Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:8844 - Bug Fix Advisory
Issued:
2026-04-20
Updated:
2026-04-20

RHBA-2026:8844 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:8534 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2449006 - CVE-2026-4424 libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
  • BZ - 2452945 - CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing

CVEs

  • CVE-2026-4424
  • CVE-2026-5121

References

  • https://access.redhat.com/errata/RHSA-2026:8534
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-17@sha256:09266f90e5ef4b6a699fc4e1a37a2de06c500d08c1fdfb135805c10717c9281f
ubi8/openjdk-17-runtime@sha256:1411a47c075c3c8b4c7b1b844b19f036937490fb7ab018370a95002c86b49657
ubi8/openjdk-21@sha256:39f5337a39bfaeaf7de06ff172dafe0adb5c476ef537b6c74c7942786a3ebe67
ubi8/openjdk-21-runtime@sha256:3bc50fd96ae5c33e73ea5f5fe114c3bcfa500a48d57fc0f307eacd13759da475
ubi8/openjdk-8@sha256:0b65bee6a5b7e8a48f678f5e8db6bccaace5a1c8bffe53c97b2e5c3273ada4a9
ubi8/openjdk-8-runtime@sha256:814d646e30768b5fd2488c8ac8ed6525bf79536c6955644b0f122045912fef89

ppc64le

ubi8/openjdk-17@sha256:6f03631602175024a08eaaf0e425f1924947e907c3b5df2f78432dcc11e16589
ubi8/openjdk-17-runtime@sha256:3b26879317da7569c71f3cdaf4eb98af186bb103e6b381f3d7d45376bf4a0463
ubi8/openjdk-21@sha256:aebd5d3cdcdc6dbe68ee34300e345ac38784a4222eb2a65babbf2da3e45a43a2
ubi8/openjdk-21-runtime@sha256:2927cf47f5846ba707c1af2f9ece4e38311f139ea6401f955d75462bdedcd918
ubi8/openjdk-8@sha256:235e2a5a0ba93292503539855e2e73231310ec404c111c14a3eb2f113c767124
ubi8/openjdk-8-runtime@sha256:5d05add0941ce3ab623782df0eb01acb1c97692206047e8f217176e15537440a

s390x

ubi8/openjdk-17@sha256:5cf82b0812d74ba83188b3d5611476ab500a25c72ff06d829d00e3ec296482d2
ubi8/openjdk-17-runtime@sha256:7b048dcd51109d85a1e26df877ba6dec3ad95589366e73df1347f5c79daef6dd
ubi8/openjdk-21@sha256:885147f83b5f685a5670074e8d0e8f3c1108e84e4dcdea754169edc78cc53453
ubi8/openjdk-21-runtime@sha256:b9695cbc2cbada0ca1e3556eaed82286cee050081763e5ca9d390aca66a3ce8f
ubi8/openjdk-8@sha256:7bbf9101fe6a7971a719f8a24646e08685853c67a4f9b3f4d44feafb7d62016c
ubi8/openjdk-8-runtime@sha256:68d096cb548a7eadf0ae473a8f688c873503dc97db3293dfe8c08c7e4bcd778f

x86_64

ubi8/openjdk-17@sha256:814f6f98e636860096c76290acffbdd660b4438909a5a165e03bdab7cf69c285
ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463
ubi8/openjdk-21@sha256:be1c83c498a282a8aa4d7c2c1206c1701af0c903a1ccf4082ebbd56e08511966
ubi8/openjdk-21-runtime@sha256:ef8b16f9d59f57bef7952a2e355bf7b32fe19d636b96ecfba466a1f310a0a449
ubi8/openjdk-8@sha256:0aa65579037332b69d927044c49ac7132637641613f0b10402500c2df3f2aa08
ubi8/openjdk-8-runtime@sha256:7206ed1ea59dd869e8c8dd933df8aa5eca9deebd860daad38a6c4502f045f916

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility