Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHBA-2026:4393 - Bug Fix Advisory
发布:
2026-03-11
已更新:
2026-03-11

RHBA-2026:4393 - Bug Fix Advisory

  • 概述
  • 更新的镜像

概述

updated RHEL-9 based Middleware Containers container images

类型/严重性

Bug Fix Advisory

标题

Updated RHEL-9 based Middleware Containers container images are now available

描述

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:4168 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

解决方案

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

受影响的产品

  • Red Hat JBoss Middleware 1 x86_64

修复

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVE

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-0865
  • CVE-2026-1299
  • CVE-2026-22695
  • CVE-2026-22801
  • CVE-2026-25646

参考

  • https://access.redhat.com/errata/RHSA-2026:4168
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:42336e4bea287579e6ecc5fa93b59006549d6cb7f4ac2f8056928a97b8cdb01e
ubi9/openjdk-17@sha256:611301337c99c4e8c48c7b9724a62ea2cfcd0c3d0766c07cc86dffef89b441ea
ubi9/openjdk-17-runtime@sha256:cbfd700c17c3536515dc9b82e5a576ec4dc2fb6b6d15b27c2f81930600ef202d
ubi9/openjdk-21@sha256:43c61606e69fb1298bbc9d22122785558ae7071f6b484c188e7bc39a8801e53c
ubi9/openjdk-21-runtime@sha256:7a9d16582a1cf06b21ca16340598420ae5f2b615126d7cc92f99816b140babfe
ubi9/openjdk-25@sha256:fe6cf7d8300fab65f6c5abd764211235c019815da9fd236f6e7eb12da9f31486
ubi9/openjdk-25-runtime@sha256:5a21789bfbb7d578aed28682a512a721427bd12e3a3cf8e488f0cf2bd180f0fe

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:81b263acb9bb738dc2870c30d467739011997adcf3a39a859d1c75afbef08367
ubi9/openjdk-17@sha256:9db5158bb6169dd1bff1c41b82ffd310c1f4bafd645c99862c5c5ba4f0ac56f8
ubi9/openjdk-17-runtime@sha256:9f544d5ce32b79b3bbbcbfa307ef4f5847a49946a8ee0932af8617ced18cc5af
ubi9/openjdk-21@sha256:c76e64aa9c08a2d94bda1ec7d0ea63d36961adf96b0ceb2a68aac2c611f9a601
ubi9/openjdk-21-runtime@sha256:5d9db1b79fda165972867f47f7c138d5f30d2849a45fe5320f5c56e67cb4db21
ubi9/openjdk-25@sha256:ca3ca4968464295d1723da3f2f7a664624b9addee4fbfabcf2f97a9f68cd30f5
ubi9/openjdk-25-runtime@sha256:eb6d5fbb70224458b6bbc3407897730eb0862db7894f8031a96aed46e22b12aa

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:053ec66c599c98412da21f2bf0c6a694eb022c888e8d5aae850e6c5e6a1635da
ubi9/openjdk-17@sha256:92f4f9c791ffd46be4586065fdda61aacae4c5128ccc60452b236c2788f52aba
ubi9/openjdk-17-runtime@sha256:5f5a7c2b67a6b68c6923c38617620504712ebd6fff995c9b67bf79e98ceb45c2
ubi9/openjdk-21@sha256:164a5c891011d9897c4456563ce270ba0dd076977136c90ec31c78dcf7dc078c
ubi9/openjdk-21-runtime@sha256:07a00349c4d92115609ec056bf9f8dea1f350d42d4dd4fdad4df69d8c0998a57
ubi9/openjdk-25@sha256:468218ae20f22eb670a35288065a7d031f79be53cd93b9bbeed7bfaabd6667db
ubi9/openjdk-25-runtime@sha256:a7562b7b54b769f545bd33e2bca57dc0d91c4d335037fa2b5b44eaeaf8b6c3cc

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:e955927c4acd54502ccee5f01cc671916427d984a23287c1a38aaa08243e90fd
ubi9/openjdk-17@sha256:a6e673869cd9c088cff35abd8e486c72cc0f7067210237348906fcf2d246ca5f
ubi9/openjdk-17-runtime@sha256:0a19f4e8324f14f57208102632b1735c9f6a9e707dbb24509b8281f7bc5a5ef5
ubi9/openjdk-21@sha256:f6bf70fafa502ffe1b59576c0eb0e934faa774cf2dbac249b66ff68cc8fb5dd7
ubi9/openjdk-21-runtime@sha256:b78b3653d407314a805d20b103c8422e94ba3662bdd46f6177b037a0805bd9fe
ubi9/openjdk-25@sha256:219c52eed7a6efd7100b9870c5aad61c637f0cb38bde6435b9a65a3fc95b110a
ubi9/openjdk-25-runtime@sha256:a077e511a0262b24c404ce398a4d5b12d19371cf2e7bee56310df74f32457aee

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility