Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:38504: Important: container-tools:rhel8 security update

This Red Hat security update addresses three vulnerabilities in the container-tools module for RHEL 8: a high-severity DoS in the Go net package via long CNAME responses (CVE-2026-33811, CVSS 7.5), a medium-severity DoS in golang.org/x/crypto/ssh via crafted SSH certificates (CVE-2026-39835, CVSS 5.3), and a high-severity information disclosure in Podman via malicious container image environment variables (CVE-2026-57231, CVSS 7.5). The underlying Go components are fixed in versions 1.25.10, 1.26.3, and 0.52.0 respectively, while Podman is fixed in version 5.8.4. IT professionals should apply the provided Red Hat update to affected RHEL 8 systems.
Read Full Article →

Red Hat Product Errata RHSA-2026:38504 - Security Advisory Issued: 2026-07-13 Updated: 2026-07-13 RHSA-2026:38504 - Security Advisory Overview Updated Packages Synopsis Important: container-tools:rhel8 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2480680 - CVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate BZ - 2493620 - CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables CVEs CVE-2026-33811 CVE-2026-39835 CVE-2026-57231 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM aardvark-dns-1.10.1-2.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 4d3173a0e81c53ae7838f0ff82fc8efa6a5e63cc0b23230dfff114235e050d76 buildah-1.33.14-4.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: ab2d3e79b18aa61cf4438d7858682529eb5a3646e0250875867012ca47f2d91c cockpit-podman-84.1-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 65ad1575d41d4d68af4f63bb0abd637ec8024895f826e69bfcea6052a34e7ed2 conmon-2.1.10-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: d8c67e248dad3481b3880a0fa48f489c9e25772ca9d7e7b715429fc711090a85 container-selinux-2.229.0-3.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 8be9292ecb562739e1610295b251cb8154735d12af67364d2fcdf9be7b5a5f93 containernetworking-plugins-1.4.0-8.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 37d31e9088e863d9a60e6a28998f9f99f8b96b394dbfa46b7ba4dc1ab51873cc containers-common-1-82.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: de4031c6e18edac96f97967a9df171db5ee59736e444c7f9691477ed77569c5c criu-3.18-5.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 1970de9f4a588228172402ec1af09f614174b54af55c9e07c843980148b69fb8 crun-1.14.3-2.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: b776cade35945b60aa293820aba0c96aa3ead08612edd8fa1b108525074a6613 fuse-overlayfs-1.13-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 93b7fc9b56546e8e9bb6a2cb5fdaa89ed6ae4444cc7ecd661fc2d8c599041e79 libslirp-4.4.0-2.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 3d7a1461c8f49f7c31940a07178e1b2e246e998231c47ae79329aa648d81980c netavark-1.10.3-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: c2f3b54cb37d3d02595d4fdf820dc161a6433d15108dc8d66bec459c673602b8 oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 4ca0d927fe83a8bb01a3e9c26deb215ac5e6618d7189d78a3ae10492ef74ca1b podman-4.9.4-34.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 6f9aec47b0d1d44d88802f3f0409d60971ab1a62417a4d349663b96dd3e51b55 python-podman-4.9.0-3.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 9de534f6d0adfdd8ac77e9d4c6f042669d561c0211887150eca5f5c283699021 runc-1.2.9-4.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: ba4f9d71a8fbc336d9e2b728d763576349adcbb104f4fe407ed1027196cc0891 skopeo-1.14.6-2.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: f63549ec293a3e8636de3cf8067f7f6d07fb4155cdbfe7af64432b56cf8ff5b9 slirp4netns-1.2.3-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 8da0b46d2f31e47bb2b2ae0d4aae309cb67a019236fadfe4d23234c499bb3659 toolbox-0.0.99.5.1-1.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: 4d7e6925853cec25b27ac7d98d809c7cd27c250eb448df5cb800791da2c67f6c udica-0.2.6-21.module+el8.10.0+24510+6ea3880e.src.rpm SHA-256: d4e3d3046ddf7b1bfa23733756956a026f5fbe0a1bf7c715aaf6620e155408ef x86_64 cockpit-podman-84.1-1.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 33e8e22ad8af3a4ecad732fb5f1ec32612acfb1aae3df5ce4ae15523b96aa127 container-selinux-2.229.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 780d52d8d0ad61a470deec7b0456656d17de223aa0ebd8d35442c42c62c21d03 podman-docker-4.9.4-34.