Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:42151: Important: Satellite 6.18.7.1 Async Update

This update for Red Hat Satellite 6.18 addresses multiple vulnerabilities in its components, including a critical authorization bypass in gRPC-Go (CVE-2026-33186, CVSS 9.1) due to improper HTTP/2 path validation, a critical privilege escalation via incorrect Punycode processing in golang.org/x/net/idna (CVE-2026-39821, CVSS 9.6), and a high-severity parsing flaw for IPv6 host literals in net/url (CVE-2026-25679, CVSS 7.5). The affected versions are grpc-go prior to 1.79.3, golang net prior to 0.55.0, and Go prior to 1.25.8. The advisory resolves these issues via the Satellite 6.18.7.1 Async Update.
Read Full Article →

Red Hat Product Errata RHSA-2026:42151 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:42151 - Security Advisory Overview Updated Packages Synopsis Important: Satellite 6.18.7.1 Async Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic A new release is now available for Red Hat Satellite 6.18 for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): yggdrasil-worker-forwarder: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) yggdrasil-worker-forwarder: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) yggdrasil-worker-forwarder: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) yggdrasil-worker-forwarder: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) yggdrasil-worker-forwarder: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) python3.12-pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701) Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Satellite 6.18 x86_64 Red Hat Satellite Capsule 6.18 x86_64 Red Hat Enterprise Linux for x86_64 9 x86_64 Fixes BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2449833 - CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries BZ - 2490703 - CVE-2026-12701 pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport CVEs CVE-2026-12701 CVE-2026-25679 CVE-2026-27145 CVE-2026-33186 CVE-2026-33811 CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Satellite 6.18 SRPM python3.12-pulpcore-3.73.30-2.el9pc.src.rpm SHA-256: 4c4c7d66f0918d3b8bfeec96ae265ada5d9173d97e9962fce44ed6e6f65599cc satellite-6.18.7.1-1.el9sat.src.rpm SHA-256: 313fb5fc5bdc64f48c86def78cfd2beb4e87376df288102c8836f58a53665bc8 yggdrasil-worker-forwarder-0.0.4-1.el9sat.src.rpm SHA-256: 387ba25ee571ab79cedbe84491b639b0b98ffee8afeee5345159fba35dff0567 x86_64 python3.12-pulpcore-3.73.30-2.el9pc.noarch.rpm SHA-256: 04e92debbcd493de45aff073a6842c8c2faba425fba85d44d86af4a5fe73915c satellite-6.18.7.1-1.el9sat.noarch.rpm SHA-256: fa5cf40e3c0cfab5c367d20ac558d0890b1b9e02c1d4e4dfa09c15bff5f66b60 satellite-cli-6.18.7.1-1.el9sat.noarch.rpm SHA-256: bb5474d1112ba817930c9a8f956e2e94b0d8dac264982a85b64a8b5ed7592a97 satellite-common-6.18.7.1-1.el9sat.noarch.rpm SHA-256: 296d53d3cf94991236a2a7e6a813eb854550ed621edabbae1b50896ee402349e satellite-obsolete-packages-6.18.7.1-1.el9sat.noarch.rpm SHA-256: 5e792c10048a2a2569b31baadfd403576a422edff3cdf64f60befa3d515d27cd yggdrasil-worker-forwarder-0.0.4-1.el9sat.x86_64.rpm SHA-256: 85f1a904da0474f9c0a22fcc78ca237be1fece967d10f0ca86ba1487b9244daf Red Hat Satellite Capsule 6.18 SRPM python3.12-pulpcore-3.73.30-2.el9pc.src.rpm SHA-256: 4c4c7d66f0918d3b8bfeec96ae265ada5d9173d97e9962fce44ed6e6f65599cc satellite-6.18.7.1-1.el9sat.src.rpm SHA-256: 313fb5fc5bdc64f48c86def78cfd2beb4e87376df288102c8836f58a53665bc8 x86_64 python3.12-pulpcore-3.73.30-2.el9pc.noarch.rpm SHA-256: 04e92debbcd493de45aff073a6842c8c2faba425fba85d44d86af4a5fe73915c satellite-capsule-6.18.7.1-1.el9sat.noarch.rpm SHA-256: 30b4252223b1ee5fc901694e0e29da4fbfc4714ad0e0288a9a751bbe1e8b1f3f satellite-common-6.18.7.1-1.el9sat.noarch.rpm SHA-256: 296d53d3cf94991236a2a7e6a813eb854550ed621edabbae1b50896ee402349e satellite-obsolete-packages-6.18.7.1-1.el9sat.noarch.rpm SHA-256: 5e792c10048a2a2569b31baadfd403576a422edff3cdf64f60befa3d515d27cd Red Hat Enterprise Linux for x86_64 9 SRPM satellite-6.18.7.1-1.el9sat.src.rpm SHA-256: 313fb5fc5bdc64f48c86def78cfd2beb4e87376df288102c8836f58a53665bc8 x86_64 satellite-cli-6.18.7.1-1.el9sat.noarch.rpm SHA-256: bb5474d1112ba817930c9a8f956e2e94b0d8dac264982a85b64a8b5ed7592a97 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article