RHSA-2026:10754HighCVSS 8.1

Red Hat Security Advisory: RHUI 4.11.4 security update - python-pyOpenSSL

Published
April 27, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow

🎯 Affected products3

  • RHUI 4 for RHEL 8
  • python-pyOpenSSL-0:24.1.0-2.el8ui.src as a component of RHUI 4 for RHEL 8
  • python3.11-pyOpenSSL-0:24.1.0-2.el8ui.noarch as a component of RHUI 4 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions on how to apply this update, see: https://docs.redhat.com/en/documentation/red_hat_update_infrastructure/4/html/migrating_red_hat_update_infrastructure/assembly_upgrading-red-hat-update-infrastructure_migrating-red-hat-update-infrastructure Note: While there is no updated version of rhui-installer, for this update to take effect, it is necessary to rerun rhui-installer on the RHUA node and to reinstall the CDS nodes, as described in the documentation. For other information, see the product documentation: https://docs.redhat.com/en/documentation/red_hat_update_infrastructure/4 Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes.

🔗 References (4)