Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39817 — cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction CVE-2026-39819 — cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack CVE-2026-39827 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings CVE-2026-39834 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42500 — golang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-46598 — golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input
🎯 Affected products14
- Red Hat Hardened Images
- golang1.26-0:1.26.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- golang1.26-0:1.26.8-0.1.hum1@src as a component of Red Hat Hardened Images
- golang1.26-0:1.26.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- golang1.26-bin-0:1.26.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- golang1.26-bin-0:1.26.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- golang1.26-docs-0:1.26.8-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- golang1.26-docs-0:1.26.8-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- golang1.26-misc-0:1.26.8-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- golang1.26-misc-0:1.26.8-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- golang1.26-src-0:1.26.8-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- golang1.26-src-0:1.26.8-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- golang1.26-tests-0:1.26.8-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- golang1.26-tests-0:1.26.8-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: No mitigation is available for this vulnerability. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate this issue, restrict the exposure of the SSH agent to untrusted sources. Avoid enabling SSH agent forwarding when connecting to untrusted hosts or environments. Ensure that applications interacting with `golang.org/x/crypto/ssh/agent` validate all inputs to prevent malformed data from being processed. Reloading or restarting SSH services may be required for changes to take effect.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:62391
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-42500
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-46598
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-39834
- externalhttps://access.redhat.com/security/cve/CVE-2026-39827
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-39817
- externalhttps://access.redhat.com/security/cve/CVE-2026-39819
- externalhttps://access.redhat.com/security/cve/CVE-2026-56851
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62391.json