RHSA-2026:44868HighCVSS 7.5
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-59818 — etcd: etcd: Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines
🎯 Affected products4
- Red Hat Hardened Images
- etcd-main@aarch64 as a component of Red Hat Hardened Images
- etcd-main@src as a component of Red Hat Hardened Images
- etcd-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:44868
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-59818
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44868.json