RHSA-2026:0996HighCVSS 8.6
Red Hat Security Advisory: OpenShift Container Platform 4.14.61 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-5987 — libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend CVE-2025-8677 — bind: Resource exhaustion via malformed DNSKEY handling CVE-2025-9714 — libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs CVE-2025-40780 — bind: Cache poisoning due to weak PRNG CVE-2025-59375 — firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:0996
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392605
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2395108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405827
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405830
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0996.json