Red Hat Product Errata RHSA-2026:68335 - Security Advisory Issued: 2026-09-16 Updated: 2026-09-16 RHSA-2026:68335 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Edge Manager Version 1.2.1 Security Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic Red Hat Edge Manager Version 1.2.1 Security Update Description Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: This solution not only helps customers manage thousands of devices but helps scale operations. To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Security Fixes: flightctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) flightctl: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) flightctl: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) flightctl: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) flightctl: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints (CVE-2026-48050) flightctl: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852) flightctl: Go net/ http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) flightctl: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) flightctl: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) flightctl: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) flightctl: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) flightctl: go-git: Arbitrary file read/write via symbolic link resolution (CVE-2026-71556) Solution See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 Affected Products Red Hat Edge Manager 1.2 for RHEL 10 x86_64 Red Hat Edge Manager 1.2 for RHEL 10 s390x Red Hat Edge Manager 1.2 for RHEL 10 ppc64le Red Hat Edge Manager 1.2 for RHEL 10 aarch64 Red Hat Edge Manager 1.2 for RHEL 9 x86_64 Red Hat Edge Manager 1.2 for RHEL 9 s390x Red Hat Edge Manager 1.2 for RHEL 9 ppc64le Red Hat Edge Manager 1.2 for RHEL 9 aarch64 Fixes BZ - 2483894 - CVE-2026-44740 github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries BZ - 2484830 - CVE-2026-41178 github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers BZ - 2504233 - CVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input BZ - 2512562 - CVE-2026-71556 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution BZ - 2515827 - CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service BZ - 2515838 - CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages BZ - 2515840 - CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVEs CVE-2026-27145 CVE-2026-33818 CVE-2026-41178 CVE-2026-44740 CVE-2026-48050 CVE-2026-56852 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-71556 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Edge Manager 1.2 for RHEL 10 SRPM flightctl-1.2.1-1.el10.src.rpm SHA-256: 40c6acda556ddc3b6a0a7c48d7b01c4c79c3deba78dd4806eac4f62b1fcd8520 x86_64 flightctl-agent-1.2.1-1.el10.x86_64.rpm SHA-256: 716f040eeb5f7a4b93d7ec5c30bb27480ae7746a16c60ea945284b7491e091f7 flightctl-cli-1.2.1-1.el10.x86_64.rpm SHA-256: 18bc6ac835af355d2061991a840bd52722ccec22d5d73c1d241a14cc7cb54c4b flightctl-observability-1.2.1-1.el10.x86_64.rpm SHA-256: a0bf46a5c5577afe6289e7e3290f2770a914e07e72619d145210c8c8d007bcf3 flightctl-selinux-1.2.1-1.el10.noarch.rpm SHA-256: 7bf8eebac944a32fe7971f0c6657cc6fc5feb145ca185a6eff7210f5a0eb2c3a flightctl-services-1.2.1-1.el10.x86_64.rpm SHA-256: 7e3492e1794a5933e018995ca25fdabbbf0a6da864fbd4d988b63deb2fba7b12 s390x flightctl-agent-1.2.1-1.el10.s390x.rpm SHA-256: 17b65de0a33dc9c6b855ec44027b60e847f2b8aec2c8e6b98608cdf3a266bf68 flightctl-cli-1.2.1-1.el10.s390x.rpm SHA-256: 14a8b331d7d04584ef9acc8047678b5a98730bb740e5395d3d95d8cc5b627e7b flightctl-observability-1.2.1-1.el10.s390x.rpm SHA-256: 828fd8889e422895b9696b14c0e1c9ea432ec40506aa4aa398e8167d0c54e9a3 flightctl-selinux-1.2.1-1.el10.noarch.rpm SHA-256: 7bf8eebac944a32fe7971f0c6657cc6fc5feb145ca185a6eff7210f5a0eb2c3a