Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:36776: Important: rhc security update

A Denial of Service vulnerability (CVE-2026-33811, CVSS 7.5 High) exists in the Go net package where a long CNAME response in a `LookupCNAME` call can crash the rhc client tool. The underlying Go versions affected are below 1.25.10, or from 1.26.0 to below 1.26.3. The fix is included in the updated rhc packages for Red Hat Enterprise Linux 8, which incorporate the patched Go versions 1.25.10 or 1.26.3.
Read Full Article →

Red Hat Product Errata RHSA-2026:36776 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36776 - Security Advisory Overview Updated Packages Synopsis Important: rhc security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rhc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description rhc is a client tool and daemon that connects the system to Red Hat hosted services enabling system and subscription management. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVEs CVE-2026-33811 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f x86_64 rhc-0.2.5-8.el8_10.x86_64.rpm SHA-256: 315f61ad3e563608fcab5624704db7d8578a845f7ae00812e4295d863aef60fd rhc-debuginfo-0.2.5-8.el8_10.x86_64.rpm SHA-256: 158135a3804c463cdab75f64f8cfd9158ad0814c9d17d91e5e227206cdf40462 rhc-debugsource-0.2.5-8.el8_10.x86_64.rpm SHA-256: 6149c6f88a8a5d0e6d695643cb4541ecae03c9d9a2718409256cabcfa2d0777b Red Hat Enterprise Linux for IBM z Systems 8 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f s390x rhc-0.2.5-8.el8_10.s390x.rpm SHA-256: 5f28e219693ad32fcac999837465ef9e5fd51d3f17d5265290e52a47a843e833 rhc-debuginfo-0.2.5-8.el8_10.s390x.rpm SHA-256: cd0ee329aeec428801077554c5e9dfa288b6a51e4c219dbf44da97b02616e615 rhc-debugsource-0.2.5-8.el8_10.s390x.rpm SHA-256: 206a36f125cca96b20c8a64b95fbf2b99b51d2f4aa9b8503b79ea12f72e2cac9 Red Hat Enterprise Linux for Power, little endian 8 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f ppc64le rhc-0.2.5-8.el8_10.ppc64le.rpm SHA-256: 9b8493df18f70eb75a07af28caf30237cda97e65df525bcb8e82ab59efc4de78 rhc-debuginfo-0.2.5-8.el8_10.ppc64le.rpm SHA-256: 900f08bd607aa70d5db0f9a4910d3dc3c093505c8aa3b9c3c7fba7345c47a831 rhc-debugsource-0.2.5-8.el8_10.ppc64le.rpm SHA-256: 949e50ec038d9cd4242e20b4c3d9bc4f9a65b1c007cb8d016615ed5049737e4b Red Hat Enterprise Linux for ARM 64 8 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f aarch64 rhc-0.2.5-8.el8_10.aarch64.rpm SHA-256: c8a2dc65c0c31d376e7194eb28f961a6f4a0b653b633220d178c99170fff6a16 rhc-debuginfo-0.2.5-8.el8_10.aarch64.rpm SHA-256: 6c4f0323e6023975995d2c3a8c688d1b720a3faba21e0dccb5cdc69cc4e4d630 rhc-debugsource-0.2.5-8.el8_10.aarch64.rpm SHA-256: 9d7dccd6456d9fa33a111685fbf2978020cb3dec743b48236321767d9cb78f31 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f x86_64 rhc-0.2.5-8.el8_10.x86_64.rpm SHA-256: 315f61ad3e563608fcab5624704db7d8578a845f7ae00812e4295d863aef60fd rhc-debuginfo-0.2.5-8.el8_10.x86_64.rpm SHA-256: 158135a3804c463cdab75f64f8cfd9158ad0814c9d17d91e5e227206cdf40462 rhc-debugsource-0.2.5-8.el8_10.x86_64.rpm SHA-256: 6149c6f88a8a5d0e6d695643cb4541ecae03c9d9a2718409256cabcfa2d0777b Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f aarch64 rhc-0.2.5-8.el8_10.aarch64.rpm SHA-256: c8a2dc65c0c31d376e7194eb28f961a6f4a0b653b633220d178c99170fff6a16 rhc-debuginfo-0.2.5-8.el8_10.aarch64.rpm SHA-256: 6c4f0323e6023975995d2c3a8c688d1b720a3faba21e0dccb5cdc69cc4e4d630 rhc-debugsource-0.2.5-8.el8_10.aarch64.rpm SHA-256: 9d7dccd6456d9fa33a111685fbf2978020cb3dec743b48236321767d9cb78f31 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f ppc64le rhc-0.2.5-8.el8_10.ppc64le.rpm SHA-256: 9b8493df18f70eb75a07af28caf30237cda97e65df525bcb8e82ab59efc4de78 rhc-debuginfo-0.2.5-8.el8_10.ppc64le.rpm SHA-256: 900f08bd607aa70d5db0f9a4910d3dc3c093505c8aa3b9c3c7fba7345c47a831 rhc-debugsource-0.2.5-8.el8_10.ppc64le.rpm SHA-256: 949e50ec038d9cd4242e20b4c3d9bc4f9a65b1c007cb8d016615ed5049737e4b Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM rhc-0.2.5-8.el8_10.src.rpm SHA-256: 97deb2a945ede3428441662944488064dcf8d9c7cd8fc807e8281c8fa602706f s390x rhc-0.2.5-8.el8_10.s390x.rpm SHA-256: 5f28e219693ad32fcac999837465ef9e5fd51d3f17d5265290e52a47a843e833 rhc-debuginfo-0.2.5-8.el8_10.s390x.rpm SHA-256: cd0ee329aeec428801077554c5e9dfa288b6a51e4c219dbf44da97b02616e615 rhc-debugsource-0.2.5-8.el8_10.s390x.rpm SHA-256: 206a36f125cca96b20c8a64b95fbf2b99b51d2f4aa9b8503b79ea12f72e2cac9 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article