RHSA-2026:75689HighCVSS 8.1
Red Hat Security Advisory: rhc-worker-script security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products3
- Red Hat Enterprise Linux Server (v. 7 ELS)
- rhc-worker-script-0:0.12-1.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- rhc-worker-script-0:0.12-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:75689
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533175
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_75689.json