Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:24470: Important: podman security update

This Red Hat security advisory addresses three high-severity Denial of Service vulnerabilities (CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVSS 7.5) in the Go crypto/x509 and crypto/tls libraries, which affect podman. The vulnerabilities involve inefficient certificate chain validation and handling of excessive TLS 1.3 key update messages. Affected systems are those running podman on RHEL 10 where the underlying Go version is earlier than 1.25.9 or from 1.26.0 through 1.26.1; remediation requires applying the Red Hat update for podman, which incorporates the patched Go libraries.
Read Full Article →

Red Hat Product Errata RHSA-2026:24470 - Security Advisory Issued: 2026-06-08 Updated: 2026-06-08 RHSA-2026:24470 - Security Advisory Overview Updated Packages Synopsis Important: podman security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for podman is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVEs CVE-2026-32280 CVE-2026-32281 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM podman-5.8.2-3.el10_2.src.rpm SHA-256: d56a45c352088f260ed8ae7c082f7e525e23e892b2e1e44a11138f8ed2cfdfdb x86_64 podman-5.8.2-3.el10_2.x86_64.rpm SHA-256: 6723b5254a23d3575b6a15cea97d0b6d6873b43f1f64d76ec48635b0c449c5ae podman-debuginfo-5.8.2-3.el10_2.x86_64.rpm SHA-256: e7b689fe13c07ea1825769469562a2728363d5c8d73446608ceb3e29e8189a46 podman-debugsource-5.8.2-3.el10_2.x86_64.rpm SHA-256: 84e878b437fc498d0d93b88a3c401f2ac8f3ee2758f56d582b030154a7ca3078 podman-docker-5.8.2-3.el10_2.noarch.rpm SHA-256: 87a3eae8c52c9176c920ce6b18493a784cbff84180e94625daaf5eb8106e078a podman-remote-5.8.2-3.el10_2.x86_64.rpm SHA-256: a369c9ef49f23dc089e9430bdefad154f382dbf504189440d5eed981870576c4 podman-remote-debuginfo-5.8.2-3.el10_2.x86_64.rpm SHA-256: 5d5e3f3cfb7d676ac3c35aca23d7e54d103fd8d75fa031e802fbe86b5b195f76 podman-tests-debuginfo-5.8.2-3.el10_2.x86_64.rpm SHA-256: 3e401fcbfb50646495d5f3b3906716023a9760cc74fdb6344f59b6cc9204753c Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM podman-5.8.2-3.el10_2.src.rpm SHA-256: d56a45c352088f260ed8ae7c082f7e525e23e892b2e1e44a11138f8ed2cfdfdb x86_64 podman-5.8.2-3.el10_2.x86_64.rpm SHA-256: 6723b5254a23d3575b6a15cea97d0b6d6873b43f1f64d76ec48635b0c449c5ae podman-debuginfo-5.8.2-3.el10_2.x86_64.rpm SHA-256: e7b689fe13c07ea1825769469562a2728363d5c8d73446608ceb3e29e8189a46 podman-debugsource-5.8.2-3.el10_2.x86_64.rpm SHA-256: 84e878b437fc498d0d93b88a3c401f2ac8f3ee2758f56d582b030154a7ca3078 podman-docker-5.8.2-3.el10_2.noarch.rpm SHA-256: 87a3eae8c52c9176c920ce6b18493a784cbff84180e94625daaf5eb8106e078a podman-remote-5.8.2-3.el10_2.x86_64.rpm SHA-256: a369c9ef49f23dc089e9430bdefad154f382dbf504189440d5eed981870576c4 podman-remote-debuginfo-5.8.2-3.el10_2.x86_64.rpm SHA-256: 5d5e3f3cfb7d676ac3c35aca23d7e54d103fd8d75fa031e802fbe86b5b195f76 podman-tests-debuginfo-5.8.2-3.el10_2.x86_64.rpm SHA-256: 3e401fcbfb50646495d5f3b3906716023a9760cc74fdb6344f59b6cc9204753c Red Hat Enterprise Linux for IBM z Systems 10 SRPM podman-5.8.2-3.el10_2.src.rpm SHA-256: d56a45c352088f260ed8ae7c082f7e525e23e892b2e1e44a11138f8ed2cfdfdb s390x podman-5.8.2-3.el10_2.s390x.rpm SHA-256: 472ff4381c6881cde936060b2ab98b10ff2c0590ab3180c903da77e59c73ac33 podman-debuginfo-5.8.2-3.el10_2.s390x.rpm SHA-256: 482ee4ace03ca53212cd3ceb8fbc85058660400567a87861534346f74a0a98ce podman-debugsource-5.8.2-3.el10_2.s390x.rpm SHA-256: 8da5754c4343eeb551a06dddd9f8fee194d94094db30893b4899a180a432d7b6 podman-docker-5.8.2-3.el10_2.noarch.rpm SHA-256: 