Red Hat Product Errata RHSA-2026:54401 - Security Advisory Issued: 2026-08-12 Updated: 2026-08-12 RHSA-2026:54401 - Security Advisory Overview Updated Packages Synopsis Important: rhc security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rhc is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description rhc is a client tool and daemon that connects the system to Red Hat hosted services enabling system and subscription management. Security Fix(es): golang.org/x/net/idna: golang: net/ http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVEs CVE-2026-27145 CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc x86_64 rhc-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: d53fe7d9ff44bf2ea7221f3661740484f6b3e143e3689f053f835c8ae5364ff5 rhc-debuginfo-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 5cef34abae4f396258dcdcfd59d78bcec9716163fca3e91c7f7341f7a58e0904 rhc-debugsource-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 6cd501c218d74ca086054846fc946511c85b4aa845c3edf111910e4eec5d4197 Red Hat Enterprise Linux Server - AUS 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc x86_64 rhc-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: d53fe7d9ff44bf2ea7221f3661740484f6b3e143e3689f053f835c8ae5364ff5 rhc-debuginfo-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 5cef34abae4f396258dcdcfd59d78bcec9716163fca3e91c7f7341f7a58e0904 rhc-debugsource-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 6cd501c218d74ca086054846fc946511c85b4aa845c3edf111910e4eec5d4197 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc s390x rhc-0.2.7-1.el9_6.5.s390x.rpm SHA-256: 4cbb4d612ae00586f9cdd61f853e85022740bd47082e789ba67711451bd44109 rhc-debuginfo-0.2.7-1.el9_6.5.s390x.rpm SHA-256: 3d4206b2cd9d292014329e141af2024b37a7cc0fc709f44c091b366df360f353 rhc-debugsource-0.2.7-1.el9_6.5.s390x.rpm SHA-256: ff56a9190b510843ba85b5c0eb9eaa6d16673a22e34c5dba74adb9eb933eb170 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc ppc64le rhc-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: ef2484abfbc6c9970a3aa86b3e3f869c264bdd5ecc6ee2aaedce8df5f2e300b8 rhc-debuginfo-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: 7dbf17e6b7984259f37a9d8245fd89c2df93d7c5032705e28114954ebbfaf443 rhc-debugsource-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: eb7e06c452cba934529035494cfd89bfdf24a274b049b27945625f533b693bf0 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc aarch64 rhc-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: b09cfa789557a44905ff7276b14c83b140ff361cbb068f42b377b28261ac29e5 rhc-debuginfo-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: c94f5e55a08f48a20d56dddf114dd98e505a763676ddf1cd44f7c80c9644d58b rhc-debugsource-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: 38603980f467c0774286718dac9f8d45820de77ad3dba942119f30ad4b8350fa Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc ppc64le rhc-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: ef2484abfbc6c9970a3aa86b3e3f869c264bdd5ecc6ee2aaedce8df5f2e300b8 rhc-debuginfo-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: 7dbf17e6b7984259f37a9d8245fd89c2df93d7c5032705e28114954ebbfaf443 rhc-debugsource-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: eb7e06c452cba934529035494cfd89bfdf24a274b049b27945625f533b693bf0 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc x86_64 rhc-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: d53fe7d9ff44bf2ea7221f3661740484f6b3e143e3689f053f835c8ae5364ff5 rhc-debuginfo-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 5cef34abae4f396258dcdcfd59d78bcec9716163fca3e91c7f7341f7a58e0904 rhc-debugsource-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 6cd501c218d74ca086054846fc946511c85b4aa845c3edf111910e4eec5d4197 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 SRPM x86_64 rhc-debuginfo-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 5cef34abae4f396258dcdcfd59d78bcec9716163fca3e91c7f7341f7a58e0904 rhc-debugsource-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 6cd501c218d74ca086054846fc946511c85b4aa845c3edf111910e4eec5d4197 rhc-devel-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: 57e181fab9459dce52fa620542130f16c51161613fc451897db360a0ab99a49d Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 SRPM ppc64le rhc-debuginfo-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: 7dbf17e6b7984259f37a9d8245fd89c2df93d7c5032705e28114954ebbfaf443 rhc-debugsource-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: eb7e06c452cba934529035494cfd89bfdf24a274b049b27945625f533b693bf0 rhc-devel-0.2.7-1.el9_6.5.ppc64le.rpm SHA-256: f7048e06a0bbb6507b9ec6cc9e78054ff95944e8cf852da31e628a17e76af696 Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 SRPM s390x rhc-debuginfo-0.2.7-1.el9_6.5.s390x.rpm SHA-256: 3d4206b2cd9d292014329e141af2024b37a7cc0fc709f44c091b366df360f353 rhc-debugsource-0.2.7-1.el9_6.5.s390x.rpm SHA-256: ff56a9190b510843ba85b5c0eb9eaa6d16673a22e34c5dba74adb9eb933eb170 rhc-devel-0.2.7-1.el9_6.5.s390x.rpm SHA-256: 8ed4910c9ee283b3409d816d09b3b14c91a9a9f52545d30ba638e489e8d4b942 Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 SRPM aarch64 rhc-debuginfo-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: c94f5e55a08f48a20d56dddf114dd98e505a763676ddf1cd44f7c80c9644d58b rhc-debugsource-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: 38603980f467c0774286718dac9f8d45820de77ad3dba942119f30ad4b8350fa rhc-devel-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: 0e9290d150b45a2a8666ba99f162fbc1e1fbbbacdac0dbc211968582fc375c6f Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc aarch64 rhc-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: b09cfa789557a44905ff7276b14c83b140ff361cbb068f42b377b28261ac29e5 rhc-debuginfo-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: c94f5e55a08f48a20d56dddf114dd98e505a763676ddf1cd44f7c80c9644d58b rhc-debugsource-0.2.7-1.el9_6.5.aarch64.rpm SHA-256: 38603980f467c0774286718dac9f8d45820de77ad3dba942119f30ad4b8350fa Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc s390x rhc-0.2.7-1.el9_6.5.s390x.rpm SHA-256: 4cbb4d612ae00586f9cdd61f853e85022740bd47082e789ba67711451bd44109 rhc-debuginfo-0.2.7-1.el9_6.5.s390x.rpm SHA-256: 3d4206b2cd9d292014329e141af2024b37a7cc0fc709f44c091b366df360f353 rhc-debugsource-0.2.7-1.el9_6.5.s390x.rpm SHA-256: ff56a9190b510843ba85b5c0eb9eaa6d16673a22e34c5dba74adb9eb933eb170 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 SRPM rhc-0.2.7-1.el9_6.5.src.rpm SHA-256: be9440c7cdaa43f7ad15a9543f65f4434f3d21c3da66cb829c9d35abda5187fc x86_64 rhc-0.2.7-1.el9_6.5.x86_64.rpm SHA-256: d53fe7d9ff44bf2ea72
This Important security update for the `rhc` client addresses two vulnerabilities in its embedded Go libraries: a critical (CVSS 9.6) privilege escalation flaw via incorrect Punycode processing in `golang.org/x/net/idna` (CVE-2026-39821), and a denial-of-service issue in `crypto/x509` (CVE-2026-27145). The `golang.org/x/net` library vulnerability affects versions prior to 0.55.0. Red Hat Enterprise Linux 9.6 EUS users should apply the provided `rhc` update to remediate these issues.