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: a438745b400cc4675f47385e5bbacbad0dc81e4cf870c67861708755c47e4dd1 python3-podman-4.9.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 6986ff3d4cb6a57335445bacd8239eecfa1f2bed20ab596c62d46fb9741e8370 udica-0.2.6-21.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: bed4dcf0d857d1f609dbde127df1f7a9eb035fce2bd82a03835478799aa96edc cockpit-podman-84.1-1.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 33e8e22ad8af3a4ecad732fb5f1ec32612acfb1aae3df5ce4ae15523b96aa127 container-selinux-2.229.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 780d52d8d0ad61a470deec7b0456656d17de223aa0ebd8d35442c42c62c21d03 podman-docker-4.9.4-34.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: a438745b400cc4675f47385e5bbacbad0dc81e4cf870c67861708755c47e4dd1 python3-podman-4.9.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 6986ff3d4cb6a57335445bacd8239eecfa1f2bed20ab596c62d46fb9741e8370 udica-0.2.6-21.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: bed4dcf0d857d1f609dbde127df1f7a9eb035fce2bd82a03835478799aa96edc cockpit-podman-84.1-1.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 33e8e22ad8af3a4ecad732fb5f1ec32612acfb1aae3df5ce4ae15523b96aa127 container-selinux-2.229.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 780d52d8d0ad61a470deec7b0456656d17de223aa0ebd8d35442c42c62c21d03 podman-docker-4.9.4-34.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: a438745b400cc4675f47385e5bbacbad0dc81e4cf870c67861708755c47e4dd1 python3-podman-4.9.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 6986ff3d4cb6a57335445bacd8239eecfa1f2bed20ab596c62d46fb9741e8370 udica-0.2.6-21.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: bed4dcf0d857d1f609dbde127df1f7a9eb035fce2bd82a03835478799aa96edc aardvark-dns-1.10.1-2.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 87d9df6c21fe3a868ce14cf1f0075f96f7ff7e3438fc8ce73349697c60f863b1 buildah-1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: fe69e9ea2cb34729f0552c0f9ada8f8f46574212b3919f90ccbb0d4ccae711aa buildah-debuginfo-1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 9b4e4a1d016e8260a76749b7b1c4ba21540dafb3935e812cc0d0b4a099ac5b79 buildah-debugsource-1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: f7af4742b03ff0304d7b6e26a8a8d67c102c2203eb224126c8da7c124a5cce07 buildah-tests-1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: dd45acdb29990ad5e830420909be3f405e18e924e09c48e0055a8b05d003cb66 buildah-tests-debuginfo-1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 1018b5e7f2202ee5ee6a1a1cb12843d190e1e2b671ca790f035184b689ba02cf cockpit-podman-84.1-1.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 33e8e22ad8af3a4ecad732fb5f1ec32612acfb1aae3df5ce4ae15523b96aa127 conmon-2.1.10-1.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 1e5557c2cb03740e5b9b6a6cad71c01f392e5bd34629be432fffa18fbc099ac6 conmon-debuginfo-2.1.10-1.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 21123233f3a9db923e0659b5b321e9ef9df79625b2886c981077514f4d8fcc32 conmon-debugsource-2.1.10-1.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: fcebc86ac086a56996790902929ae2de1e1126b737d327ffd96bc84b86fc05b3 container-selinux-2.229.0-3.module+el8.10.0+24510+6ea3880e.noarch.rpm SHA-256: 780d52d8d0ad61a470deec7b0456656d17de223aa0ebd8d35442c42c62c21d03 containernetworking-plugins-1.4.0-8.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 1681cf110e5c572409cfda7c8824f4108367762815603e5cc90de76fbd1ac08f containernetworking-plugins-debuginfo-1.4.0-8.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 3b2c1eac9e95488ecc435cf3402c018580894f156219d557bd2a23b91b61a451 containernetworking-plugins-debugsource-1.4.0-8.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 6e9a0fe532424eec016339f99ade677e9baca627dce6897d8be93b37c8ea1b05 containers-common-1-82.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 7fe472999d62c86820cc4a6aab3698e2fe065d548892bd3390ac97dad1c24d95 crit-3.18-5.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: 9ca53a9549cfea8c33c38b48f25ea6935c037db6c4f1cda22eed5c0d828a96cf criu-3.18-5.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: f86a4c96663f81b4327a84e627359d09c37bfa6b75209132bfd7958168e8d6c5 criu-debuginfo-3.18-5.module+el8.10.0+24510+6ea3880e.x86_64.rpm SHA-256: fbdaad79723e3dd9eda

Share this article