flightctl-services-1.2.1-1.el10.s390x.rpm SHA-256: f6bb53d73ca9607d833a84f7c6feee043b59d92c9c993b7f2caf7fdb99154694 ppc64le flightctl-agent-1.2.1-1.el10.ppc64le.rpm SHA-256: d5d870ba708838fc218b9c6cfa04ca46967b1498a184fabe7591c72d729d1c92 flightctl-cli-1.2.1-1.el10.ppc64le.rpm SHA-256: 2dee0eabfe134533396931335c5772186368130ae6779753bb4f6eba66b3a6b1 flightctl-observability-1.2.1-1.el10.ppc64le.rpm SHA-256: 70bcf76e09dd8b3166dbf6ebced3231c14a2bbda0ff4b82eb24a53e1cc11dc08 flightctl-selinux-1.2.1-1.el10.noarch.rpm SHA-256: 7bf8eebac944a32fe7971f0c6657cc6fc5feb145ca185a6eff7210f5a0eb2c3a flightctl-services-1.2.1-1.el10.ppc64le.rpm SHA-256: e3124f1a6419c1de202ad4405d8677d3ea27b5664cc01aa1d60fd43d553fc6c8 aarch64 flightctl-agent-1.2.1-1.el10.aarch64.rpm SHA-256: 897f050edd5f5b06a3924646e522a19fed35472d2accb5c6c04e319b0f825ddf flightctl-cli-1.2.1-1.el10.aarch64.rpm SHA-256: ccde589ef5f6202f1dc143e2c4e5c51a09d860270e238c08e8ae4c53b875de81 flightctl-observability-1.2.1-1.el10.aarch64.rpm SHA-256: 1135075b21cbb1d2d5512f88d4f0c47fdaa77874ab173ad5300ee895a7389d99 flightctl-selinux-1.2.1-1.el10.noarch.rpm SHA-256: 7bf8eebac944a32fe7971f0c6657cc6fc5feb145ca185a6eff7210f5a0eb2c3a flightctl-services-1.2.1-1.el10.aarch64.rpm SHA-256: 80965c19ffc04399efbd3a6d70e1f3f614555b5861aa31c1d734d5431a7b8f45 Red Hat Edge Manager 1.2 for RHEL 9 SRPM flightctl-1.2.1-1.el9.src.rpm SHA-256: a8e26da17da6d40ac537f09d62d2aeff5e8a30ca3af02fdae677a7c1300e19a1 x86_64 flightctl-agent-1.2.1-1.el9.x86_64.rpm SHA-256: 33ab92886c7404502115b5817341122609180b3abf0aef9f2ed3d12f0206ec7a flightctl-cli-1.2.1-1.el9.x86_64.rpm SHA-256: 4894b512b7818820d2baa576909a806e75b49bcdb31b57aec16d77166037624f flightctl-observability-1.2.1-1.el9.x86_64.rpm SHA-256: 4fce3bf5a355e1d4e1a2bbb8c3a9a770034287f565003e460fec30f50640cf50 flightctl-selinux-1.2.1-1.el9.noarch.rpm SHA-256: fc127cadc298f5a35d3917430651f3f587666c10d24004a9aeddffd6998da2cb flightctl-services-1.2.1-1.el9.x86_64.rpm SHA-256: 04ddefb5431fa2be20fe96fc5984b3a1badb6125c12af46c0f91f4f64e4b0bfe s390x flightctl-agent-1.2.1-1.el9.s390x.rpm SHA-256: cb24f08f4f5cf89ab0100a5ed6424a028c609e66fc0f97707aaf3a7fce2450ea flightctl-cli-1.2.1-1.el9.s390x.rpm SHA-256: e4a3279c56a2c0ac6d06bec8cd8febfe5055a3007905af94ff950c4bf1ae448e flightctl-observability-1.2.1-1.el9.s390x.rpm SHA-256: 0f88182905b0250986d5347ed534758249d8699905ee66ca2d7f9c3122eb24f6 flightctl-selinux-1.2.1-1.el9.noarch.rpm SHA-256: fc127cadc298f5a35d3917430651f3f587666c10d24004a9aeddffd6998da2cb flightctl-services-1.2.1-1.el9.s390x.rpm SHA-256: be710bd6195f83181bbcb9e1cbfa4c21bd5cf422f0091ccf1511c36bf00ce575 ppc64le flightctl-agent-1.2.1-1.el9.ppc64le.rpm SHA-256: c580b95c8a611d0274872fd1a7b27ba06223238749a472f6bd5bafe786d52780 flightctl-cli-1.2.1-1.el9.ppc64le.rpm SHA-256: eb3b8f577171ba12579b2c32396769f9a1b18f133eb3cd4b238d0a6af5952d7d flightctl-observability-1.2.1-1.el9.ppc64le.rpm SHA-256: 748c57d75ab62a43cd6881dc4ef4233954f7cced0ee55afd6fd7ef6e658b26e5 flightctl-selinux-1.2.1-1.el9.noarch.rpm SHA-256: fc127cadc298f5a35d3917430651f3f587666c10d24004a9aeddffd6998da2cb flightctl-services-1.2.1-1.el9.ppc64le.rpm SHA-256: f21f8dd622d173de452d67b2026cad3390ea4babd21519908a3651e6a96ffcee aarch64 flightctl-agent-1.2.1-1.el9.aarch64.rpm SHA-256: d32141b8653770af1ce592fdbd8c2983f43a2bc5bdaf3920869e79fe312bb45
This security update addresses multiple vulnerabilities in the `flightctl` component of Red Hat Edge Manager 1.2.1, primarily involving denial-of-service through crafted inputs, unauthenticated access to debug endpoints, and cross-site scripting. The CVSS scores for the listed CVEs range from Medium to High, with CVE-2026-33818 scoring 7.5. Affected users should apply the Red Hat-provided patch for Red Hat Edge Manager Version 1.2.1.