Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:66401: Important: Red Hat OpenStack Platform 17.1 security and bug fix advisory

This Red Hat security advisory addresses multiple Important-severity vulnerabilities in OpenStack Platform 17.1, including an arbitrary host file overwrite via unconstrained qemu-img format handling in Nova (CVE-2026-24708, CVSS 8.2) and several high-severity Go language vulnerabilities affecting net/url and crypto/tls components, such as memory exhaustion in query parsing (CVE-2025-61726, CVSS 7.5) and a denial-of-service via TLS 1.3 key update messages (CVE-2026-32283). The advisory provides updated packages for Red Hat OpenStack Platform 17.1 on RHEL 9.2 to remediate these issues.
Read Full Article →

Red Hat Product Errata RHSA-2026:66401 - Security Advisory Issued: 2026-09-10 Updated: 2026-09-10 RHSA-2026:66401 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat OpenStack Platform 17.1 security and bug fix advisory Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic Updated packages that resolve various issues are now available for Red Hat OpenStack Platform 17.1 (Wallaby) for Red Hat Enterprise Linux (RHEL) 9.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat OpenStack Platform provides the facilities for building, deploying and monitoring a private or public infrastructure-as-a-service (IaaS) cloud running on commonly available physical hardware. Security Fix(es): Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova (CVE-2026-24708) net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat OpenStack 17.1 for RHEL 9 x86_64 Red Hat OpenStack Director Deployment Tools 17.1 for RHEL 9 x86_64 Red Hat Enterprise Linux for x86_64 9 x86_64 Fixes BZ - 2430312 - CVE-2026-24708 openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building OSPRH-25386 - Neutron SR-IOV agent restart interrupts connectivity for ports with propagate_uplink_status flag OSPRH-25998 - Impossible to extend FC-based volumes on loaded computes because of "multipathd resize map" exit codes OSPRH-31915 - HPE: Fix handling of QOS for Alletra MP OSPRH-26003 - TripleO may bring down pacemaker in InstanceHA overclouds via suboptimal puppet-pacemaker calls OSPRH-19640 - [17.1] 'nova-manage image_property set' does not update request_specs OSPRH-23919 - Add os_params in rabbitmq_bundle OSPRH-25720 - [rhos17.1] Cinder database purge fails due to foreign key constraint errors due to bad timestamp handling OSPRH-29196 - [FFU 16.2-17.1.13] Overcloud upgrade is failing with "Unexpected templating type error occurred on ({{ (static_brick_locks + dynamic_brick_locks)"" CVEs CVE-2025-61726 CVE-2025-68121 CVE-2026-24708 CVE-2026-25679 CVE-2026-32280 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat OpenStack 17.1 for RHEL 9 SRPM ansible-collection-ansible-posix-1.2.0-1.4.el9ost.src.rpm SHA-256: 291e7af5b1a695c11f13e7e4d0720a12cf530f4781e98d5180adeb3ccb51455a ansible-collections-openstack-1.9.1-17.1.20260318160829.0e9a6f2.el9ost.src.rpm SHA-256: 21f8acf4959625351b50126b37875320d8108e12939be655594ffa6a560e133b collectd-sensubility-0.2.1-6.el9ost.src.rpm SHA-256: ca63658d059d19c921b6f543a9170cae17072dff3893baf7b7ddfbe2124786b0 erlang-24.3.4.2-7.el9ost.src.rpm SHA-256: 3f30861354bb3bcfde13562fd5682335d3a1bac032af3c4a2de22c0e1e6e66e8 etcd-3.4.26-9.6.el9ost.src.rpm SHA-256: 87fd1ff35ee29d54f370d955672e95f18c8884a686de0352c3ad5c8d1ae0204c octavia-amphora-image-fips-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 06ef424cce7fbbbf6b8f454ab27d1b9b9b24e307a81032b8848a218b3e2d562d octavia-amphora-image-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 2d0dfa89135eb5710310111c73d754099bc821832149ba267e90e217993c9d0a openstack-cinder-18.2.2-17.1.20260702111621.f6b44fc.el9ost.src.rpm SHA-256: e8a2b0e2d5c280195c1126edb313f6ff4b184c36f339dbc24a6f54cccc1b2e4a openstack-heat-16.1.1-17.1.20260713101101.edc6d60.el9ost.src.rpm SHA-256: 647438094e4699ba3284f5c2cb05f9649913414c530b9268f655de595227d5bf openstack-ironic-17.1.1-17.1.20260721220909.c31db88.el9ost.src.rpm SHA-256: 997885a5f93c87a27495688c092d43e9a87e39ccbe3434783c302e01aeec9cdb openstack-ironic-python-agent-7.1.1-17.1.20260803104219.0211fa9.el9ost.src.rpm SHA-256: 8a8a55be57bfcbe427e30cbd4f26c23435f1b6ede9d71ba9e2f7c8a91b8e7c0a openstack-keystone-19.0.2-17.1.20260630150819.54dd95d.el9ost.src.rpm