Red Hat Security Advisory: Satellite 6.16.7 Async Update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-6176 — Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS CVE-2025-14550 — Django: Django: Denial of Service via crafted request with duplicate headers CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-0980 — rubyipmi: Red Hat Satellite: Remote Code Execution in rubyipmi via malicious BMC username CVE-2026-1207 — Django: Django: SQL Injection via RasterField band index parameter CVE-2026-1285 — Django: Django: Denial of Service via crafted HTML inputs CVE-2026-1287 — Django: Django: SQL Injection via crafted column aliases CVE-2026-1312 — Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() CVE-2026-1530 — fog-kubevirt: fog-kubevirt: Man-in-the-Middle vulnerability due to disabled certificate validation CVE-2026-1531 — foreman-kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification CVE-2026-1961 — forman: Foreman: Remote Code Execution via command injection in WebSocket proxy
🎯 Affected products100
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 9
- foreman-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-0:3.12.0.14-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-0:3.12.0.14-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-cli-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-cli-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-debug-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-debug-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-dynflow-sidekiq-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-dynflow-sidekiq-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-ec2-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-ec2-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-journald-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-journald-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-libvirt-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-libvirt-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-openstack-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-openstack-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-ovirt-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-ovirt-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-pcp-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-pcp-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-postgresql-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-postgresql-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-redis-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-redis-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-service-0:3.12.0.14-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-service-0:3.12.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- +70 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications utilizing Django should avoid processing untrusted HTML content through the `django.utils.text.Truncator.chars()` and `Truncator.words()` methods with `html=True`, or the `truncatechars_html` and `truncatewords_html` template filters. Restrict the use of these functions to only trusted inputs where the HTML structure is controlled and validated. Workaround: To mitigate this issue, ensure that a Certificate Authority (CA) certificate is explicitly configured when setting up the connection to OpenShift in foreman_kubevirt. This will enable SSL verification and prevent Man-in-the-Middle attacks. Refer to the foreman_kubevirt documentation for specific instructions on configuring CA certificates. A restart or service reload may be required for the changes to take effect.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:5971
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2408762
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429874
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2433784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2433786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436338
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2437036
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2437111
- externalhttps://issues.redhat.com/browse/SAT-42870
- externalhttps://issues.redhat.com/browse/SAT-42880
- externalhttps://issues.redhat.com/browse/SAT-42883
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5971.json