- What: Security update for libgcrypt library
- Impact: Red Hat Enterprise Linux systems may be vulnerable to denial of service and buffer overflow attacks
Red Hat Product Errata RHSA-2026:58979 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:58979 - Security Advisory Overview Updated Packages Synopsis Moderate: libgcrypt security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libgcrypt is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libgcrypt library provides general-purpose implementations of various cryptographic algorithms. Security Fix(es): Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext (CVE-2026-41989) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2461063 - CVE-2026-41989 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext CVEs CVE-2026-41989 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM libgcrypt-1.8.5-4.el8_4.1.src.rpm SHA-256: 91f7c8e1385181bc2f28e2544f3a96f2e6d1f0786e9c3539ccfe909ccc41cc47 x86_64 libgcrypt-1.8.5-4.el8_4.1.i686.rpm SHA-256: 36d4ad3f48edc5015956a44624887eb5a03d90aae3c817c8e69f0ccf0d7063c5 libgcrypt-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: f78a376d6745fbe34525264fd50349651d4f03fca4ed8f7f2d1122d0cfbea143 libgcrypt-debuginfo-1.8.5-4.el8_4.1.i686.rpm SHA-256: 1bd75ec56649735ece685b760f4d1b27035089e8ca9c54e51dac9667282b336c libgcrypt-debuginfo-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: 7c2effab17807040d54f158ac3c795cfed25976e69189cc7a432e75de2ef9367 libgcrypt-debugsource-1.8.5-4.el8_4.1.i686.rpm SHA-256: b68029c01a139cafb00eb647f089b48bb3eac52aa94fcb84f13e3f1ac0dd78a3 libgcrypt-debugsource-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: 26ac97925785876e1eb9a6b7c9b303ac398731740b3cf5a459473f35616b901e libgcrypt-devel-1.8.5-4.el8_4.1.i686.rpm SHA-256: c96de71655baba9558ac20d7602952ecb61588f8bb33b7b320802576ab40c989 libgcrypt-devel-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: 7b1cf5f71bf4280471166b94adc6a5f5b4022c39a294723c49469b6ab85db4ce libgcrypt-devel-debuginfo-1.8.5-4.el8_4.1.i686.rpm SHA-256: 2a56f36712c60aa4967942c859aaa9c02924208850f6b8a3038605aa1372eaf0 libgcrypt-devel-debuginfo-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: f449d171ce50c00febcae678fb23e34c68cd47a2cfc8793e93c3db44ae676f39 Red Hat Enterprise Linux Server - AUS 8.4 SRPM libgcrypt-1.8.5-4.el8_4.1.src.rpm SHA-256: 91f7c8e1385181bc2f28e2544f3a96f2e6d1f0786e9c3539ccfe909ccc41cc47 x86_64 libgcrypt-1.8.5-4.el8_4.1.i686.rpm SHA-256: 36d4ad3f48edc5015956a44624887eb5a03d90aae3c817c8e69f0ccf0d7063c5 libgcrypt-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: f78a376d6745fbe34525264fd50349651d4f03fca4ed8f7f2d1122d0cfbea143 libgcrypt-debuginfo-1.8.5-4.el8_4.1.i686.rpm SHA-256: 1bd75ec56649735ece685b760f4d1b27035089e8ca9c54e51dac9667282b336c libgcrypt-debuginfo-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: 7c2effab17807040d54f158ac3c795cfed25976e69189cc7a432e75de2ef9367 libgcrypt-debugsource-1.8.5-4.el8_4.1.i686.rpm SHA-256: b68029c01a139cafb00eb647f089b48bb3eac52aa94fcb84f13e3f1ac0dd78a3 libgcrypt-debugsource-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: 26ac97925785876e1eb9a6b7c9b303ac398731740b3cf5a459473f35616b901e libgcrypt-devel-1.8.5-4.el8_4.1.i686.rpm SHA-256: c96de71655baba9558ac20d7602952ecb61588f8bb33b7b320802576ab40c989 libgcrypt-devel-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: 7b1cf5f71bf4280471166b94adc6a5f5b4022c39a294723c49469b6ab85db4ce libgcrypt-devel-debuginfo-1.8.5-4.el8_4.1.i686.rpm SHA-256: 2a56f36712c60aa4967942c859aaa9c02924208850f6b8a3038605aa1372eaf0 libgcrypt-devel-debuginfo-1.8.5-4.el8_4.1.x86_64.rpm SHA-256: f449d171ce50c00febcae678fb23e34c68cd47a2cfc8793e93c3db44ae676f39 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .