Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:17606 - Security Advisory
Issued:
2025-10-08
Updated:
2025-10-10

RHSA-2025:17606 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Satellite 6.17.5 Async Update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A new release is now available for Red Hat Satellite 6.17 for RHEL 9.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

  • puppet-agent: incomplete fix for CVE-2024-49761 (CVE-2025-10990)
  • python-django: Django SQL injection in FilteredRelation column aliases (CVE-2025-57833)
  • cjson: out-of-bounds access in decode_array_index_from_pointer() in cJSON_Utils.c via crafted JSON pointer strings (CVE-2025-57052)

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.17/html/updating_red_hat_satellite/index

Affected Products

  • Red Hat Satellite 6.17 x86_64
  • Red Hat Satellite Capsule 6.17 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64

Fixes

  • BZ - 2392894 - CVE-2025-57052 cJSON: out-of-bounds access in decode_array_index_from_pointer() in cJSON_Utils.c via crafted JSON pointer strings
  • BZ - 2392990 - CVE-2025-57833 django: Django SQL injection in FilteredRelation column aliases
  • BZ - 2398216 - CVE-2025-10990 rexml: incomplete fix for CVE-2024-49761
  • SAT-38394 - Update the Hypervisor last_checkin once the same still around and reporting
  • SAT-38396 - Satellite should include mmx64.efi into the full bootdisks
  • SAT-38397 - Pulp content app never close Redis connections
  • SAT-38398 - "No hosts matched search, or action unauthorized for selected hosts" error comes while using the filter box in Content Host Errata Management in Satellite 6.15
  • SAT-38496 - Global registration template takes longer and failed when load balancer is unreachable.
  • SAT-38730 - Bootdisk generation fails with "ERF42-8203 [Foreman::Exception]: Ensure /var/lib/tftpboot/grub2/mmx64.efi is readable (or update "Grub2 directory" setting)"

CVEs

  • CVE-2025-10990
  • CVE-2025-57052
  • CVE-2025-57833

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/documentation/en-us/red_hat_satellite/6.17/html/updating_red_hat_satellite/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Satellite 6.17

SRPM
cjson-1.7.18-2.el9sat.src.rpm SHA-256: 7e3282c60fdba65ddce65e58aaaedaaa3eb5c4a9b7718ae66f625e2b6bb62dae
foreman-3.14.0.8-1.el9sat.src.rpm SHA-256: 903ff70291ee5899a56c949b0519973749305ffb59e6fcf94421137092e212b3
foreman-installer-3.14.0.7-1.el9sat.src.rpm SHA-256: 1b3da402cb9165b91d74124db5610d5332c8a72765b05af0b3e64f670b8e2fb3
puppet-agent-8.8.1-3.el9sat.src.rpm SHA-256: e29fda0b14a6b23ed56a9713346712a6081ae7bb2efb6e8dcbd2dcf8d3f01210
python-django-4.2.24-0.1.el9pc.src.rpm SHA-256: 255257b22246693d3114733ba7a4c630df8d2f109228150473af833bb438b3b7
rubygem-foreman_bootdisk-22.0.4-1.el9sat.src.rpm SHA-256: 7d03b83ec91893226bd4f9c2fe30758f5ac75d7c711cb56dbc669d0deca34b42
satellite-6.17.5-1.el9sat.src.rpm SHA-256: b206a47a0cd10029095e3fa99ea98cb9a56cb785659345d8f685837ce40ef172
x86_64
cjson-1.7.18-2.el9sat.x86_64.rpm SHA-256: e4199697901ba2bee704bf83c85e39474b6a428a559ab41e7d371bf4e7433ff6
cjson-debuginfo-1.7.18-2.el9sat.x86_64.rpm SHA-256: 39fe5743b85609ac2a84e9c5b53807fc03f504de89d1eecf94c3f00771942a6d
cjson-debugsource-1.7.18-2.el9sat.x86_64.rpm SHA-256: b5afb3d73cf052786db1c79f09db8041652df644756bae7ca177c2019c346e6c
foreman-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 7a848129736711a517ccf85ec4b616aac487f611926ed31de8c239f7660f935d
foreman-cli-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 2c7f5aecf694f1d15df9b4d5f8872e1041366d492a4787b7fd1fd35b327f4d1f
foreman-debug-3.14.0.8-1.el9sat.noarch.rpm SHA-256: bd552d7890ac4d1a9414113a1e77351066d23b58255b1186a7d0537f31b7cada
foreman-dynflow-sidekiq-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 0f1eca8db48b99871327a0044e5f6ac8c9cf2d4c03a48f58f3353df4b8b9b8ed
foreman-ec2-3.14.0.8-1.el9sat.noarch.rpm SHA-256: d8e8c9d752befd1a020a23cc9a85a716cb96419ae13e56c4f481c7ec7928ebc2
foreman-installer-3.14.0.7-1.el9sat.noarch.rpm SHA-256: 9f3b9e479aaa1d871995fb85d08eb5045b19ecb5a3010043c0b7d70ee413adc1
foreman-installer-katello-3.14.0.7-1.el9sat.noarch.rpm SHA-256: 1b0269d5ce45413879084b6c058a4ba9e18efa07e56b702c0f0d5c70b8007bdc
foreman-journald-3.14.0.8-1.el9sat.noarch.rpm SHA-256: c8d71bc707a9c576e53fc33b59f8f3b2a70959676af2c89b0d627278991926b4
foreman-libvirt-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 448e9feb64ed38e4fa69552b792a5432540a33d4ffe7151e385931ff6975d149
foreman-openstack-3.14.0.8-1.el9sat.noarch.rpm SHA-256: adb1ea472d7cc8533fabb55f6fe8d75e6dab8a7a8428d6c6415365580114fd04
foreman-ovirt-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 5c5dd2707974be4e6ef9a91dd1673d42f0ae0fa56732eda6586102518c3f0b3c
foreman-pcp-3.14.0.8-1.el9sat.noarch.rpm SHA-256: d471b421e59049552dfc33ea0e08a159878605170ded50d77f2bcb8d51f3bea6
foreman-postgresql-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 05fafd33d0f390d2a2a20302a3da1d1b21483279b2de0046f2f974939b52eb6f
foreman-redis-3.14.0.8-1.el9sat.noarch.rpm SHA-256: e438e5d4677e1d4fa9d5199066646dd0807cd412571a7c4cbe4c149e724fef12
foreman-service-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 02dbfaca183215f17d73ec71ef94b01c677623ce6dc60229ba6734c1520e9e6c
foreman-telemetry-3.14.0.8-1.el9sat.noarch.rpm SHA-256: d02ef86d26714130b93e549402a6b20ac0a430992d8457025c5c76214f9008bc
foreman-vmware-3.14.0.8-1.el9sat.noarch.rpm SHA-256: e10b698ea261aaf30b4ba8bfd276f5867e7a4f9e8a035393c49c7e857811fcbf
puppet-agent-8.8.1-3.el9sat.x86_64.rpm SHA-256: 9b307b0aa7ce3b0d1e65fca7bd8e77b7b16abf309def4e7ba28773b544455af8
python3.11-django-4.2.24-0.1.el9pc.noarch.rpm SHA-256: f2b65828c3c49b6530acc2a4a555cbf1ddc1931e5d68d847d049c92ed1afcfc8
rubygem-foreman_bootdisk-22.0.4-1.el9sat.noarch.rpm SHA-256: 6d0ae2b8237822972ac0f876eb38eb62422e0596a041842956dcb30e645cae15
satellite-6.17.5-1.el9sat.noarch.rpm SHA-256: 8c58e68865207e698eb6637f82b030c91132cc18e6de89fd575e628aa858df19
satellite-cli-6.17.5-1.el9sat.noarch.rpm SHA-256: 2f887d4ab66c50a9b55cfafd657ea898639708c8eb30dff04b26048c0842a626
satellite-common-6.17.5-1.el9sat.noarch.rpm SHA-256: 0d30efc0f7090bfbd6c431ec6aea0b3ae8da0f20f012b003b2378b067b45f9bf
satellite-obsolete-packages-6.17.5-1.el9sat.noarch.rpm SHA-256: 462682c952ffcd520df4b1cc9f5cdf900bf9d7e835c60b7867c1fefda66cfd45

Red Hat Satellite Capsule 6.17

SRPM
cjson-1.7.18-2.el9sat.src.rpm SHA-256: 7e3282c60fdba65ddce65e58aaaedaaa3eb5c4a9b7718ae66f625e2b6bb62dae
foreman-3.14.0.8-1.el9sat.src.rpm SHA-256: 903ff70291ee5899a56c949b0519973749305ffb59e6fcf94421137092e212b3
foreman-installer-3.14.0.7-1.el9sat.src.rpm SHA-256: 1b3da402cb9165b91d74124db5610d5332c8a72765b05af0b3e64f670b8e2fb3
puppet-agent-8.8.1-3.el9sat.src.rpm SHA-256: e29fda0b14a6b23ed56a9713346712a6081ae7bb2efb6e8dcbd2dcf8d3f01210
python-django-4.2.24-0.1.el9pc.src.rpm SHA-256: 255257b22246693d3114733ba7a4c630df8d2f109228150473af833bb438b3b7
satellite-6.17.5-1.el9sat.src.rpm SHA-256: b206a47a0cd10029095e3fa99ea98cb9a56cb785659345d8f685837ce40ef172
x86_64
cjson-1.7.18-2.el9sat.x86_64.rpm SHA-256: e4199697901ba2bee704bf83c85e39474b6a428a559ab41e7d371bf4e7433ff6
cjson-debuginfo-1.7.18-2.el9sat.x86_64.rpm SHA-256: 39fe5743b85609ac2a84e9c5b53807fc03f504de89d1eecf94c3f00771942a6d
cjson-debugsource-1.7.18-2.el9sat.x86_64.rpm SHA-256: b5afb3d73cf052786db1c79f09db8041652df644756bae7ca177c2019c346e6c
foreman-debug-3.14.0.8-1.el9sat.noarch.rpm SHA-256: bd552d7890ac4d1a9414113a1e77351066d23b58255b1186a7d0537f31b7cada
foreman-installer-3.14.0.7-1.el9sat.noarch.rpm SHA-256: 9f3b9e479aaa1d871995fb85d08eb5045b19ecb5a3010043c0b7d70ee413adc1
foreman-installer-katello-3.14.0.7-1.el9sat.noarch.rpm SHA-256: 1b0269d5ce45413879084b6c058a4ba9e18efa07e56b702c0f0d5c70b8007bdc
foreman-pcp-3.14.0.8-1.el9sat.noarch.rpm SHA-256: d471b421e59049552dfc33ea0e08a159878605170ded50d77f2bcb8d51f3bea6
puppet-agent-8.8.1-3.el9sat.x86_64.rpm SHA-256: 9b307b0aa7ce3b0d1e65fca7bd8e77b7b16abf309def4e7ba28773b544455af8
python3.11-django-4.2.24-0.1.el9pc.noarch.rpm SHA-256: f2b65828c3c49b6530acc2a4a555cbf1ddc1931e5d68d847d049c92ed1afcfc8
satellite-capsule-6.17.5-1.el9sat.noarch.rpm SHA-256: 3076f44a30f9bb3f4a83931eef5a6ff2b97437fb0c29971b9a96b0d1c4379914
satellite-common-6.17.5-1.el9sat.noarch.rpm SHA-256: 0d30efc0f7090bfbd6c431ec6aea0b3ae8da0f20f012b003b2378b067b45f9bf
satellite-obsolete-packages-6.17.5-1.el9sat.noarch.rpm SHA-256: 462682c952ffcd520df4b1cc9f5cdf900bf9d7e835c60b7867c1fefda66cfd45

Red Hat Enterprise Linux for x86_64 9

SRPM
foreman-3.14.0.8-1.el9sat.src.rpm SHA-256: 903ff70291ee5899a56c949b0519973749305ffb59e6fcf94421137092e212b3
satellite-6.17.5-1.el9sat.src.rpm SHA-256: b206a47a0cd10029095e3fa99ea98cb9a56cb785659345d8f685837ce40ef172
x86_64
foreman-cli-3.14.0.8-1.el9sat.noarch.rpm SHA-256: 2c7f5aecf694f1d15df9b4d5f8872e1041366d492a4787b7fd1fd35b327f4d1f
satellite-cli-6.17.5-1.el9sat.noarch.rpm SHA-256: 2f887d4ab66c50a9b55cfafd657ea898639708c8eb30dff04b26048c0842a626

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility