RHSA-2026:66401HighCVSS 7.8

Red Hat Security Advisory: Red Hat OpenStack Platform 17.1 security and bug fix advisory

Published
September 10, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-24708 — openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages

🎯 Affected products147

  • Red Hat OpenStack Platform 17.1
  • ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • collectd-sensubility-0:0.2.1-6.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • collectd-sensubility-0:0.2.1-6.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • collectd-sensubility-debuginfo-0:0.2.1-6.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-0:24.3.4.2-7.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • erlang-asn1-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-asn1-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-compiler-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-crypto-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-crypto-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-debugsource-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-eldap-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-erl_interface-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-erts-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-erts-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-inets-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-kernel-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-mnesia-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-odbc-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-os_mon-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-os_mon-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-parsetools-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-public_key-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-runtime_tools-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • erlang-runtime_tools-debuginfo-0:24.3.4.2-7.el9ost.x86_64 as a component of Red Hat OpenStack Platform 17.1
  • +117 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (18)