Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:8846 - Bug Fix Advisory
Issued:
2026-04-20
Updated:
2026-04-20

RHBA-2026:8846 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:8510 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2449006 - CVE-2026-4424 libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
  • BZ - 2452945 - CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing

CVEs

  • CVE-2026-4424
  • CVE-2026-5121

References

  • https://access.redhat.com/errata/RHSA-2026:8510
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:e9770199df532b5036cfd9e1dae94a09943d3b398aef76db0a6dcd12c188bb1f
ubi9/openjdk-17@sha256:f2627d746fab284c19e219f257e98eae508158987f1a943675fadb63a223bded
ubi9/openjdk-17-runtime@sha256:beaba897cf1e09f11c13066f8e072d06ff7f53775787f5a72911b8c5355d5d73
ubi9/openjdk-21@sha256:f9ee9c48e2819725bfc9eab861a6b630e1b1fd9d26990ac59dbe16cd717fad43
ubi9/openjdk-21-runtime@sha256:6bd8a2c8080274933b135dd42b09e56fe909ef3413daa7e7fb5c646a90cc1a24
ubi9/openjdk-25@sha256:de403e80e23ecba68276f55cfc1d4860db38f046d2873eccaba19601ada6673d
ubi9/openjdk-25-runtime@sha256:af8689d3733557c21c4369e49ea3a70e7a3aff1011009aec5141bab465dff3f4

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:ff87fb7eb6b74348e7cf2dc1789eace00f6fff27b910f8197fcd853768972e28
ubi9/openjdk-17@sha256:37881cd208beae179b11e05bcd917fbb6e08f1eb0dcc0fd11243c732ec6507ee
ubi9/openjdk-17-runtime@sha256:16b4e2752f86e9b0971bfcc2b1c7243665a4cb201667a026b0a2626015051ad1
ubi9/openjdk-21@sha256:0379a6a1a92731286ac177f61a112531b0117b0e8d57d5ca4ea485e6116d4013
ubi9/openjdk-21-runtime@sha256:fb6654a4d286c4c22bd63f538482e59f64101ce7653b3025f37a3ca16ac9963f
ubi9/openjdk-25@sha256:a1284fed11c11293b3f91070d62cb20a0c016ba77fb02f0c67079b3aac49c32f
ubi9/openjdk-25-runtime@sha256:65cf95b4184e01b47c75c7fbeb0a58eb20d5ac260270619b8c60c15403f69667

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:96a35baf8229c3cf4f07393805834b7eb3252f50feef48158c50c53d276a7cfa
ubi9/openjdk-17@sha256:17d20433ad8a879b9c187f5dcf47a57c9d00cfc1b2dde244da10c1d9de768ae6
ubi9/openjdk-17-runtime@sha256:c3f8e73ccf8a86b5989653958b012acaa892a7af0d0c4f47c954407e580b4135
ubi9/openjdk-21@sha256:f63919da27952242037efdd62847faa38f3cf3924c7bd06886161fa1d4419ce2
ubi9/openjdk-21-runtime@sha256:3303688ceed87bc496a1d17f683bea9bd0b27bd62646b10a556961b2595234b8
ubi9/openjdk-25@sha256:17d72b79e430ed57cd9d16b4fbad0813b644d050b10defa2752913de55268485
ubi9/openjdk-25-runtime@sha256:7b24117175ccd8a62c50af07e572448e296a21193e9a0a9df8e23d4fb7bac9f9

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:23d7e7e0272287e4c57c098864561a660009e66025986c8ffbd71610e28b6a14
ubi9/openjdk-17@sha256:abb8c76a88c7747d962f4d01804f057acd08b2f1c65a3a8da4e4a17bab4f53b6
ubi9/openjdk-17-runtime@sha256:1d077c431002f604be4d5497fbddba1d6b587e8d87431d6f9b936eeda7c61318
ubi9/openjdk-21@sha256:c58f99222e8cfed2a13c098774c89b1385e70eea2465f4ac82c09628d612f599
ubi9/openjdk-21-runtime@sha256:6394a16a1bcf37adc4622e26617de1a538b95cf6862272932e7fca1ec50485d1
ubi9/openjdk-25@sha256:62e25ecd6cbc4b896a7cb132dc0792a14d8b19784df9f59afc3764805bc19b82
ubi9/openjdk-25-runtime@sha256:0716756c1efb4ad8db2fbf21db40d838c35145dd3aa09a67cd9682b98153b1c1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility