Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:26394 - Bug Fix Advisory
Issued:
2026-06-16
Updated:
2026-06-16

RHBA-2026:26394 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:25239 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2481879 - CVE-2026-7383 openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing
  • BZ - 2481880 - CVE-2026-9076 openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption
  • BZ - 2481881 - CVE-2026-34180 openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.
  • BZ - 2481882 - CVE-2026-34181 openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
  • BZ - 2481884 - CVE-2026-34182 openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
  • BZ - 2481885 - CVE-2026-34183 openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
  • BZ - 2481887 - CVE-2026-42764 openssl: NULL pointer dereference in QUIC server initial packet handling
  • BZ - 2481890 - CVE-2026-42766 openssl: Possible NULL Dereference in Password-Based CMS Decryption
  • BZ - 2481891 - CVE-2026-42767 openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption
  • BZ - 2481892 - CVE-2026-42768 openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
  • BZ - 2481893 - CVE-2026-42769 openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
  • BZ - 2481894 - CVE-2026-42770 openssl: FFC-DH Peer Validation Uses Attacker-Supplied q
  • BZ - 2481896 - CVE-2026-45445 openssl: AES-OCB IV Ignored on EVP_Cipher() Path
  • BZ - 2481897 - CVE-2026-45446 openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
  • BZ - 2481898 - CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

CVEs

  • CVE-2026-7383
  • CVE-2026-9076
  • CVE-2026-34180
  • CVE-2026-34181
  • CVE-2026-34182
  • CVE-2026-34183
  • CVE-2026-42764
  • CVE-2026-42766
  • CVE-2026-42767
  • CVE-2026-42768
  • CVE-2026-42769
  • CVE-2026-42770
  • CVE-2026-45445
  • CVE-2026-45446
  • CVE-2026-45447

References

  • https://access.redhat.com/errata/RHSA-2026:25239
  • https://access.redhat.com/containers

aarch64

ubi9/openjdk-17@sha256:fb049a4b5d08bef16615765b4311b9827d22ecc0f281fd16772f7fb2153d80f4
ubi9/openjdk-17-runtime@sha256:d5fee79ad6818be9d4ac8eae68aa3b3fa00b881b63fb5fb40a2166c6b8cf9230
ubi9/openjdk-21@sha256:d71405097d3f5e9faac33a2e40a777d8e674cf8f2a7644aaa114600e6079c3e0
ubi9/openjdk-21-runtime@sha256:76903aaf7aef43c1572674ac745de54e6c9877796127ac498959697afbc84dd5
ubi9/openjdk-25@sha256:4fb045e1e7ed1d27b4e9af1577f4078a065a2b82bbdb66953997f19193817915
ubi9/openjdk-25-runtime@sha256:e60c7950b0ac0e961c6faf763998e242e896303a228bdb09ecc088b7b3512c4c

ppc64le

ubi9/openjdk-17@sha256:db08eb4af5be5e4832ac07d8eac9415604ab828ffcf532aec0b5b22ba539f1ef
ubi9/openjdk-17-runtime@sha256:93314f31e1d21c1e4ee2a012c82495339c5353bace5770a0689f338c115cad01
ubi9/openjdk-21@sha256:e12d9fca9e1f729c5b750111f75880d779776e94e21e868ee551889ed72c4cb9
ubi9/openjdk-21-runtime@sha256:e220598d0b37722a38d03db071b1fe1f929208095cfc247260a8689d79d66bbc
ubi9/openjdk-25@sha256:943e056ce7f6b03a28582502969eebc5d7f3c93d1e7092587aa11a48de34d42e
ubi9/openjdk-25-runtime@sha256:acd489bc4a03a1d503a05b215158d278dddb75c1ff4b91417b9c164d28165075

s390x

ubi9/openjdk-17@sha256:f818b542d6c3ef2d5ba12756e500b953e7abefe45b88cfd5277b67b87e0e11fc
ubi9/openjdk-17-runtime@sha256:e7126187bf75fea4c72518d758a2815bf912ab01d7b32bf5124fca1fc742b541
ubi9/openjdk-21@sha256:df0ddd8d223d2fa8824baf90641912a0c3760e89f8ee6eacc7fa675db6093193
ubi9/openjdk-21-runtime@sha256:ca0a2c702ca405695455699a3d3ef22ebf332502b836b06fa4f4713e2fe7f37f
ubi9/openjdk-25@sha256:13d0e061e4ac8333c07bc86fd4a41b8dc22fa657713f3f6259edb712737f0875
ubi9/openjdk-25-runtime@sha256:760d21068e9c8184f2660fb23fd5b721a4645f2b80cbdd0b202a2139207eb36a

x86_64

ubi9/openjdk-17@sha256:d729386414248346b936d4e08cb8b0b501666ce2ba10552ab75155bff4c8577a
ubi9/openjdk-17-runtime@sha256:e61800b80268a32bf4b449c6a4ecd136f16ebc0ce98487d4c99c35f71494a33c
ubi9/openjdk-21@sha256:78f7200dae457636ded6f413611c9af26a84ef63139ed35402442996988278a7
ubi9/openjdk-21-runtime@sha256:c0d236d387572d24b5846c1df9dc6a8ee5d6a7e3a37f2379965165676f5ae119
ubi9/openjdk-25@sha256:44c8574f3f5634f1820de04da91e2e769b2755799bedcc9c892e0d09a67b0c6c
ubi9/openjdk-25-runtime@sha256:2ff4bb9db8db4c6ce7eade86db6a8c8f87814ba90be95350b5d63c2fd2bbe4b6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility