Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:0028 - Bug Fix Advisory
Issued:
2026-01-05
Updated:
2026-01-05

RHBA-2026:0028 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2025:23383 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x

Fixes

  • BZ - 2394750 - CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path

CVEs

  • CVE-2025-5372
  • CVE-2025-9086
  • CVE-2025-58364

References

  • https://access.redhat.com/errata/RHSA-2025:23383
  • https://access.redhat.com/containers

ppc64le

fuse7/fuse-console-rhel8@sha256:55fdfa7c365e1d271bdeddc63bfdb5a4261df5312023e453d95882723ed22a57
fuse7/fuse-console-rhel8-operator@sha256:ba1d75c64232733cf0670e876749f7656164bbf8256bf4b2b835e7089b9997d5
fuse7/fuse-console-rhel8-operator-bundle@sha256:96505659d9f003a6ceb282983e6d158a9bdb74d1cc96a71280d7706b4a633775
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:c7eb167d6878322a32e296322770c9b76666a9e4071d8a057c685abd9ed7f8f8
fuse7/fuse-java-openshift-jdk17-rhel8@sha256:d360ec154c0c4799e5844a162abff7457f7e78687ae0d7dd985af7ebff0eaf7e

s390x

fuse7/fuse-console-rhel8@sha256:ce8bfc9a516c5415406a01658e91d512344601a116d944efeddd5ea9e069ddc6
fuse7/fuse-console-rhel8-operator@sha256:598fb0f4b75d04d98962ad7390aa5d9b2b386b37009e9d8304a7ba025c3e8d00
fuse7/fuse-console-rhel8-operator-bundle@sha256:67dd5c7e861388f3ee7f2bbfed4bbd00ecf57a81baeabf7c8ad36bf0738b30ae
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:3e542ae2740fc57138efd6e85d2e28049bb76e438d4d0d0d172a46a030115245
fuse7/fuse-java-openshift-jdk17-rhel8@sha256:51c9eb62d9db1ab7c04c37fb4a0ea5fdf49bfbaa28bb89f7bba2563ad70a936e

x86_64

fuse7/fuse-apicurito-generator-rhel8@sha256:28c1d83363a0bb558bd872c93d15f54efea68fbaf1a4af545ecaa72068e5067f
fuse7/fuse-apicurito-rhel8@sha256:740a1886fbaa57d41db066523a69e960d3fd59929a6d1787c11ad19cc769131f
fuse7/fuse-apicurito-rhel8-operator@sha256:71663212c5568f4ae071e9dfd5ec78f25d942331bd59368e6b349be89fb194b9
fuse7/fuse-apicurito-rhel8-operator-bundle@sha256:75608fbf6c20bac35bdbaca071315e000df42d09bf171a690f4371291663ea83
fuse7/fuse-console-rhel8@sha256:f10e68086a68ad0f2a237c26be8f1361303a7b4c3768895a37c903f93921294c
fuse7/fuse-console-rhel8-operator@sha256:b35183219533faa8b1e14cbfc74dbe97e115928ca103d85041ff111d0c338175
fuse7/fuse-console-rhel8-operator-bundle@sha256:604011e60b1ea342db34ffe9c4ad5c13f6417667cde611f21c2cd1094552aad3
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:869b6bce39f742beb38e6ec85f5ed4413fd67436e86bd6da0f3a4795da100a26
fuse7/fuse-java-openshift-jdk17-rhel8@sha256:23d497c4f1dbc7b0b2a2be633e14ea00a691902956a5e8cb3f514767f2708288
fuse7/fuse-java-openshift-rhel8@sha256:b1ee449cf5ba9b6ca266d00fb227a5b18dd9d51de88e15e38fe9560589b74584
fuse7/fuse-karaf-openshift-jdk11-rhel8@sha256:f3390c6d7361b361abc055f70afacc3c303bdb3ff2bdfce9a57b6926c37e58ae
fuse7/fuse-karaf-openshift-jdk17-rhel8@sha256:1b2d8045e020ec8b72a701cc5eb64f2c413ffafb80f5b1dd0e9f73e322d75c7b
fuse7/fuse-karaf-openshift-rhel8@sha256:bcecbaeed1dece8c76f09a2f286e94016029bc4bf27d53fc77fe54a36972ab61

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility