- What: rhc-worker-playbook security update released
- Impact: Fixes DoS vulnerability
Red Hat Product Errata RHSA-2026:54168 - Security Advisory Issued: 2026-08-12 Updated: 2026-08-12 RHSA-2026:54168 - Security Advisory Overview Updated Packages Synopsis Important: rhc-worker-playbook security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rhc-worker-playbook is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description A worker for yggdrasil that receives Ansible playbooks and executes them against the local host. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVEs CVE-2026-27145 CVE-2026-33811 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 x86_64 rhc-worker-playbook-0.2.3-6.el10_0.x86_64.rpm SHA-256: 0b1afe8b09a18e3cbe567e59281a5069e92e655ec4611e156d57a90cc1b4d652 rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.x86_64.rpm SHA-256: f2f82a9e6e4ff5f456d6c8220076b785702e28eb4afc8036f4d460d9a322b61f rhc-worker-playbook-debugsource-0.2.3-6.el10_0.x86_64.rpm SHA-256: 17f8471dbfc55beee700c3b956a69b978f25950dec1f9a00e52fcba765a6d933 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 s390x rhc-worker-playbook-0.2.3-6.el10_0.s390x.rpm SHA-256: e0c335ba3be1de6cd841233285d1d253a24c57281f271bfe642d1e5a3418e7ae rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.s390x.rpm SHA-256: 0f85b20f5e20a4321e5acfea2d7c55f23546d9bc619ae4522a3c71791d92f9d6 rhc-worker-playbook-debugsource-0.2.3-6.el10_0.s390x.rpm SHA-256: af41c739219ab801127e4732d4f106e33a1ec1867b82bb09c96ea5cf090e0218 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 ppc64le rhc-worker-playbook-0.2.3-6.el10_0.ppc64le.rpm SHA-256: 07a4433fc69abcb5bbb643f1b699b677fb42c9378cd7bc519364f6022fa28341 rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.ppc64le.rpm SHA-256: f27b932b20e50baf487a87a35f61c4a7b94947064f3edbfc0978f058aa718c8c rhc-worker-playbook-debugsource-0.2.3-6.el10_0.ppc64le.rpm SHA-256: 57dd550261983a7b377b03b2f8631e39e91ed7a1f14b852ccf2c5ffd53124c61 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 aarch64 rhc-worker-playbook-0.2.3-6.el10_0.aarch64.rpm SHA-256: 660d20afee7490cf0feb82702d979a085a50ef2420b57778f17ba26029da17ad rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.aarch64.rpm SHA-256: 874ce5bedabfedf2ba0fdc1d0821bf5e665d6d85ac7efa2a416537edcd41583b rhc-worker-playbook-debugsource-0.2.3-6.el10_0.aarch64.rpm SHA-256: d82a66c535715cbed65badae47a170302e743f27856afe060bc1924ee62f7bc5 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 aarch64 rhc-worker-playbook-0.2.3-6.el10_0.aarch64.rpm SHA-256: 660d20afee7490cf0feb82702d979a085a50ef2420b57778f17ba26029da17ad rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.aarch64.rpm SHA-256: 874ce5bedabfedf2ba0fdc1d0821bf5e665d6d85ac7efa2a416537edcd41583b rhc-worker-playbook-debugsource-0.2.3-6.el10_0.aarch64.rpm SHA-256: d82a66c535715cbed65badae47a170302e743f27856afe060bc1924ee62f7bc5 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 s390x rhc-worker-playbook-0.2.3-6.el10_0.s390x.rpm SHA-256: e0c335ba3be1de6cd841233285d1d253a24c57281f271bfe642d1e5a3418e7ae rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.s390x.rpm SHA-256: 0f85b20f5e20a4321e5acfea2d7c55f23546d9bc619ae4522a3c71791d92f9d6 rhc-worker-playbook-debugsource-0.2.3-6.el10_0.s390x.rpm SHA-256: af41c739219ab801127e4732d4f106e33a1ec1867b82bb09c96ea5cf090e0218 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 ppc64le rhc-worker-playbook-0.2.3-6.el10_0.ppc64le.rpm SHA-256: 07a4433fc69abcb5bbb643f1b699b677fb42c9378cd7bc519364f6022fa28341 rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.ppc64le.rpm SHA-256: f27b932b20e50baf487a87a35f61c4a7b94947064f3edbfc0978f058aa718c8c rhc-worker-playbook-debugsource-0.2.3-6.el10_0.ppc64le.rpm SHA-256: 57dd550261983a7b377b03b2f8631e39e91ed7a1f14b852ccf2c5ffd53124c61 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM rhc-worker-playbook-0.2.3-6.el10_0.src.rpm SHA-256: 29c4d98cd945625513acefb9f988c29a54ebe0343771d8232f53019d38798206 x86_64 rhc-worker-playbook-0.2.3-6.el10_0.x86_64.rpm SHA-256: 0b1afe8b09a18e3cbe567e59281a5069e92e655ec4611e156d57a90cc1b4d652 rhc-worker-playbook-debuginfo-0.2.3-6.el10_0.x86_64.rpm SHA-256: f2f82a9e6e4ff5f456d6c8220076b785702e28eb4afc8036f4d460d9a322b61f rhc-worker-playbook-debugsource-0.2.3-6.el10_0.x86_64.rpm SHA-256: 17f8471dbfc55beee700c3b956a69b978f25950dec1f9a00e52fcba765a6d933 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .