Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:19832 - Security Advisory
Issued:
2025-11-05
Updated:
2025-11-05

RHSA-2025:19832 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Satellite 6.17.6 Async Update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A new release is now available for Red Hat Satellite 6.17 for RHEL 9.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

  • rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)
  • rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)
  • foreman: OS command injection via ct_location and fcct_location parameters (CVE-2025-10622)

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index

Affected Products

  • Red Hat Satellite 6.17 x86_64
  • Red Hat Satellite Capsule 6.17 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64

Fixes

  • BZ - 2396020 - CVE-2025-10622 foreman: OS command injection via ct_location and fcct_location parameters
  • BZ - 2398167 - CVE-2025-59830 rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters
  • BZ - 2403180 - CVE-2025-61919 rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion
  • SAT-39213 - Host registration shows no errors even when built submission fails at the end of Global Registration process
  • SAT-39215 - OpenSCAP reports shown falsely as succeeded
  • SAT-39216 - Clean duplicate erratum packages before bigint migration
  • SAT-39217 - Busy Satellite with no candlepin restart hits "database is not accepting commands" fatal error
  • SAT-39219 - Filter in content host page not working properly
  • SAT-39232 - Regression - Bootdisk generation fails with "ERF42-8203 [Foreman::Exception]: Ensure /var/lib/tftpboot/grub2/mmx64.efi is readable (or update "Grub2 directory" setting)"

CVEs

  • CVE-2025-10622
  • CVE-2025-59830
  • CVE-2025-61919

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Satellite 6.17

SRPM
candlepin-4.4.23-1.el9sat.src.rpm SHA-256: e8f7694331028b014c1eb16e19d8660f412c20c1b3e1f9c6ea3adc465f4a0da7
foreman-3.14.0.10-1.el9sat.src.rpm SHA-256: b13f8125139b9e55c031b3cf33535091a06948d5f72a5be92bee3a04f4d85083
foreman-bootloaders-redhat-202506020000-1.el9sat.src.rpm SHA-256: 08157f56eaaac386a24a2499d487d1298ff42a7f8ecf8956a1c376def25bd5a9
rubygem-foreman_maintain-1.10.4-1.el9sat.src.rpm SHA-256: bd7b03da3b4d42cd2590929f3d461073874f5e357bbe1cebe4d1ad1db44a9248
rubygem-katello-4.16.0.10-1.el9sat.src.rpm SHA-256: 333ee9ec5107dcbd3ac00e73327db96a7f0b9037454b6c159af4a1e7f113399d
rubygem-rack-2.2.20-1.el9sat.src.rpm SHA-256: 90b55249cd79e2c97d422bd683ebfcf29d0c0b441c3fae2f231569c93dd42a82
rubygem-smart_proxy_openscap-0.12.1-1.el9sat.src.rpm SHA-256: 21bb84ac49885d5431a8fdf8d859c0b5774b0e0b346d90909d2d0d53d6d30aab
satellite-6.17.6-1.el9sat.src.rpm SHA-256: 79a74d6b61f009d84862894bdadd64823356218948ee15e9e8a89a6f950372ad
x86_64
candlepin-4.4.23-1.el9sat.noarch.rpm SHA-256: 904615d204b225c1dba1b7177c4822a9854c06814caec559c838cead8febd09b
candlepin-selinux-4.4.23-1.el9sat.noarch.rpm SHA-256: a63d2f451b72d8a8f9b5da7bb72851834d9dd5ec8ea285706005f096e7341094
foreman-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 88e0a470cfe834dfd4a973283349713456ca82f6aaa2bea54ecbc183ac35150e
foreman-bootloaders-redhat-202506020000-1.el9sat.noarch.rpm SHA-256: 5acf805857a962eb0a5deb774797085dc3aa96f0bfd9750cd257ad740ee5e747
foreman-bootloaders-redhat-tftpboot-202506020000-1.el9sat.noarch.rpm SHA-256: 5ec6090ea7c4047645c8fe5452edf096cd5704d0eb3bb5a0f523b636c1de1dd4
foreman-cli-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 8139283be66c6df76093c3f31c2e2c86eef723d1cf96a2e2b852ad0df57f24ca
foreman-debug-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 8ba953c2dd79abd7a4f2ade93f3247a62646b502500a0d31bf2c12de15ded9d6
foreman-dynflow-sidekiq-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 8702c414b18002698231917389e1d548058afc7aff97b209bc93daba59c22def
foreman-ec2-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 074c9f55b158ded67eac61e40db129850e9c5e790b2bd418f99b590aff657498
foreman-journald-3.14.0.10-1.el9sat.noarch.rpm SHA-256: a52e57b6911501c7c8d4d52341a23bb42454e3e7ff50a225a313e763317ca8ad
foreman-libvirt-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 503dcbbf64cf53e3f8401fcb8145b6b3efb82904de06cdd2752047b2993d35b3
foreman-openstack-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 4c5f0c97fd108c9d6cfbc53038c8629e76230e374463da6949cd8029d70cdf6e
foreman-ovirt-3.14.0.10-1.el9sat.noarch.rpm SHA-256: b4ced571bd983c5670c48930dd845367e8e0e3e9ef0bc31089cf543fed20c50d
foreman-pcp-3.14.0.10-1.el9sat.noarch.rpm SHA-256: e1161b7ae47bff0ff98237477c6418882b8c8d263e9c73c199231ae870ca3062
foreman-postgresql-3.14.0.10-1.el9sat.noarch.rpm SHA-256: c9fa73a0a85d7084a8230e8798e2ab7019027d6f256559d87ff685077034875e
foreman-redis-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 0c43bb513aa515a30e6133fd28c304e191035c3051a439eba024b76887a1f4ad
foreman-service-3.14.0.10-1.el9sat.noarch.rpm SHA-256: f5b23eab68bb450f6e671c0c42de2507b573211c39d14f0d533c0ad45a0629ae
foreman-telemetry-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 85fb3ffc583b846970a6d8679dd044e8f426d7847b947171ed358b5df24a4cf6
foreman-vmware-3.14.0.10-1.el9sat.noarch.rpm SHA-256: bc9d8f1dbda3b221d7bb452d22f9a6b967da3636dbd4f920c3c2ba7cd4ffea0a
rubygem-foreman_maintain-1.10.4-1.el9sat.noarch.rpm SHA-256: 64a615af5e76770829e15b150f7553be5427c49e64a228eabaf3ba3ae56daf0f
rubygem-katello-4.16.0.10-1.el9sat.noarch.rpm SHA-256: ab6c90cfc4b16b0b69367380f98f0b2b92f1d206032397a792b68cfbdaf54c3b
rubygem-rack-2.2.20-1.el9sat.noarch.rpm SHA-256: d078d57ed494f2751026286770bbaf4f5945eb34ed33cfb2f103fc60699d37a9
rubygem-smart_proxy_openscap-0.12.1-1.el9sat.noarch.rpm SHA-256: 55f0cc9d7793c4d7bab9bcac026be8c542bd3bcf3e4d199484726ba94f0a9511
satellite-6.17.6-1.el9sat.noarch.rpm SHA-256: 95f52f4ac1223757ec204aa5910ca1f1f3e7a423174869603bc85be5081338bd
satellite-cli-6.17.6-1.el9sat.noarch.rpm SHA-256: f24ada587c5bd128655ac96d0c0435a743addad2142cc0b3ea4103b9c2c9701f
satellite-common-6.17.6-1.el9sat.noarch.rpm SHA-256: 901657ad89590584fcfd18ac49b2c367c1044489739702cff0ad2d3a87cd47e4
satellite-obsolete-packages-6.17.6-1.el9sat.noarch.rpm SHA-256: 9f5476d0582906631d0ae12b286fa7fbb0147c4c58b1d40a30f5a1b41af68b27

Red Hat Satellite Capsule 6.17

SRPM
foreman-3.14.0.10-1.el9sat.src.rpm SHA-256: b13f8125139b9e55c031b3cf33535091a06948d5f72a5be92bee3a04f4d85083
foreman-bootloaders-redhat-202506020000-1.el9sat.src.rpm SHA-256: 08157f56eaaac386a24a2499d487d1298ff42a7f8ecf8956a1c376def25bd5a9
rubygem-foreman_maintain-1.10.4-1.el9sat.src.rpm SHA-256: bd7b03da3b4d42cd2590929f3d461073874f5e357bbe1cebe4d1ad1db44a9248
rubygem-rack-2.2.20-1.el9sat.src.rpm SHA-256: 90b55249cd79e2c97d422bd683ebfcf29d0c0b441c3fae2f231569c93dd42a82
rubygem-smart_proxy_openscap-0.12.1-1.el9sat.src.rpm SHA-256: 21bb84ac49885d5431a8fdf8d859c0b5774b0e0b346d90909d2d0d53d6d30aab
satellite-6.17.6-1.el9sat.src.rpm SHA-256: 79a74d6b61f009d84862894bdadd64823356218948ee15e9e8a89a6f950372ad
x86_64
foreman-bootloaders-redhat-202506020000-1.el9sat.noarch.rpm SHA-256: 5acf805857a962eb0a5deb774797085dc3aa96f0bfd9750cd257ad740ee5e747
foreman-bootloaders-redhat-tftpboot-202506020000-1.el9sat.noarch.rpm SHA-256: 5ec6090ea7c4047645c8fe5452edf096cd5704d0eb3bb5a0f523b636c1de1dd4
foreman-debug-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 8ba953c2dd79abd7a4f2ade93f3247a62646b502500a0d31bf2c12de15ded9d6
foreman-pcp-3.14.0.10-1.el9sat.noarch.rpm SHA-256: e1161b7ae47bff0ff98237477c6418882b8c8d263e9c73c199231ae870ca3062
rubygem-foreman_maintain-1.10.4-1.el9sat.noarch.rpm SHA-256: 64a615af5e76770829e15b150f7553be5427c49e64a228eabaf3ba3ae56daf0f
rubygem-rack-2.2.20-1.el9sat.noarch.rpm SHA-256: d078d57ed494f2751026286770bbaf4f5945eb34ed33cfb2f103fc60699d37a9
rubygem-smart_proxy_openscap-0.12.1-1.el9sat.noarch.rpm SHA-256: 55f0cc9d7793c4d7bab9bcac026be8c542bd3bcf3e4d199484726ba94f0a9511
satellite-capsule-6.17.6-1.el9sat.noarch.rpm SHA-256: 4b12a8d4e16e62f252308b7ddb5937ee9d23c11858271a24569385acb85ae117
satellite-common-6.17.6-1.el9sat.noarch.rpm SHA-256: 901657ad89590584fcfd18ac49b2c367c1044489739702cff0ad2d3a87cd47e4
satellite-obsolete-packages-6.17.6-1.el9sat.noarch.rpm SHA-256: 9f5476d0582906631d0ae12b286fa7fbb0147c4c58b1d40a30f5a1b41af68b27

Red Hat Enterprise Linux for x86_64 9

SRPM
foreman-3.14.0.10-1.el9sat.src.rpm SHA-256: b13f8125139b9e55c031b3cf33535091a06948d5f72a5be92bee3a04f4d85083
rubygem-foreman_maintain-1.10.4-1.el9sat.src.rpm SHA-256: bd7b03da3b4d42cd2590929f3d461073874f5e357bbe1cebe4d1ad1db44a9248
satellite-6.17.6-1.el9sat.src.rpm SHA-256: 79a74d6b61f009d84862894bdadd64823356218948ee15e9e8a89a6f950372ad
x86_64
foreman-cli-3.14.0.10-1.el9sat.noarch.rpm SHA-256: 8139283be66c6df76093c3f31c2e2c86eef723d1cf96a2e2b852ad0df57f24ca
rubygem-foreman_maintain-1.10.4-1.el9sat.noarch.rpm SHA-256: 64a615af5e76770829e15b150f7553be5427c49e64a228eabaf3ba3ae56daf0f
satellite-cli-6.17.6-1.el9sat.noarch.rpm SHA-256: f24ada587c5bd128655ac96d0c0435a743addad2142cc0b3ea4103b9c2c9701f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility