- What: Red Hat Edge Manager receives a security update
- Impact: Addresses vulnerabilities in edge device management
Red Hat Product Errata RHSA-2026:41019 - Security Advisory Issued: 2026-07-16 Updated: 2026-07-16 RHSA-2026:41019 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Edge Manager Version 1.1.3 Security Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic Red Hat Edge Manager Version 1.1.3 Security Update Description Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: This solution not only helps customers manage thousands of devices but helps scale operations. To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Security fixes: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions (CVE-2026-39828) golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595) golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) Go crypto/x509: Incorrect enforcement of email constraints (CVE-2026-27137) Go net/url: Incorrect parsing of IPv6 host literals (CVE-2026-25679) golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816) github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815) gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151) Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154) Root.Chmod can follow symlinks out of the root (CVE-2026-32282) Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469) Solution See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Affected Products Red Hat Edge Manager 1.1 for RHEL 10 x86_64 Red Hat Edge Manager 1.1 for RHEL 10 s390x Red Hat Edge Manager 1.1 for RHEL 10 ppc64le Red Hat Edge Manager 1.1 for RHEL 10 aarch64 Red Hat Edge Manager 1.1 for RHEL 9 x86_64 Red Hat Edge Manager 1.1 for RHEL 9 s390x Red Hat Edge Manager 1.1 for RHEL 9 ppc64le Red Hat Edge Manager 1.1 for RHEL 9 aarch64 Fixes BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate BZ - 2445345 - CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509 BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2449833 - CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation BZ - 2455972 - CVE-2026-33816 github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability BZ - 2455975 - CVE-2026-33815 github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2457729 - CVE-2026-35469 Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code BZ - 2466505 - CVE-2026-42154 github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint BZ - 2466507 - CVE-2026-42151 github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2480680 - CVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate BZ - 2480681 - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters BZ - 2480684 - CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses BZ - 2480685 - CVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions BZ - 2480687 - CVE-2026-39828 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions BZ - 2480688 - CVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey BZ - 2480689 - CVE-2026-46595 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2025-61729 CVE-2026-25679 CVE-2026-27137 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-33186 CVE-2026-33811 CVE-2026-33815 CVE-2026-33816 CVE-2026-35469 CVE-2026-39821 CVE-2026-39828 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835 CVE-2026-42151 CVE-2026-42154 CVE-2026-42508 CVE-2026-46595 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_enterprise_linux/rhem-integrating-with-aap https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_openshift_container_platform/edge-manager-install-rhem-ocp#edge-manager-verify-rhem-acm-console Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Edge Manager 1.1 for RHEL 10 SRPM flightctl-1.1.3-1.el10em.src.rpm SHA-256: 3ecdc6e393545cebcb8a3a7e3c0825ca4d027e8cd4ce172bfaac043cc3b0bb58 x86_64 flightctl-agent-1.1.3-1.el10em.x86_64.rpm SHA-256: 8bb2627fecd765fac266d530a3d80b26d881090de7afe539b1347bd92568bb60 flightctl-cli-1.1.3-1.el10em.x86_64.rpm SHA-256: 30fc5256f2164618201446a2cca7471f22ed453ffc2fad83f89bbf53fc28500f flightctl-observability-1.1.3-1.el10em.x86_64.rpm SHA-256: 7ba13d36a09492e64141586b891e01c22a82e252f01cbf9c6e4c93418936e184 flightctl-selinux-1.1.3-1.el10em.noarch.rpm SHA-256: 010a75cd1936cde6cff13b350e7cd02994dda62ec25a29d45ac2f360b977ca05 flightctl-services-1.1.3-1.el10em.x86_64.rpm SHA-256: a4152dd6302b46d0393b83cf6b2b6f681d6c6f2dc57cfa29748dddd521468865 s390x flightctl-agent-1.1.3-1.el10em.s390x.rpm SHA-256: e17bccc9bf09a99548e67fca5bb13b4b49bc73496437d0fbd7d9de4303020bf0 flightctl-cli-1.1.3-1.el10em.s390x.rpm SHA-256: f5096606822655c7a6ddf268955e6d17c13a3ee753901563647326b9de197ad1 flightctl-observability-1.1.3-1.el10em.s390x.rpm SHA-256: b05af3ac767f46a6cbfeb878b622f59d1f411bf41c027bc4103baad2e4dd24a8 flightctl-selinux-1.1.3-1.el10em.noarch.rpm SHA-256: 010a75cd1936cde6cff13b350e7cd02994dda62ec25a29d45ac2f360b977ca05 flightctl-services-1.1.3-1.el10em.s390x.rpm SHA-256: 0a3a38f4af76557b4f6c907988d779f0b527264ed39ac190d94e26fae0422f0f ppc64le flightctl-agent-1.1.3-1.el10em.ppc64le.rpm SHA-256: 4e3babfa13cd7eb6d431ab3a0761efb5e61b01748ef641069ce6e1a226a24cf9 flightctl-cli-1.1.3-1.el10em.ppc64le.rpm SHA-256: b4de5ae76a47acea8bd90e8009af74d67d02b96e8ddf2e96bde65f399826327f flightctl-observability-1.1.3-1.el10em.ppc64le.rpm SHA-256: 75db599b201782595d7e4d779040136c186a6e170dd360975a2a5ba9fb2aa540 flightctl-selinux