Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:15124 - Security Advisory
Issued:
2025-09-03
Updated:
2025-09-03

RHSA-2025:15124 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Satellite 6.16.5.3 Async Update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A new release is now available for Red Hat Satellite 6.16 for RHEL 8 and 9.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

  • puppet-agent: REXML ReDoS vulnerability (CVE-2024-49761)
  • puppetserver: REXML ReDoS vulnerability (CVE-2024-49761)
  • After upgrading from RHEL8 to RHEL9, the webhooks stopped working (SAT-37580)
  • foreman-rake rh_cloud:hybridcloud_register task is broken (SAT-37586)

Users of Red Hat Satellite are advised to upgrade to these updated
packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Satellite 6.16 for RHEL 9 x86_64
  • Red Hat Satellite 6.16 for RHEL 8 x86_64
  • Red Hat Satellite Capsule 6.16 for RHEL 9 x86_64
  • Red Hat Satellite Capsule 6.16 for RHEL 8 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64

Fixes

  • BZ - 2322153 - CVE-2024-49761 rexml: REXML ReDoS vulnerability
  • SAT-37580 - After upgrading from RHEL8 to RHEL9, the webhooks stopped working [rhn_satellite_6.16]
  • SAT-37586 - foreman-rake rh_cloud:hybridcloud_register task is broken [rhn_satellite_6.16]

CVEs

  • CVE-2024-49761

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Satellite 6.16 for RHEL 9

SRPM
puppet-agent-8.8.1-2.el9sat.src.rpm SHA-256: 13a519f70d7e582ac3be44905a95ea51ccbfe87db18dd4594a241c0d4139ab6b
puppetserver-8.6.2-3.el9sat.src.rpm SHA-256: 9185fc7c0ed86b2da5a4443debe053211e07102311ae10f615064040c356b0b9
rubygem-foreman_rh_cloud-10.0.7-1.el9sat.src.rpm SHA-256: a10a49aa48fbf2f6e592166daaa14ccd4dc31642575de2d8ba90ddc986d6d8eb
rubygem-foreman_webhooks-3.2.4-1.el9sat.src.rpm SHA-256: 1fe72f22ae41d114c1a5e5c300fe16758a1aded7d7b101646e73ad599dcf481d
satellite-6.16.5.3-1.el9sat.src.rpm SHA-256: 25ece61c0c112bfb8e865ac8bc060f392bca08843bd002a9b305beef1dc2e9fe
x86_64
puppet-agent-8.8.1-2.el9sat.x86_64.rpm SHA-256: bbbf44e150009794729f7cedf5801a203b60acd52eb383572ec0adf0448776f4
puppetserver-8.6.2-3.el9sat.noarch.rpm SHA-256: 2ee98faf642cfdce45be44262c17fc7e8ffb79bea808b76d943744ab7abb393b
rubygem-foreman_rh_cloud-10.0.7-1.el9sat.noarch.rpm SHA-256: 75735b0452dd784903e2e04603990e3ec8c038fed47cb496a6d541727bca8e27
rubygem-foreman_webhooks-3.2.4-1.el9sat.noarch.rpm SHA-256: 9c502fc497cfece815f59512d767cb7d88544e630ba5a2fd1ba04fa862048ecf
satellite-6.16.5.3-1.el9sat.noarch.rpm SHA-256: 30c00714c2106bf4683ea70ae1050e0919029db82cb1bd764a65099c2424baa2
satellite-cli-6.16.5.3-1.el9sat.noarch.rpm SHA-256: bd5b7aa62ee216dc2d562350f60a02c52b7f2e8c7c37da13a75ce8d0c813407d
satellite-common-6.16.5.3-1.el9sat.noarch.rpm SHA-256: dc51e84c88ab5b433843d1321281c49959eefb9f9c1ab14e3f2e177962721896

Red Hat Satellite 6.16 for RHEL 8

SRPM
puppet-agent-8.8.1-2.el8sat.src.rpm SHA-256: db4dec8d86894497e24c95a459d121c948fe0f687ab4e8235c961ed7995d2295
puppetserver-8.6.2-3.el8sat.src.rpm SHA-256: e5194f61ecdfe60393170ca504ccab47c132de7ae8b6836d3da3c77271bddffe
rubygem-foreman_rh_cloud-10.0.7-1.el8sat.src.rpm SHA-256: 43bd74d21211b1e76be9c61da48a37c84aa1948e9eea36e82074dc31dbd2e224
rubygem-foreman_webhooks-3.2.4-1.el8sat.src.rpm SHA-256: 7f6701dd6e8f34780ffb1771dcc2b40af01cfb31fc6e4408f9553d9977dc1954
satellite-6.16.5.3-1.el8sat.src.rpm SHA-256: bbfe1ddc54a51b33a5d8ed8c345361db41080e57e314466c7ee93d7e46f51114
x86_64
puppet-agent-8.8.1-2.el8sat.x86_64.rpm SHA-256: 87482059cd40b847b3111e76efdd673904e42e665423346b9439e7f6543e31e1
puppetserver-8.6.2-3.el8sat.noarch.rpm SHA-256: 6ba42d2042045cb861559fe8db6d3c44cd60181074520c3cce4c55c4f8b5cd5e
rubygem-foreman_rh_cloud-10.0.7-1.el8sat.noarch.rpm SHA-256: 0c434b70ea172f659a6b06e1b5541e40ae545bca231e68452d523f38b48a4911
rubygem-foreman_webhooks-3.2.4-1.el8sat.noarch.rpm SHA-256: d98f1ca173df93be63f40330b53f32c44f4f7b8562cd550248e3d90f01d2f80e
satellite-6.16.5.3-1.el8sat.noarch.rpm SHA-256: 198f0bbdd09c126610be3ca1d5b29aa9a62781e262d9779817d8e5ac30e57b04
satellite-cli-6.16.5.3-1.el8sat.noarch.rpm SHA-256: 467e7e5cc34dd02b3c1493ae7436fcf226be68ce4dee7f6931cd6bc9a536e182
satellite-common-6.16.5.3-1.el8sat.noarch.rpm SHA-256: 0504d75626830bdaaf49d5d685a1aebdb81930c43aef483f21566142658d12be

Red Hat Satellite Capsule 6.16 for RHEL 9

SRPM
puppet-agent-8.8.1-2.el9sat.src.rpm SHA-256: 13a519f70d7e582ac3be44905a95ea51ccbfe87db18dd4594a241c0d4139ab6b
puppetserver-8.6.2-3.el9sat.src.rpm SHA-256: 9185fc7c0ed86b2da5a4443debe053211e07102311ae10f615064040c356b0b9
satellite-6.16.5.3-1.el9sat.src.rpm SHA-256: 25ece61c0c112bfb8e865ac8bc060f392bca08843bd002a9b305beef1dc2e9fe
x86_64
puppet-agent-8.8.1-2.el9sat.x86_64.rpm SHA-256: bbbf44e150009794729f7cedf5801a203b60acd52eb383572ec0adf0448776f4
puppetserver-8.6.2-3.el9sat.noarch.rpm SHA-256: 2ee98faf642cfdce45be44262c17fc7e8ffb79bea808b76d943744ab7abb393b
satellite-capsule-6.16.5.3-1.el9sat.noarch.rpm SHA-256: b02bf75635f9df0415b0fe719b15757c9b5ca557c320082583cb2808b79d8067
satellite-common-6.16.5.3-1.el9sat.noarch.rpm SHA-256: dc51e84c88ab5b433843d1321281c49959eefb9f9c1ab14e3f2e177962721896

Red Hat Satellite Capsule 6.16 for RHEL 8

SRPM
puppet-agent-8.8.1-2.el8sat.src.rpm SHA-256: db4dec8d86894497e24c95a459d121c948fe0f687ab4e8235c961ed7995d2295
puppetserver-8.6.2-3.el8sat.src.rpm SHA-256: e5194f61ecdfe60393170ca504ccab47c132de7ae8b6836d3da3c77271bddffe
satellite-6.16.5.3-1.el8sat.src.rpm SHA-256: bbfe1ddc54a51b33a5d8ed8c345361db41080e57e314466c7ee93d7e46f51114
x86_64
puppet-agent-8.8.1-2.el8sat.x86_64.rpm SHA-256: 87482059cd40b847b3111e76efdd673904e42e665423346b9439e7f6543e31e1
puppetserver-8.6.2-3.el8sat.noarch.rpm SHA-256: 6ba42d2042045cb861559fe8db6d3c44cd60181074520c3cce4c55c4f8b5cd5e
satellite-capsule-6.16.5.3-1.el8sat.noarch.rpm SHA-256: e96c69a8a6aa1d8a7363946cbbb7c34bf63c5649f578bcda1185ebd1c1c90725
satellite-common-6.16.5.3-1.el8sat.noarch.rpm SHA-256: 0504d75626830bdaaf49d5d685a1aebdb81930c43aef483f21566142658d12be

Red Hat Enterprise Linux for x86_64 9

SRPM
satellite-6.16.5.3-1.el9sat.src.rpm SHA-256: 25ece61c0c112bfb8e865ac8bc060f392bca08843bd002a9b305beef1dc2e9fe
x86_64
satellite-cli-6.16.5.3-1.el9sat.noarch.rpm SHA-256: bd5b7aa62ee216dc2d562350f60a02c52b7f2e8c7c37da13a75ce8d0c813407d

Red Hat Enterprise Linux for x86_64 8

SRPM
satellite-6.16.5.3-1.el8sat.src.rpm SHA-256: bbfe1ddc54a51b33a5d8ed8c345361db41080e57e314466c7ee93d7e46f51114
x86_64
satellite-cli-6.16.5.3-1.el8sat.noarch.rpm SHA-256: 467e7e5cc34dd02b3c1493ae7436fcf226be68ce4dee7f6931cd6bc9a536e182

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility