Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:21455 - Bug Fix Advisory
Issued:
2026-05-27
Updated:
2026-05-27

RHBA-2026:21455 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:20597 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2449777 - CVE-2026-4437 glibc: glibc: Incorrect DNS response parsing via crafted DNS server response
  • BZ - 2449783 - CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
  • BZ - 2453117 - CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets

CVEs

  • CVE-2026-3832
  • CVE-2026-3833
  • CVE-2026-4046
  • CVE-2026-4437
  • CVE-2026-4438
  • CVE-2026-5260
  • CVE-2026-5419
  • CVE-2026-33845
  • CVE-2026-33846
  • CVE-2026-42009
  • CVE-2026-42010
  • CVE-2026-42011
  • CVE-2026-42012
  • CVE-2026-42013
  • CVE-2026-42014
  • CVE-2026-42015

References

  • https://access.redhat.com/errata/RHSA-2026:20597
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:7abd525583791dbdbc85775e856a68a418024a1f90ba81f4d288adfc6595fb83
ubi9/openjdk-17@sha256:a1d817a77000974d29802d867adf99c77c723d83e8d9b7d617dd6a784417841f
ubi9/openjdk-17-runtime@sha256:7ea7e51bb38d6699b17270a163202e22e606799907f2a9f5665d1bfbb382c683
ubi9/openjdk-21@sha256:f03f867d6bb1e15862194baef298726706bbafcc612fe3c6d36c1ffe1c61c4ae
ubi9/openjdk-21-runtime@sha256:1716d5e0f342a61e5822ad69e92c8a51027727c90a0167af22dcdeadff936621
ubi9/openjdk-25@sha256:4f02260ccfbaca1f9debf9c212a2a90e4565a6d0efa58db57aa5bc052f039e04
ubi9/openjdk-25-runtime@sha256:120ee1efa0f89bccfeb108303a5cf1b607b7e570346cc869d655921612f60cef

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:ec7a1e782a7dc03dd73ec1a566d79c7c6b05dbc52360471583bbdb04b52b9f8a
ubi9/openjdk-17@sha256:946c49ecc550a39ae1a2cd785a254c7bed59c0248020d094a6bdb88c9b796c9a
ubi9/openjdk-17-runtime@sha256:54612058dea339c27447de41f62a027a63e2a4686324dd2e28c85f73808987d5
ubi9/openjdk-21@sha256:7facf2911e142abdd6b8193ecdc15ea2b4426a729f4f0fbe9d9f5b463a01ca43
ubi9/openjdk-21-runtime@sha256:d49eeaf03abff1b879d2b10e74f4a19177211933c4b8cdb4a1c18c013db2985c
ubi9/openjdk-25@sha256:b4a768279804411df70d29c23202ab9037cb29db283b6090f2fc4f12d0dad2a9
ubi9/openjdk-25-runtime@sha256:f07c8b7e9526315b62b975e34e3b76a848753a363bcd222a7c6c9658b5c3d3ac

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:3425d0ce301e17652562fb98e82270f1d77510c3b87453a464290d4e9eb8e6fc
ubi9/openjdk-17@sha256:9eaba1f364ed86c2cc24312f82f7e3daf1448ed7aa4c2d84894a7d1804841611
ubi9/openjdk-17-runtime@sha256:76f01adce2bdf978cd385ed25d287f0b9a51ac619ff26da77d53e27e97990968
ubi9/openjdk-21@sha256:00d63650a6c00f737353b8166394ce75cc612ee0478b77169a96e8ca5ba28367
ubi9/openjdk-21-runtime@sha256:6bb2c151cff4d6304010ed9a742ab427ff6909d1e7b756bc937979401b07de6f
ubi9/openjdk-25@sha256:bff09049a5fd006b8563d3c4726146c7c8076e7f18cffa876d53f248b3095845
ubi9/openjdk-25-runtime@sha256:cb95749e227e32578a3c33318423ea4f9907a94f19511e9d4225acdbca0f2da0

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:d093bbec408290a20dfb06c9bd249f257eaa28d93b22165015f47b06abe059d4
ubi9/openjdk-17@sha256:0dd6dd56eb261ae6a7a0a464db71fda8da11af76bb6c162ba0db8a0fa9031d78
ubi9/openjdk-17-runtime@sha256:eb32f7b670287c703e874fa1b73122a17d26f54b5897e3d9356b5c61f5ea7b92
ubi9/openjdk-21@sha256:b811da0e34e7dcfb885fb9c473571b382e408b93180ff6bfb0a144d57c576ceb
ubi9/openjdk-21-runtime@sha256:4edd18ab17ef6e8627aa6582ea9415337f292e3490f2d5a33e7703678ce158b8
ubi9/openjdk-25@sha256:043963a1f6cad04b162781e01c66690d340a2177233f1b54fff5d915b0490f78
ubi9/openjdk-25-runtime@sha256:985ebcf4dc8564dbd384cd4a2b872c3e2fb240801264a6dd6517806c9fde9f7f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility