Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-63209 — github.com/klauspost/compress: klauspost/compress: Denial of Service via integer overflow in dictionary processing CVE-2026-77403 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation CVE-2026-77404 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection CVE-2026-77406 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting CVE-2026-77407 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Fields CVE-2026-77409 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking CVE-2026-77410 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation CVE-2026-77412 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length CVE-2026-81872 — go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
🎯 Affected products4
- Red Hat Hardened Images
- opentelemetry-collector-contrib-0:0.161.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- opentelemetry-collector-contrib-0:0.161.0-0.1.hum1@src as a component of Red Hat Hardened Images
- opentelemetry-collector-contrib-0:0.161.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation. Workaround: Avoid accepting untrusted values for TLS certificate, key, CA, or server-name paths. Restrict write access to directories and environment settings used to configure those paths, and upgrade applications using amqp091-go to version 1.13.0 or later when available. Workaround: Do not allow untrusted users to control AMQP QoS prefetch settings. Validate configured values are non-negative, and update applications using amqp091-go when a fixed version is available. Workaround: Avoid logging or exporting complete AMQP connection objects and ensure diagnostic tooling redacts credentials. Update applications using amqp091-go when a fixed version is available. Workaround: Use adequately buffered notification channels and ensure event consumers continuously drain them. Update applications using amqp091-go when a fixed version is available. Workaround: Connect only to trusted AMQP brokers, protect broker credentials and transport security, and update applications using amqp091-go when a fixed version is available.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:68290
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-81872
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-77404
- externalhttps://access.redhat.com/security/cve/CVE-2026-77412
- externalhttps://access.redhat.com/security/cve/CVE-2026-77403
- externalhttps://access.redhat.com/security/cve/CVE-2026-77410
- externalhttps://access.redhat.com/security/cve/CVE-2026-77409
- externalhttps://access.redhat.com/security/cve/CVE-2026-77406
- externalhttps://access.redhat.com/security/cve/CVE-2026-77407
- externalhttps://access.redhat.com/security/cve/CVE-2026-93450
- externalhttps://access.redhat.com/security/cve/CVE-2026-63209
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68290.json