RHSA-2026:4220HighCVSS 7.5
Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
🎯 Affected products6
- Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-operator-bundle@sha256:7af8be9671b3abd78541307e1dcebdc649057175595ae368485ad6ed7890e7c9_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:63f64a69dfe53d99d6e4daa777e56af3f2a1c2370cdb8846f430694f46264f60_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:6ebdce89c1e02b5cb34554666d28df796b82b19530f34c83ddb4758b52e0940d_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:d3de3556d1b49202cde5fb04941f6b5d364a7b69302b986b052012b72e9c3286_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:fc6cd4a43aa9ca1cf87722be0a600a74c7b6c5adbdd970ce418f149a8f85d7b1_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:4220
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4220.json