Red Hat Security Advisory: Satellite 6.16.14 Async Update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-12405 — rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter CVE-2026-12423 — foreman: unauthenticated information disclosure via provisioning token validation flaw CVE-2026-12540 — foreman: command injection in foreman-rake errors:fetch_log via request_id parameter CVE-2026-12541 — foreman: command injection in foreman-rake database tasks CVE-2026-12542 — foreman: command injection in foreman-tail CVE-2026-12544 — foreman: SSTI and insecure deserialization in foreman-rake configuration CVE-2026-12545 — rubygem-hammer_cli: command injection via insecure editor invocation CVE-2026-33154 — dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56097 — rubygem-katello: SQL injection in Registry Proxy via labels CVE-2026-56098 — rubygem-katello: improper authorization logic allows resource enumeration CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-79654 — ketello: Katello Content View History API Cross-Organization Authorization Bypass CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation CVE-2026-96658 — foreman: Safemode Bypass leading to RCE CVE-2026-96659 — foreman: Excessive Permissions for Viewer Role on Preview
🎯 Affected products90
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 9
- foreman-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-0:3.12.0.23-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-0:3.12.0.23-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-cli-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-cli-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-debug-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-debug-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-dynflow-sidekiq-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-dynflow-sidekiq-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-ec2-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-ec2-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-journald-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-journald-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-libvirt-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-libvirt-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-openstack-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-openstack-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-ovirt-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-ovirt-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-pcp-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-pcp-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-postgresql-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-postgresql-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-redis-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-redis-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-service-0:3.12.0.23-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-service-0:3.12.0.23-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- +60 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Release Notes: Provisioning tokens are now required for all Operating System entries with Redhat family set. Attempts to download a unattended template without valid token will lead to “a provisioning token is required but a valid one was not provided” error. This changed behavior will lead to inability to use Generic or Subnet Bootdisks, systems using this bootdiks will be not matched with the host entry and not boot. To use Bootdisk after applying the errata, either use Full Host Bootdisk which uses tokens, or set Administer - Settings - Provisioning - Installation token lifetime to zero. This turns off the token enforcement and allows unauthenticated parties to use arbitrary MAC addresses in unattended requests to fetch provisioning kickstart with possibly sensitive data. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:74506
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2449774
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488956
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489969
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489992
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489993
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490543
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517523
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2520368
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2523205
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2523348
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2530744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2534185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2536844
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74506.json