RHSA-2026:44868HighCVSS 7.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
July 24, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-59818 — etcd: etcd: Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines

🎯 Affected products4

  • Red Hat Hardened Images
  • etcd-main@aarch64 as a component of Red Hat Hardened Images
  • etcd-main@src as a component of Red Hat Hardened Images
  • etcd-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.

🔗 References (6)