87a3eae8c52c9176c920ce6b18493a784cbff84180e94625daaf5eb8106e078a podman-remote-5.8.2-3.el10_2.s390x.rpm SHA-256: 861791444653c28024926c0e7f0fdf839dd0d2b26c69ccb1494619f6de8688a0 podman-remote-debuginfo-5.8.2-3.el10_2.s390x.rpm SHA-256: 1a80669eaf4fd88185b027f3375119095487f62c19448c03149dc11e027da94f podman-tests-debuginfo-5.8.2-3.el10_2.s390x.rpm SHA-256: 7db6ba991853ea01e70cf9f0942a8648a9d59e8a099e5abdeef87a6f6786957d Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM podman-5.8.2-3.el10_2.src.rpm SHA-256: d56a45c352088f260ed8ae7c082f7e525e23e892b2e1e44a11138f8ed2cfdfdb s390x podman-5.8.2-3.el10_2.s390x.rpm SHA-256: 472ff4381c6881cde936060b2ab98b10ff2c0590ab3180c903da77e59c73ac33 podman-debuginfo-5.8.2-3.el10_2.s390x.rpm SHA-256: 482ee4ace03ca53212cd3ceb8fbc85058660400567a87861534346f74a0a98ce podman-debugsource-5.8.2-3.el10_2.s390x.rpm SHA-256: 8da5754c4343eeb551a06dddd9f8fee194d94094db30893b4899a180a432d7b6 podman-docker-5.8.2-3.el10_2.noarch.rpm SHA-256: 87a3eae8c52c9176c920ce6b18493a784cbff84180e94625daaf5eb8106e078a podman-remote-5.8.2-3.el10_2.s390x.rpm SHA-256: 861791444653c28024926c0e7f0fdf839dd0d2b26c69ccb1494619f6de8688a0 podman-remote-debuginfo-5.8.2-3.el10_2.s390x.rpm SHA-256: 1a80669eaf4fd88185b027f3375119095487f62c19448c03149dc11e027da94f podman-tests-debuginfo-5.8.2-3.el10_2.s390x.rpm SHA-256: 7db6ba991853ea01e70cf9f0942a8648a9d59e8a099e5abdeef87a6f6786957d Red Hat Enterprise Linux for Power, little endian 10 SRPM podman-5.8.2-3.el10_2.src.rpm SHA-256: d56a45c352088f260ed8ae7c082f7e525e23e892b2e1e44a11138f8ed2cfdfdb ppc64le podman-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 044b9e02ba37b80facd0d93f1540f1a245a26ae7aaf76413244bd3e8be1d245e podman-debuginfo-5.8.2-3.el10_2.ppc64le.rpm SHA-256: ac923ffb1a03ab4e6c7e08d441bb1cbea11dfe9656107c1f235a56221d54cb6d podman-debugsource-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 20eecebb62de59c9dec1720dfdd587d0960a38f0c25cd52f56af0a90c0ad4532 podman-docker-5.8.2-3.el10_2.noarch.rpm SHA-256: 87a3eae8c52c9176c920ce6b18493a784cbff84180e94625daaf5eb8106e078a podman-remote-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 713b8b14a87b390074d775fe2c6e20ab4e3f06628dbbe79a25b1d637b523c84a podman-remote-debuginfo-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 26f9235494ef59bd39af37c705663b1538971932ff46b1ca18b06cc064effab6 podman-tests-debuginfo-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 4c7e867411a6048b77c7c80f271b2229dac397671fe8dfb42c4b65187e3a554e Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM podman-5.8.2-3.el10_2.src.rpm SHA-256: d56a45c352088f260ed8ae7c082f7e525e23e892b2e1e44a11138f8ed2cfdfdb ppc64le podman-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 044b9e02ba37b80facd0d93f1540f1a245a26ae7aaf76413244bd3e8be1d245e podman-debuginfo-5.8.2-3.el10_2.ppc64le.rpm SHA-256: ac923ffb1a03ab4e6c7e08d441bb1cbea11dfe9656107c1f235a56221d54cb6d podman-debugsource-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 20eecebb62de59c9dec1720dfdd587d0960a38f0c25cd52f56af0a90c0ad4532 podman-docker-5.8.2-3.el10_2.noarch.rpm SHA-256: 87a3eae8c52c9176c920ce6b18493a784cbff84180e94625daaf5eb8106e078a podman-remote-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 713b8b14a87b390074d775fe2c6e20ab4e3f06628dbbe79a25b1d637b523c84a podman-remote-debuginfo-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 26f9235494ef59bd39af37c705663b1538971932ff46b1ca18b06cc064effab6 podman-tests-debuginfo-5.8.2-3.el10_2.ppc64le.rpm SHA-256: 4c7e867411a6048b77c7c80f271b2229dac397671fe8dfb42c4b65187e3a554e Red Hat Enterprise Linux for ARM 64 10 SRPM podman-5.8.2-3.el10_2.src.rpm S

Share this article