Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:18060 - Bug Fix Advisory
Issued:
2026-05-18
Updated:
2026-05-18

RHBA-2026:18060 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:16799 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2463368 - CVE-2026-40356 krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
  • BZ - 2463370 - CVE-2026-40355 krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism

CVEs

  • CVE-2026-40355
  • CVE-2026-40356

References

  • https://access.redhat.com/errata/RHSA-2026:16799
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-17@sha256:0bb9d36597c68af497854c91aa351cc4b489907f0f99182a7eddc1b2aee8cfcd
ubi8/openjdk-17-runtime@sha256:8a5c2d544290d4064d2af0f3d6c6c2fd7438ad28a2b4561677f06cdfeb7695df
ubi8/openjdk-21@sha256:8e231e7684dd3eb43dc8a098dfd71cdba53fae0653b8bc6b681b93f61c6fec68
ubi8/openjdk-21-runtime@sha256:3191cf6144a3aca36eafcca16b776744c750590c267c9054e8178294b6d9027b
ubi8/openjdk-8@sha256:e6fa32930beee82640257eae8494c7babb441d82b2b01f73fdc33a05ef855151
ubi8/openjdk-8-runtime@sha256:29058fac48909024f311967e71cc113e3f7c02a71600637d298580244277ef0a

ppc64le

ubi8/openjdk-17@sha256:7cbe11d3bd6ef92ad8162c4ae7f2ba643492a90164a5c4b43b2ff63419164798
ubi8/openjdk-17-runtime@sha256:df46277298179b950a247cdd29434d1d6a241ea6ba6496095e0622ef87e786e5
ubi8/openjdk-21@sha256:63bea79b879f8c08fc214f51759ebc68d1feba2009e36a10b1b28f22d68d5dd6
ubi8/openjdk-21-runtime@sha256:534b4d944978857d8a9aaee95db5c6854775257218c206a3515fd34a5b59d021
ubi8/openjdk-8@sha256:3f05d55a94cc446d3911bbb534b1dd667012fbaf0fc439eb12490f02cb5ff174
ubi8/openjdk-8-runtime@sha256:4ddf1525379d7b47a3a0c7b22c41fbd41a230011b17228515b6ac6e7b13f4f38

s390x

ubi8/openjdk-17@sha256:f923f04f98b6162ec23b0ef0472d6f5b136c0f8159f43b761cf0ded88d7bc646
ubi8/openjdk-17-runtime@sha256:14a45b521fe4edd44def8b7af7255a78b067037acbc67756cc2cf2a5bae41386
ubi8/openjdk-21@sha256:4e4415f75105c43d1f18a46bc456c251725332298c9ff2bb226f5852dcb17e50
ubi8/openjdk-21-runtime@sha256:05282b6d271b48917f7e371004556a70a599bdd746959b3a639f50db9190fbc0
ubi8/openjdk-8@sha256:b1213e92eddff7be53fe6e341124bce3f5962e48205657d51e8fc323e6187f1f
ubi8/openjdk-8-runtime@sha256:0e4c026b54b97528eb3bb34a9e3b30af36ab14a153277cb6bfb491204db5e914

x86_64

ubi8/openjdk-17@sha256:211eadbbdc5f85a4fb90d09888b533a5a300b82e6084b7852903f70164e1819b
ubi8/openjdk-17-runtime@sha256:14315e4f2b484e0ff6faf877579703ebc4e5ba1c746126c3653bdbdecbf2a6d7
ubi8/openjdk-21@sha256:e8f7fc9c771a3a750eaaa0a9790bbd3b3b595392c3f3f1d9a3147982ffd42544
ubi8/openjdk-21-runtime@sha256:df54d5ef8ce85f6d95290eaf8bba094e35919115d3b234333b39d3e58f398d60
ubi8/openjdk-8@sha256:06f0dbbfa3cfeaab49a5b38edab52b948c16ba93662afe2350c93efd80cf7f58
ubi8/openjdk-8-runtime@sha256:b2ad05b7e98993411337ac1a70b916c8d509119506011177c07c697b6bc052ae

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility