Red Hat Security Advisory: Updated Red Hat OpenStack Platform 16.2 director Operator container images
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
🎯 Affected products5
- Red Hat OpenStack Platform 16.2
- registry.redhat.io/rhosp-rhel8/osp-director-agent@sha256:27d5e76c8a96c0a5b2a5c8625390b8a92c9858e9cce962bf7c6d74b2b53f50a1_amd64 as a component of Red Hat OpenStack Platform 16.2
- registry.redhat.io/rhosp-rhel8/osp-director-downloader@sha256:bb19d69d370ad281c687b1d9b373881fdd7f28fdf55a05ca11edd53219b3f127_amd64 as a component of Red Hat OpenStack Platform 16.2
- registry.redhat.io/rhosp-rhel8/osp-director-operator-bundle@sha256:14e06abfb86c74e455e6c96156cd7bb588ddcef5629037fd9ac58afd4796209b_amd64 as a component of Red Hat OpenStack Platform 16.2
- registry.redhat.io/rhosp-rhel8/osp-director-operator@sha256:6647286b1af638916fce0f146ba4f0b0dde8eeff512a2605dc30a86abe190699_amd64 as a component of Red Hat OpenStack Platform 16.2
✅ Remediation
The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io or registry.access.redhat.com using the 'podman pull' command. For more information about the images, search the image name in the Red Hat Ecosystem Catalog. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:65964
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65964.json