- What: Security update for Red Hat Satellite 6.16
- Impact: Systems using Satellite may be vulnerable if not updated
Red Hat Product Errata RHSA-2026:50223 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:50223 - Security Advisory Overview Updated Packages Synopsis Important: Satellite 6.16.12 Async Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Satellite 6.16 for RHEL 8 and RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): puppet-agent: Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) puppetserver: HTTP request smuggling via chunked extension quoted-string parsing (CVE-2026-2332) python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379) python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380) python-pillow: Pillow: Denial of Service via crafted PCF font data (CVE-2026-54059) python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060) python-pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197) python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526) rubygem-faraday-cookie_jar: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-em_ http: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-em_synchrony: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-excon: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-httpclient: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday_middleware: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-multipart: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-net_ http: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-net_http_persistent: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-patron: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-rack: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-faraday-retry: Faraday: Denial of Service via crafted nested query strings (CVE-2026-54297) rubygem-katello: missing repository authorization in content_uploads exposes cross-product content existence (CVE-2026-12515) rubygem-nokogiri: Nokogiri: Denial of Service or Information Disclosure via invalid encoding handling (CVE-2026-57236) libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864) Bug Fix(es): scap-security-guide-satellite: Update of scap-security-guide-satellite package sources 'Katello::Errors::Pulp3Error: nextval: reached maximum value of sequence "container_blobmanifest_id_seq"' during container image sync Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Satellite Extended Update Support 6.16 for RHEL 9 x86_64 Red Hat Satellite Extended Update Support 6.16 for RHEL 8 x86_64 Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 9 x86_64 Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 8 x86_64 Fixes BZ - 2396054 - CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap BZ - 2458187 - CVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing BZ - 2460425 - CVE-2026-48864 libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data BZ - 2482734 - CVE-2026-48526 python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens BZ - 2489812 - CVE-2026-12515 katello: missing repository authorization in content_uploads exposes cross-product content existence BZ - 2492252 - CVE-2026-54297 faraday: Faraday: Denial of Service via crafted nested query strings BZ - 2492952 - CVE-2026-57236 nokogiri: Nokogiri: Denial of Service or Information Disclosure via invalid encoding handling BZ - 2497452 - CVE-2026-55379 python-pillow: Pillow: Denial of Service via crafted BDF font file BZ - 2497455 - CVE-2026-55380 python-pillow: Pillow: Denial of Service via crafted GD 2.x image file BZ - 2497464 - CVE-2026-54059 python-pillow: Pillow: Denial of Service via crafted PCF font data BZ - 2497466 - CVE-2026-54060 python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files BZ - 2500043 - CVE-2026-59197 Pillow: Pillow: Native heap out-of-bounds write SAT-48146 - Update of scap-security-guide-satellite package sources [satellite_6.16] SAT-48289 - 'Katello::Errors::Pulp3Error: nextval: reached maximum value of sequence "container_blobmanifest_id_seq"' during container image sync [satellite_6.16] SAT-44868 - Switch Satellite 6.16 to OpenVox CVEs CVE-2025-9230 CVE-2026-2332 CVE-2026-12515 CVE-2026-48526 CVE-2026-48864 CVE-2026-54059 CVE-2026-54060 CVE-2026-54297 CVE-2026-55379 CVE-2026-55380 CVE-2026-57236 CVE-2026-59197 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM rubygem-foreman_maintain-1.7.15-1.el9sat.src.rpm SHA-256: 34cfe90044927770882c360869ae7fe1a8edc12abed8dc932c050508f8026f1e satellite-6.16.12-1.el9sat.src.rpm SHA-256: c050b090306fa637257e4a0f5e0bfbfe886c5e0ec07b70c457404cf57388838c x86_64 rubygem-foreman_maintain-1.7.15-1.el9sat.noarch.rpm SHA-256: b1da810f2d00ebd7c164960cb3d23706d04d64346829f7a2b916f868890377a2 satellite-cli-6.16.12-1.el9sat.noarch.rpm SHA-256: d7b7d75e387446a5472499755754f5c8c0d00dd2e888a8b07ad8b9d3dfec3a31 Red Hat Enterprise Linux for x86_64 8 SRPM rubygem-foreman_maintain-1.7.15-1.el8sat.src.rpm SHA-256: 11642657dafe8137e627adc9917c3d352263e2acfeec46f94937e10f6b287445 satellite-6.16.12-1.el8sat.src.rpm SHA-256: 55d09c105aa5db52f3001ac5269743d13a34f86dee2e0c756b80dcb530ad52f7 x86_64 rubygem-foreman_maintain-1.7.15-1.el8sat.noarch.rpm SHA-256: e3d32f2f72b9b53cebfa011894e9af858ef117be590669bbdc291cb26b4e7804 satellite-cli-6.16.12-1.el8sat.noarch.rpm SHA-256: aa54c9bc47b9d186a966011dbdae7e79d90d0dbce63d58a1c4d448a0683da546 Red Hat Satellite Extended Update Support 6.16 for RHEL 9 SRPM foreman-installer-3.12.0.8-1.el9sat.src.rpm SHA-256: daa0e49c1e59cb9a0168524fcc9a0ddb63fe08c3f00dd0ef1d64a87bf404da9c openvox-agent-8.24.1-3.el9sat.src.rpm SHA-256: f2be77937a849612488c606cc9433f75b8656f276bfe430afb41de39c695cfa9 openvox-server-8.14.1-1.el9sat.src.rpm SHA-256: a78d21484629a731d6b66eaca9fb0c7c8a5a489860b3967a42f1b016a727a1a8 python-pillow-12.3.0-1.el9pc.src.rpm SHA-256: 94338a20b1c7d6e87fb2c27aedcd96d952678e377eb207294b01907b59ea4150 python-pulp-container-2.20.10-2.el9pc.src.rpm SHA-256: 0212f07dfa5b2f2d5b508e4e1e11095a4deb19ab703b5e59c030a8f19ac77b23 python-pyjwt-2.13.0-1.el9pc.src.rpm SHA-256: f049d0098fc36ef0e106de687289047f0a431a6b53750b3ea2cea96eb799a460 python-pysequoia-0.1.33-1.el9pc.src.rpm SHA-256: dd5fdf45e0a02eb663ad465631c4a6a425289202fe964e55b8a1c7328949359a rubygem-faraday-1.10.6-1.el9sat.src.rpm SHA-256: 74f638434ff19a9e703f2792f3cb8bc1fc2dc467aecbfd97a7dd648505d03b9f rubygem-foreman_maintain-1.7.15-1.el9sat.src.rpm SHA-256: 34cfe90044927770882c360869ae7fe1a8edc12abed8dc932c050508f8026f1e rubygem-katello-4.14.0.21-1.el9sat.src.rpm SHA-256: 4186393dadcad1e1b2748beee9d2f4ba579001b0262fd0e401ad5629cd709008 rubygem-nokogiri-1.15.7-3.el9sat.src.rpm SHA-256: eb84e56282b26a78e6875d5187445e01302153082e651af00836f80902a64ad0 satellite-6.16.12-1.el9sat.src.rpm SHA-256: c050b090306fa637257e4a0f5e0bfbfe886c5e0ec07b70c457404cf57388838c scap-security-guide-satellite-1.0.6-1.el9sat.src.rpm SHA-256: 4c29d812196f98389c918673184a5cefe8308aa2dcdfd00333b8e394b6bc68c5 x86_64 foreman-installer-3.12.0.8-1.el9sat.noarch.rpm SHA-256: 7256700cd8d2c1adb5ea74a11bbcaaabbfe32e88c147582de70d25fc91da701d foreman-installer-katello-3.12.0.8-1.el9sat.noarch.rpm SHA-256: 8808499d57890f2e20a68fcb10a60760adead73eda2654ecb9dc8450f9e237e7 openvox-agent-8.24.1-3.el9sat.x86_64.rpm SHA-256: 0877931b6cfd178af8f547fdbf4f1efd756ed17bcb524408d2389e02dce2ea57 openvox-server-8.14.1-1.el9sat.noarch.rpm SHA-256: 04acd810d2fd8ade1afabecc237f1b77b72d21f933a987ced727aebb77332169 python3.11-pillow-12.3.0-1.el9pc.x86_64.rpm SHA-256: 18055e730527134d122723e7edfbe83075ac96924fd002318967ae33d60e89de python3.11-pulp-container-2.20.10-2.el9pc.noarch.rpm SHA-256: c87dda53e363890512093830eef35da5c8749ca24476fbcf0e66caa90b25f2aa python3.11-pyjwt+crypto-2.13.0-1.el9pc.noarch.rpm SHA-256: a66a3dd4469937af07c65f1eaf09742eb51caf243e9685df9da9fc97ff5cdfb9 python3.11-pyjwt-2.13.0-1.el9pc.noarch.rpm SHA-256: e62fd78deed871ca5fdd6dff4dab1c68454e2071eb2c8af10c97f97b187329d8 python3.11-pysequoia-0.1.33-1.el9pc