Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:46957 - Bug Fix Advisory
Issued:
2026-07-27
Updated:
2026-07-27

RHBA-2026:46957 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:43420 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x

Fixes

  • BZ - 2490277 - CVE-2026-54369 acl: Symlink traversal privilege escalation via libacl functions
  • BZ - 2490279 - CVE-2026-54370 acl: TOCTOU Symlink Traversal via getfacl/setfacl

CVEs

  • CVE-2026-5435
  • CVE-2026-5928
  • CVE-2026-6238
  • CVE-2026-15308
  • CVE-2026-28390
  • CVE-2026-41254
  • CVE-2026-46917
  • CVE-2026-46968
  • CVE-2026-47010
  • CVE-2026-47021
  • CVE-2026-47027
  • CVE-2026-47057
  • CVE-2026-47058
  • CVE-2026-47059
  • CVE-2026-47063
  • CVE-2026-54369
  • CVE-2026-54370
  • CVE-2026-58016
  • CVE-2026-60147

References

  • https://access.redhat.com/errata/RHSA-2026:43420
  • https://access.redhat.com/containers

ppc64le

fuse7/fuse-console-rhel8@sha256:7e24328bd76bf30a1dced0658679a4246a0c348eb449f1376caa6a20e8664085
fuse7/fuse-console-rhel8-operator@sha256:7cc17145628b9ab1bb83b89d4bbe5addffe30b996cf872763a5d60497c11be58
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:fdfe9b77a292a236c9487d341c6aa7c9df55e0e992a46f74fd1b50c0aa23e001
fuse7/fuse-java-openshift-jdk17-rhel8@sha256:21b766bebe450418ef396130d6d5bb40180388407f758218161c3845fdf0a362

s390x

fuse7/fuse-console-rhel8@sha256:b040d2759c4b11f10cde5a69cc44b02a948546c1b02e5dc87736ca08254ee05e
fuse7/fuse-console-rhel8-operator@sha256:45ba5cab4820a0f3aa5782162835362bd1139801a7eb7cd47e2752b0d4df4dde
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:99c089a9115dc3758e9e96b2a43f125aafc0b2f9c5414fa9579a59ec77d592a1
fuse7/fuse-java-openshift-jdk17-rhel8@sha256:d0a237e1bd9054d4ba7d2f5bac6ec17fb23cf355d62e57ead2e592860c23a380

x86_64

fuse7/fuse-apicurito-generator-rhel8@sha256:8be39f7dac63e8fe6a5bd316a7ae76e462fd6e9839434645460928e8b493b7ba
fuse7/fuse-apicurito-rhel8@sha256:977e5c5618a13800277167653e24d810fb2ab1b8a15cac318c0dbf1f2c047223
fuse7/fuse-apicurito-rhel8-operator@sha256:8042983dd18330158dc2025b868725310fa29f62ef3ad88f947d6496b2b5e4f6
fuse7/fuse-console-rhel8@sha256:29df2f36e4befcb757f444befc0ae4bdd9b3fb340810bc3fa1ec80cc38d5a72d
fuse7/fuse-console-rhel8-operator@sha256:de37db2ec37f9b61d2d1c141e3afc3d8939f02cc7c001c05d4cee30ce4019978
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:14dd9a9c8b3f3a4d601cf6ab24a20efddfa62dac49fac2cc3916da7ff1238b1b
fuse7/fuse-java-openshift-jdk17-rhel8@sha256:fe7d23e126bb98ee2b552303626140d0822dc5e7a4097fee656e498af25cb553
fuse7/fuse-java-openshift-rhel8@sha256:06262d965805b2bdb7c0ca5ef60d23792517a5b6aa53ede8050c615707546c8f
fuse7/fuse-karaf-openshift-jdk11-rhel8@sha256:015076a21fbe95b5151d82fc540f82fd212eb8481cbdb4a148a562aa8004adec
fuse7/fuse-karaf-openshift-jdk17-rhel8@sha256:311f8f6b5c11d5cd0a7c36de0cb276937fb35373e99ce8ce32f6da4e5fcbb173
fuse7/fuse-karaf-openshift-rhel8@sha256:0476ace547a92279cac7d7d84b47a371593ef208f1eb01fce5b46f53444a9835

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility