x.rpm SHA-256: a7bae6499a736ffdf585be4de1c68f6b04824f870346898959d1404a6cb04556 rhc-debugsource-0.3.8-6.el10_2.s390x.rpm SHA-256: 18a8fe76089bd2b809a6b0fb506285ad360c14b098a26c41bc2817ec5a557fe6 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 s390x rhc-0.3.8-6.el10_2.s390x.rpm SHA-256: 29f6016e843af34a3df408aac0ee73cfffa80d1467fcb30f1c0c3a5f51e78d4e rhc-debuginfo-0.3.8-6.el10_2.s390x.rpm SHA-256: a7bae6499a736ffdf585be4de1c68f6b04824f870346898959d1404a6cb04556 rhc-debugsource-0.3.8-6.el10_2.s390x.rpm SHA-256: 18a8fe76089bd2b809a6b0fb506285ad360c14b098a26c41bc2817ec5a557fe6 Red Hat Enterprise Linux for Power, little endian 10 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 ppc64le rhc-0.3.8-6.el10_2.ppc64le.rpm SHA-256: b2f3513d03060b6c24dc40af76a1416bf2c65b6c873f9a51815965765be51686 rhc-debuginfo-0.3.8-6.el10_2.ppc64le.rpm SHA-256: 2ea560bde2910e2d283da4bd6aaf49191ee860e6b777be771193063f7d03ee1f rhc-debugsource-0.3.8-6.el10_2.ppc64le.rpm SHA-256: fec53de7a7b96622b1e658dbf3c9f284246ce21b68b88b11298588e526627cfe Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 ppc64le rhc-0.3.8-6.el10_2.ppc64le.rpm SHA-256: b2f3513d03060b6c24dc40af76a1416bf2c65b6c873f9a51815965765be51686 rhc-debuginfo-0.3.8-6.el10_2.ppc64le.rpm SHA-256: 2ea560bde2910e2d283da4bd6aaf49191ee860e6b777be771193063f7d03ee1f rhc-debugsource-0.3.8-6.el10_2.ppc64le.rpm SHA-256: fec53de7a7b96622b1e658dbf3c9f284246ce21b68b88b11298588e526627cfe Red Hat Enterprise Linux for ARM 64 10 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 aarch64 rhc-0.3.8-6.el10_2.aarch64.rpm SHA-256: 55ba7a8e7c26ce01b79b162e4dd632d6bec73994450709babf342daad54cd4d9 rhc-debuginfo-0.3.8-6.el10_2.aarch64.rpm SHA-256: 0c6d1bc064c6d2963754b3ca9fb38dbf787b9bb6129945952ecb81c28b66a6e0 rhc-debugsource-0.3.8-6.el10_2.aarch64.rpm SHA-256: 505452e8c0038c37fb46186f4d7437340d964acfb6c8eba71ec22515a5a38d9e Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 aarch64 rhc-0.3.8-6.el10_2.aarch64.rpm SHA-256: 55ba7a8e7c26ce01b79b162e4dd632d6bec73994450709babf342daad54cd4d9 rhc-debuginfo-0.3.8-6.el10_2.aarch64.rpm SHA-256: 0c6d1bc064c6d2963754b3ca9fb38dbf787b9bb6129945952ecb81c28b66a6e0 rhc-debugsource-0.3.8-6.el10_2.aarch64.rpm SHA-256: 505452e8c0038c37fb46186f4d7437340d964acfb6c8eba71ec22515a5a38d9e Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 aarch64 rhc-0.3.8-6.el10_2.aarch64.rpm SHA-256: 55ba7a8e7c26ce01b79b162e4dd632d6bec73994450709babf342daad54cd4d9 rhc-debuginfo-0.3.8-6.el10_2.aarch64.rpm SHA-256: 0c6d1bc064c6d2963754b3ca9fb38dbf787b9bb6129945952ecb81c28b66a6e0 rhc-debugsource-0.3.8-6.el10_2.aarch64.rpm SHA-256: 505452e8c0038c37fb46186f4d7437340d964acfb6c8eba71ec22515a5a38d9e Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 s390x rhc-0.3.8-6.el10_2.s390x.rpm SHA-256: 29f6016e843af34a3df408aac0ee73cfffa80d1467fcb30f1c0c3a5f51e78d4e rhc-debuginfo-0.3.8-6.el10_2.s390x.rpm SHA-256: a7bae6499a736ffdf585be4de1c68f6b04824f870346898959d1404a6cb04556 rhc-debugsource-0.3.8-6.el10_2.s390x.rpm SHA-256: 18a8fe76089bd2b809a6b0fb506285ad360c14b098a26c41bc2817ec5a557fe6 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 ppc64le rhc-0.3.8-6.el10_2.ppc64le.rpm SHA-256: b2f3513d03060b6c24dc40af76a1416bf2c65b6c873f9a51815965765be51686 rhc-debuginfo-0.3.8-6.el10_2.ppc64le.rpm SHA-256: 2ea560bde2910e2d283da4bd6aaf49191ee860e6b777be771193063f7d03ee1f rhc-debugsource-0.3.8-6.el10_2.ppc64le.rpm SHA-256: fec53de7a7b96622b1e658dbf3c9f284246ce21b68b88b11298588e526627cfe Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 x86_64 rhc-0.3.8-6.el10_2.x86_64.rpm SHA-256: d429680c3405901367143fd664475fa349ff884604e620c09f23c450420e39a4 rhc-debuginfo-0.3.8-6.el10_2.x86_64.rpm SHA-256: cf5990fdb239e205aa9f51547fa68fc32063a8f7c0458f745c8cfa3ac9758997 rhc-debugsource-0.3.8-6.el10_2.x86_64.rpm SHA-256: a98c3caa8312ffc573dfdff311aceffa88ce67d27722465418e0f3dcf428fc72 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 x86_64 rhc-0.3.8-6.el10_2.x86_64.rpm SHA-256: d429680c3405901367143fd664475fa349ff884604e620c09f23c450420e39a4 rhc-debuginfo-0.3.8-6.el10_2.x86_64.rpm SHA-256: cf5990fdb239e205aa9f51547fa68fc32063a8f7c0458f745c8cfa3ac9758997 rhc-debugsource-0.3.8-6.el10_2.x86_64.rpm SHA-256: a98c3caa8312ffc573dfdff311aceffa88ce67d27722465418e0f3dcf428fc72 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 SRPM rhc-0.3.8-6.el10_2.src.rpm SHA-256: a9058abb0e24b0c33f7857f73d38e10dc8d69f532a215bc66765be3d1ac3fcd9 aarch64 rhc-0.3.8-6.el10_2.aarch64.rpm SHA-256: 55ba7a8e7c26ce01b79b162e4dd632d6bec73994450709babf342daad54cd4

Share this article