RHSA-2026:9052HighCVSS 7.5
Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🎯 Affected products6
- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-operator-bundle@sha256:e4f8aee3f5516d88ba4125cef4c162e19c87ae1654c46069c59a0b26aec172bb_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:37405eb98fc40f9b04ce0a5bdc37bd3941c1f3a3eee2c7a5195e0ccfd561364e_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:7058c6cb9f9feb524dd8ae915fa266540a1c3ff05a8bc90f558a16ee99891799_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:d71235e8467fad21686023bc3b843222cd40b5b44de614d28592b6ffb4b7d4b6_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:e65ed233ea4b24fc1bbdd82e7719e797067fa53ea99ba0c3b9aa50e2ca8dc2b6_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:9052
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_9052.json