Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:42150: Important: Satellite 6.17.9.1 Async Update

This important update for Red Hat Satellite 6.17 addresses multiple vulnerabilities, including a critical directory traversal in pulpcore (CVE-2026-12701, CVSS 9.0) allowing filesystem export bypass and several high/critical issues in the yggdrasil-worker-forwarder component related to Go and gRPC libraries, such as an authorization bypass in gRPC-Go (CVE-2026-33186, CVSS 9.1). The advisory provides the patched version, Satellite 6.17.9.1, to remediate these flaws. Administrators should apply this update after ensuring all previous errata are installed, following the documented upgrade procedures.
Read Full Article →

Red Hat Product Errata RHSA-2026:42150 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:42150 - Security Advisory Overview Updated Packages Synopsis Important: Satellite 6.17.9.1 Async Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic A new release is now available for Red Hat Satellite 6.17 for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701) yggdrasil-worker-forwarder: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) yggdrasil-worker-forwarder: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) yggdrasil-worker-forwarder: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) yggdrasil-worker-forwarder: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) yggdrasil-worker-forwarder: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): Satellite 6.16→6.17 upgrade fails: pulpcore-manager rpm-datarepair 4073 CommandError: Unknown issue: '4073' (SAT-47477) Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index Affected Products Red Hat Satellite 6.17 x86_64 Red Hat Satellite Capsule 6.17 x86_64 Red Hat Enterprise Linux for x86_64 9 x86_64 Fixes BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2449833 - CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries BZ - 2490703 - CVE-2026-12701 pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport SAT-47477 - Satellite 6.16?6.17 upgrade fails: pulpcore-manager rpm-datarepair 4073 CommandError: Unknown issue: '4073' CVEs CVE-2026-12701 CVE-2026-25679 CVE-2026-27145 CVE-2026-33186 CVE-2026-33811 CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Satellite 6.17 SRPM python-pulp-rpm-3.27.12-1.el9pc.src.rpm SHA-256: de460e4a8f6a433aa91cf2257b39afe48b9c67c383a26a164b7c2c7bac008097 python-pulpcore-3.63.21-2.el9pc.src.rpm SHA-256: ca0755d60ebd3148c2372cf4a3229a0363ef2e1e1673ba6762ca8b462671997e satellite-6.17.9.1-1.el9sat.src.rpm SHA-256: 97960d8a1250a8165722aee23b4ec420a3d39ab734db8f492f164294f80f550d yggdrasil-worker-forwarder-0.0.4-1.el9sat.src.rpm SHA-256: 387ba25ee571ab79cedbe84491b639b0b98ffee8afeee5345159fba35dff0567 x86_64 python3.11-pulp-rpm-3.27.12-1.el9pc.noarch.rpm SHA-256: 5ce50a39ff39add5bc72118be557e4593d4452f88ead51b2ca9099c5436df9d2 python3.11-pulpcore-3.63.21-2.el9pc.noarch.rpm SHA-256: b2de80f78cf6b6d8526e3a5d839e6ca657e1d40c241de769612e0a68fc228aa4 satellite-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 4550c09ef6585ed0153702c9e14848cf95b528745a59269eabcfe3448550325e satellite-cli-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 8181971e22923a49cd1dde09e169a5dc5ec22abef214218382b931518873df6d satellite-common-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 3d3b541ec4c8db73662b8cc81eca3faa7b311b1ccf6494558e7405dd5613da8c satellite-obsolete-packages-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 92ef8e3ba53da7aac7b38acbe76e6270d822b940e270b935470c375db56bf579 yggdrasil-worker-forwarder-0.0.4-1.el9sat.x86_64.rpm SHA-256: 85f1a904da0474f9c0a22fcc78ca237be1fece967d10f0ca86ba1487b9244daf Red Hat Satellite Capsule 6.17 SRPM python-pulp-rpm-3.27.12-1.el9pc.src.rpm SHA-256: de460e4a8f6a433aa91cf2257b39afe48b9c67c383a26a164b7c2c7bac008097 python-pulpcore-3.63.21-2.el9pc.src.rpm SHA-256: ca0755d60ebd3148c2372cf4a3229a0363ef2e1e1673ba6762ca8b462671997e satellite-6.17.9.1-1.el9sat.src.rpm SHA-256: 97960d8a1250a8165722aee23b4ec420a3d39ab734db8f492f164294f80f550d x86_64 python3.11-pulp-rpm-3.27.12-1.el9pc.noarch.rpm SHA-256: 5ce50a39ff39add5bc72118be557e4593d4452f88ead51b2ca9099c5436df9d2 python3.11-pulpcore-3.63.21-2.el9pc.noarch.rpm SHA-256: b2de80f78cf6b6d8526e3a5d839e6ca657e1d40c241de769612e0a68fc228aa4 satellite-capsule-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 83c76981626fc74b3f15dc1bb03136d0e3170f40997609d95f4b1c34818cab69 satellite-common-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 3d3b541ec4c8db73662b8cc81eca3faa7b311b1ccf6494558e7405dd5613da8c satellite-obsolete-packages-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 92ef8e3ba53da7aac7b38acbe76e6270d822b940e270b935470c375db56bf579 Red Hat Enterprise Linux for x86_64 9 SRPM satellite-6.17.9.1-1.el9sat.src.rpm SHA-256: 97960d8a1250a8165722aee23b4ec420a3d39ab734db8f492f164294f80f550d x86_64 satellite-cli-6.17.9.1-1.el9sat.noarch.rpm SHA-256: 8181971e22923a49cd1dde09e169a5dc5ec22abef214218382b931518873df6d The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article