Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:39806 - Bug Fix Advisory
Issued:
2026-07-15
Updated:
2026-07-15

RHBA-2026:39806 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:38503 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2456314 - CVE-2026-28390 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

CVEs

(none)

References

  • https://access.redhat.com/errata/RHSA-2026:38503
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-17@sha256:f7e34b718d01d8fe7eadb66aacf6db5769f29d26b056a5445bac09d0c252ddc5
ubi8/openjdk-17-runtime@sha256:1d633869d5080611c47f366179d37e9041ccf3cf3bb28f904a26255e97cbb97d
ubi8/openjdk-21@sha256:02d60442f7e291b6720b96200736df98ec69f0640e9dccb88ab13199a058a3f3
ubi8/openjdk-21-runtime@sha256:15d11461f7a3c481c6f4de394cb64b3e0ab509681ea9b27f5ca77f89bc369966
ubi8/openjdk-8@sha256:d7ad571bf3afe5edb8cfee3b6f311d93dc2d5e6c2b77b0fc79a5fdb9ec5fdf12
ubi8/openjdk-8-runtime@sha256:d6720b5a71bf10b75765b7a1bb2976252a9e889d9f0eedeb06bb350d0f5b5a6b

ppc64le

ubi8/openjdk-17@sha256:77f9d4c4fc31695caeeffd5e168a653612701894d72e54091daa7a50ca79c4a8
ubi8/openjdk-17-runtime@sha256:b7028f162c7d8bd6158fa227b5bc94be7954cc2983d9c9aa3207cb1d3dbf6d65
ubi8/openjdk-21@sha256:c96768e205441db3a36d0b570475758412675a140b326f4a9c9b2327df23a650
ubi8/openjdk-21-runtime@sha256:ad1e8223ff3dfd064d930ce6c3f258074cfdf932ba677155269f32fd34f1097c
ubi8/openjdk-8@sha256:7d08701ea928839218266f9990fd64b6fedaf5f63a88337b2e7f5dfbd7af21b1
ubi8/openjdk-8-runtime@sha256:dfd0d75df6fdf4104d95aa330132a28338b7cbaa83eeff143d131dc0587daad7

s390x

ubi8/openjdk-17@sha256:f84ec35e2a44f77919454a2e2707c4d46240f6e744dcb9eaf37f8ecae0f00726
ubi8/openjdk-17-runtime@sha256:e52a932b2ec75023c34b7f83930d054c02b30ab92500abe04ff9d3493f30ef8a
ubi8/openjdk-21@sha256:d7bb431aa850ba815ef9af919473d238011d5c4b37a519f22dda71a478e239ec
ubi8/openjdk-21-runtime@sha256:830d6e99601d913ee0b3c60644c2a0779c7491ea05a1d536e17ed882d5de47b5
ubi8/openjdk-8@sha256:efda0c111ab458e74447ece7e3b440b1c2a93e13b09710bc54a000059e8b525b
ubi8/openjdk-8-runtime@sha256:21a72cd148f1c4cb3a405ac0f752030fed8969e51371dab9761c62b28fbfc732

x86_64

ubi8/openjdk-17@sha256:f9a745279c3bde48cc3442092dced77d31269e2fa6b94b6faab846df9c49856c
ubi8/openjdk-17-runtime@sha256:1b546fb0f2128dca9c5623da511b2b0ad6e3734ce05c40ee2b47b82310f652c0
ubi8/openjdk-21@sha256:51eef928324905cb02d3cd957b1098bca6db0d58d0a05e76c11c0b7c8f66786a
ubi8/openjdk-21-runtime@sha256:a4223fff549560ec4b707159c9492a119aa4a72c84be32011263f877d6c2da46
ubi8/openjdk-8@sha256:b7334318855700c7da2f25952180785b8f2ec0a39e7ff174443d945ae96c97f4
ubi8/openjdk-8-runtime@sha256:b6b6e8b3f76adef61f93c497088094bdcb2445cef413060cb79c5f69749c0573

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility