Red Hat Product Errata RHSA-2026:42946 - Security Advisory Issued: 2026-07-21 Updated: 2026-07-21 RHSA-2026:42946 - Security Advisory Overview Updated Packages Synopsis Important: rhc-worker-playbook security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rhc-worker-playbook is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description A worker for yggdrasil that receives Ansible playbooks and executes them against the local host. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) Bug Fix(es) and Enhancement(s): Update Ansible dependencies (ansible-runner, collections) [10.2.z] (JIRA:RHEL-208712) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries RHEL-208712 - Update Ansible dependencies (ansible-runner, collections) [10.2.z] CVEs CVE-2026-27145 CVE-2026-33811 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 x86_64 rhc-worker-playbook-0.2.10-1.el10_2.x86_64.rpm SHA-256: 8d7b895b7c4dd8d9c7a4db4a695646e79c82008c83dd5de5226c83f1e555e67a rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.x86_64.rpm SHA-256: 03f0f2fee04dc1ec087804fce71aafcc9ad5b2f45a952a836750a318d5ae8865 rhc-worker-playbook-debugsource-0.2.10-1.el10_2.x86_64.rpm SHA-256: 223138b8f042c7c22308e97c8c5faccae2822a689f3e0b1c7d3fc3733e265e79 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 x86_64 rhc-worker-playbook-0.2.10-1.el10_2.x86_64.rpm SHA-256: 8d7b895b7c4dd8d9c7a4db4a695646e79c82008c83dd5de5226c83f1e555e67a rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.x86_64.rpm SHA-256: 03f0f2fee04dc1ec087804fce71aafcc9ad5b2f45a952a836750a318d5ae8865 rhc-worker-playbook-debugsource-0.2.10-1.el10_2.x86_64.rpm SHA-256: 223138b8f042c7c22308e97c8c5faccae2822a689f3e0b1c7d3fc3733e265e79 Red Hat Enterprise Linux for IBM z Systems 10 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 s390x rhc-worker-playbook-0.2.10-1.el10_2.s390x.rpm SHA-256: c6c3db08fdc3ed8ac156b128001d8b7e89e6f21ad051837a64d4befabc48e44d rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.s390x.rpm SHA-256: 18dbe17e99477f638310f3f73f5a3ded52fdccd0455b81b2456d83b6ea6fc9e8 rhc-worker-playbook-debugsource-0.2.10-1.el10_2.s390x.rpm SHA-256: 829e5191f4d782b1afe5afe6a846c14f0e6fe6fc06fc3d7c5a44ab97af73caaf Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 s390x rhc-worker-playbook-0.2.10-1.el10_2.s390x.rpm SHA-256: c6c3db08fdc3ed8ac156b128001d8b7e89e6f21ad051837a64d4befabc48e44d rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.s390x.rpm SHA-256: 18dbe17e99477f638310f3f73f5a3ded52fdccd0455b81b2456d83b6ea6fc9e8 rhc-worker-playbook-debugsource-0.2.10-1.el10_2.s390x.rpm SHA-256: 829e5191f4d782b1afe5afe6a846c14f0e6fe6fc06fc3d7c5a44ab97af73caaf Red Hat Enterprise Linux for Power, little endian 10 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 ppc64le rhc-worker-playbook-0.2.10-1.el10_2.ppc64le.rpm SHA-256: fa290d7fc0481ab3344c0b253d5e7fa9f1d31c99ca9c9e042968bb425dad5b93 rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.ppc64le.rpm SHA-256: 0bae97253ad8ab2b8f4d3e38fcdbabb7e6e7d0e5756af5af75008dbb0e051c5b rhc-worker-playbook-debugsource-0.2.10-1.el10_2.ppc64le.rpm SHA-256: 4c3d3699ceb2f2968a66b5a2d6858dbb7c2f7eb27257dad707b71d8eff8ef5d9 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 ppc64le rhc-worker-playbook-0.2.10-1.el10_2.ppc64le.rpm SHA-256: fa290d7fc0481ab3344c0b253d5e7fa9f1d31c99ca9c9e042968bb425dad5b93 rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.ppc64le.rpm SHA-256: 0bae97253ad8ab2b8f4d3e38fcdbabb7e6e7d0e5756af5af75008dbb0e051c5b rhc-worker-playbook-debugsource-0.2.10-1.el10_2.ppc64le.rpm SHA-256: 4c3d3699ceb2f2968a66b5a2d6858dbb7c2f7eb27257dad707b71d8eff8ef5d9 Red Hat Enterprise Linux for ARM 64 10 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 aarch64 rhc-worker-playbook-0.2.10-1.el10_2.aarch64.rpm SHA-256: 50289ee9cb22369b434ad392552ea2bd6d3c01ef376b4f3dc8fb5fa04829c7ab rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.aarch64.rpm SHA-256: 43a9d890115f88f81e1388c861d70fd4ccced27af08fc84beff8e23970d2f41d rhc-worker-playbook-debugsource-0.2.10-1.el10_2.aarch64.rpm SHA-256: a82cd5dc094b9aa31a0e0fbc6ee26cf52c14b9dfe383a7c2e618199088694e8f Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 aarch64 rhc-worker-playbook-0.2.10-1.el10_2.aarch64.rpm SHA-256: 50289ee9cb22369b434ad392552ea2bd6d3c01ef376b4f3dc8fb5fa04829c7ab rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.aarch64.rpm SHA-256: 43a9d890115f88f81e1388c861d70fd4ccced27af08fc84beff8e23970d2f41d rhc-worker-playbook-debugsource-0.2.10-1.el10_2.aarch64.rpm SHA-256: a82cd5dc094b9aa31a0e0fbc6ee26cf52c14b9dfe383a7c2e618199088694e8f Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 aarch64 rhc-worker-playbook-0.2.10-1.el10_2.aarch64.rpm SHA-256: 50289ee9cb22369b434ad392552ea2bd6d3c01ef376b4f3dc8fb5fa04829c7ab rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.aarch64.rpm SHA-256: 43a9d890115f88f81e1388c861d70fd4ccced27af08fc84beff8e23970d2f41d rhc-worker-playbook-debugsource-0.2.10-1.el10_2.aarch64.rpm SHA-256: a82cd5dc094b9aa31a0e0fbc6ee26cf52c14b9dfe383a7c2e618199088694e8f Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 s390x rhc-worker-playbook-0.2.10-1.el10_2.s390x.rpm SHA-256: c6c3db08fdc3ed8ac156b128001d8b7e89e6f21ad051837a64d4befabc48e44d rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.s390x.rpm SHA-256: 18dbe17e99477f638310f3f73f5a3ded52fdccd0455b81b2456d83b6ea6fc9e8 rhc-worker-playbook-debugsource-0.2.10-1.el10_2.s390x.rpm SHA-256: 829e5191f4d782b1afe5afe6a846c14f0e6fe6fc06fc3d7c5a44ab97af73caaf Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 ppc64le rhc-worker-playbook-0.2.10-1.el10_2.ppc64le.rpm SHA-256: fa290d7fc0481ab3344c0b253d5e7fa9f1d31c99ca9c9e042968bb425dad5b93 rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.ppc64le.rpm SHA-256: 0bae97253ad8ab2b8f4d3e38fcdbabb7e6e7d0e5756af5af75008dbb0e051c5b rhc-worker-playbook-debugsource-0.2.10-1.el10_2.ppc64le.rpm SHA-256: 4c3d3699ceb2f2968a66b5a2d6858dbb7c2f7eb27257dad707b71d8eff8ef5d9 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM rhc-worker-playbook-0.2.10-1.el10_2.src.rpm SHA-256: 2c15a94d5fe8362ae41e5a2f93e37c221cb91c351143d61af525dcb44b658318 x86_64 rhc-worker-playbook-0.2.10-1.el10_2.x86_64.rpm SHA-256: 8d7b895b7c4dd8d9c7a4db4a695646e79c82008c83dd5de5226c83f1e555e67a rhc-worker-playbook-debuginfo-0.2.10-1.el10_2.x86_64.rpm SHA-256: 03f0
This update addresses two denial-of-service vulnerabilities in the Go libraries used by `rhc-worker-playbook`: CVE-2026-33811 (CVSS 7.5 High) via long CNAME responses in the net package, and CVE-2026-27145 (CVSS 6.5 Medium) via excessive DNS SAN processing in crypto/x509. The underlying Go vulnerabilities affect versions prior to 1.25.10 and versions 1.26.0 through 1.26.2, which are fixed in Go 1.25.10 and 1.26.3 respectively. Red Hat has rated this update as Important and released patched packages for Red Hat Enterprise Linux 10.