SHA-256: bc5de0a47e054deb7699d0f24655adddaf4b7751edca6d611e1e1784c17f359d openstack-neutron-18.6.1-17.1.20260810120959.85ff760.el9ost.src.rpm SHA-256: 3f1719da6698a0d907a1b4e44301fcf463048a545443001baa83f922e4eed165 openstack-nova-23.2.3-17.1.20260810140853.2ace99d.el9ost.src.rpm SHA-256: a97e310b6adf4ffc104c1f69ab479f49450143ad417678ec8d8dcd0fd1513c09 openstack-selinux-0.8.37-17.1.20260107141051.05dd1b2.el9ost.src.rpm SHA-256: 4d2cf56289a6d16cfcaa7c8d2c650bacd5d262cc899ac42923c3450681fd6fd0 openstack-swift-2.27.1-17.1.20260806131309.16dbcae.el9ost.src.rpm SHA-256: 6ba37c6e18c59e167bef87f3240537e775a2162b5b9fe2b70f1cd18d861a8b86 openstack-tripleo-heat-templates-14.3.1-17.1.20260803105013.e7c7ce3.el9ost.src.rpm SHA-256: 706acf9f941eca62adf63844364dc4056bdbc42e2e806613a7a19606708cba15 os-net-config-14.2.1-17.1.20260803103231.61d7bd7.el9ost.src.rpm SHA-256: b18507e0f63229f43670fe063081b756dd73c3c6b431b69411ccd72dffe3d22e puppet-rabbitmq-11.0.1-17.1.20260306080955.63fee2c.el9ost.src.rpm SHA-256: 3846d0a78e1798be46a711d99ed098e6cf684a076e1c756ade4965f0329caa93 puppet-tripleo-14.2.3-17.1.20260206090839.40278e1.el9ost.src.rpm SHA-256: a30a63f8582012b45d47c5f8bb616abc0f6857dcbba5eb3dacecf694305446a7 python-cinder-tests-tempest-1.8.0-17.1.20260114160833.0e94611.el9ost.src.rpm SHA-256: fbbc50b2c8fccce077af73bd4491c956327fa2eebbd45a7a0966f84b89cfa851 python-django-horizon-19.4.1-17.1.20260630130603.9b1a13e.el9ost.src.rpm SHA-256: 5c9924b61912498ff503cf8540027cd847a1baf429268f96481c695cb00a3065 python-glance-store-2.5.1-17.1.20260225150839.5f1cee6.el9ost.src.rpm SHA-256: 9bfbba3fdeb6dc7d3ee312414193f23464b048df137055b44fa6c0c33a96e172 python-os-brick-4.3.4-17.1.20260324150947.cf69f92.el9ost.src.rpm SHA-256: 17ae2d91fe460142256b7ed5d0a41da6925003b4c70396099694d4c17ee883e3 python-oslo-messaging-12.7.3-17.1.20260701150916.5d6fd1a.el9ost.src.rpm SHA-256: 708b9d29c6ad20ba0d9b754c06a578b38a8d96dce2a759cd307b66b2f8d843af python-oslo-serialization-4.1.1-17.1.20260326121047.bbe5d5a.el9ost.src.rpm SHA-256: 65532aaced8d330041db7aeba920a873d0eee8caea21ec4ec9a6f29d0ac44a94 python-ovsdbapp-1.9.4-17.1.20260304101059.65d02f0.el9ost.src.rpm SHA-256: 620a58baea3a8caec1f370c0858cb2f55cbc74c26d5932cfd07447b976f0b0d8 rhosp-director-images-17.1-20260901.1.el9ost.src.rpm SHA-256: c495e2eeafc01ca9cf4a40e529389daa2d1348db4fce89038209f5b1a12b3792 rhosp-director-images-fips-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 99ccca0128d7d0a7eab620b68361ad69fbf1856aa8b9a06878796082e624a67a rhosp-director-images-ipa-fips-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 54af7af15c63e68b309096ff2798160f3e439caa9cd3fc12adafdc6b0831235a rhosp-director-images-ipa-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 2adc94a2ea734998a37ce50faca7ca08cdfa33393c8136af11d2b56db094d927 rhosp-director-images-minimal-17.1-20260901.1.el9ost.src.rpm SHA-256: 29b0bfaf568acaf11d03f77f392d7ebbfca1e7a5247c2c1dd9e5de1faefa4102 rhosp-director-images-minimal-fips-17.1-20260901.1.el9ost.src.rpm SHA-256: acbbe3c6d426a1d5b25e47dbb432fd55fcbead515303ee206ff8817c0f29b8e5 rhosp-director-images-multirhel-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 3806c555715102613e3baae88c494ae8bef380de516aabc488ade6aa6bce3702 rhosp-director-images-uefi-fips-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: 595a57414efd96c52ec6c87f565df24ab1e3d20318fe6ad4059c0fb5a9c6febb rhosp-director-images-uefi-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: efcbcbd4a9fc4c35987a04c9c0e3d5be6955fb57f54c7dee7b8c0e9a4760d971 rhosp-director-images-x86_64-17.1-20260901.1.el9ost.src.rpm SHA-256: d9e51a85872d4e3fd61ed314eb1be60954322f5cfbf0c44b129a2d70ecd2684e tripleo-ansible-3.3.1-17.1.20260603190918.8debef3.el9ost.src.rpm SHA-256: bf83292b2432cbc3b0f429616a2fb4916629cfee97c186df76ef4f210a262e1f x86_64 ansible-collection-ansible-posix-1.2.0-1.4.el9ost.noarch.rpm SHA-256: ed74a93f1ccb47cb6e9e434792c1128a0004ae00ca18e90304dfb0e639629120 ansible-collections-openstack-1.9.1-17.1.20260318160829.0e9a6f2.el9ost.noarch.rpm SHA-256: 56854e1d6c324f9da111088da0ea048b52d9f56cf95f97dac05affd9e0f48aec collectd-sensubility-0.2.1-6.el9ost.x86_64.rpm SHA-256: ba1d6a801e2cf4d5d853e0bfe76770db000196561eb525cb3c88fdfff255fedc collectd-sensubility-debuginfo-0.2.1-6.el9ost.x86_64.rpm SHA-256: e2e482398478af1

Share this article