Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:19855 - Security Advisory
Issued:
2025-11-06
Updated:
2025-11-06

RHSA-2025:19855 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Satellite 6.16.5.5 Async Update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat Satellite 6.16 for RHEL 8 and RHEL 9.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

  • Host registration shows no errors even when built submission fails at the end of Global Registration process
  • rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)
  • rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)
  • foreman: OS command injection via ct_location and fcct_location parameters (CVE-2025-10622)

Users of Red Hat Satellite are advised to upgrade to these updated
packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Satellite 6.16 for RHEL 9 x86_64
  • Red Hat Satellite 6.16 for RHEL 8 x86_64
  • Red Hat Satellite Capsule 6.16 for RHEL 9 x86_64
  • Red Hat Satellite Capsule 6.16 for RHEL 8 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64

Fixes

  • BZ - 2396020 - CVE-2025-10622 foreman: OS command injection via ct_location and fcct_location parameters
  • BZ - 2398167 - CVE-2025-59830 rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters
  • BZ - 2403180 - CVE-2025-61919 rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion
  • SAT-39698 - Host registration shows no errors even when built submission fails at the end of Global Registration process [6.16.5.5]

CVEs

  • CVE-2025-10622
  • CVE-2025-59830
  • CVE-2025-61919

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Satellite 6.16 for RHEL 9

SRPM
foreman-3.12.0.11-1.el9sat.src.rpm SHA-256: edbb9703f0f2ae6c32f5b0bcd9e5021a82345c1a76438ee14ac18fa0b2e8a949
rubygem-rack-2.2.20-1.el9sat.src.rpm SHA-256: 90b55249cd79e2c97d422bd683ebfcf29d0c0b441c3fae2f231569c93dd42a82
satellite-6.16.5.5-1.el9sat.src.rpm SHA-256: b8d9b6e5b82459932dd59e2073b424ceb9e2f7f4ef5a5de2324276bcbe9cca1b
x86_64
foreman-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 98b8bd3662b77033a8d9f68caf862f29648aeb34dacef05b763bb2f591777a39
foreman-cli-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 6555682b6262318db0dacaadc811cb31dc0e210a311902b90298d9531c84c9bd
foreman-debug-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 2d1e341e906f92aa4dd5d6517a6f1bc89d25590f4dae949c5b9f670fa2a158f6
foreman-dynflow-sidekiq-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 0ef697f53f06a05d5ea749901ed0d1784b8c225f8346a056a5fd4cab25c1b5b6
foreman-ec2-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 529eecefbfcb12e94803aed0a08c4758d4c1a1c94ae7f00f11f459a3a8cc677a
foreman-journald-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 37b59faddfaebbea57972ceec047110a4db86f6a4627d9f7e57f9ade729a3d69
foreman-libvirt-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 2b5d41ded7132f4b8874c6a9d065af44f95dd4313dcda5f36531063adc4bcf81
foreman-openstack-3.12.0.11-1.el9sat.noarch.rpm SHA-256: acf97ac773a50ba998847d1ca1da5886e590eaab42e232e87bfa3783fb9fe167
foreman-ovirt-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 5fa27153d2e456fd32ddf010716d32799bf1228dc4a69b9716b690547166feb5
foreman-pcp-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 6c7bbfc9707637f0b1c1d887777ecc3f7ea798abd19a8edca59fc4d10d194760
foreman-postgresql-3.12.0.11-1.el9sat.noarch.rpm SHA-256: d13323cda02ad54fa9c6f6175fc04bdc82546f345070ad6388e6510b3229cc55
foreman-redis-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 9a1b5bb814a97e07556577808c186d3dca0db57254e5ef8d9268bfcaa51b6951
foreman-service-3.12.0.11-1.el9sat.noarch.rpm SHA-256: fb11fa7b2359a0b1c7e823d8e687c5a58a59fe0d8ee5004cb9cd165d783eecfb
foreman-telemetry-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 399cbfc96080160c0a7a4bef0975d3df71fd01ff477c82f88b0622ef9ba79f13
foreman-vmware-3.12.0.11-1.el9sat.noarch.rpm SHA-256: ccf5d7cfa3f5091cc0fe7ca3ecb9a5e764149f3217ad596fcbfac1c5c98b4d92
rubygem-rack-2.2.20-1.el9sat.noarch.rpm SHA-256: d078d57ed494f2751026286770bbaf4f5945eb34ed33cfb2f103fc60699d37a9
satellite-6.16.5.5-1.el9sat.noarch.rpm SHA-256: 71ce9291bd9978726140a9cab1a8972e4030c9d3d52a917a6cd0874eee6b0a26
satellite-cli-6.16.5.5-1.el9sat.noarch.rpm SHA-256: 10c1ed054573bd067357640541a5437a28e4040506fde6465b43aac25792c86a
satellite-common-6.16.5.5-1.el9sat.noarch.rpm SHA-256: bb272ae5d899246dcac4ab2846acc347f38d52fd4160456899451c3cd0dceef4

Red Hat Satellite 6.16 for RHEL 8

SRPM
foreman-3.12.0.11-1.el8sat.src.rpm SHA-256: f784413c424715560d94c2ce3c1e656db08f1275f8709a056e92c9cf452f5dea
rubygem-rack-2.2.20-1.el8sat.src.rpm SHA-256: 60ad3ec844b2bf69e9aeccd73961ed25b2ac796fd0d0838be283eec6ff2d66f4
satellite-6.16.5.5-1.el8sat.src.rpm SHA-256: a8bedd22ef9317d123faaa50a6fc3f481cc323ada7949ea86d7fc36b6e1c69b3
x86_64
foreman-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 26e52189842632e47c2c12b96ff21a6d0c8842d7437a8d6c38b751c6ef20ee35
foreman-cli-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 76f3d177fd84b32a1f820371839373de0b78fb3424f66562585f0735ad349fb4
foreman-debug-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 7c3f10833e955cf842871030dd087721184857bc6ed852944af0784ba890c500
foreman-dynflow-sidekiq-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 2e708036436497bfa837da5e4e289bc39c97a906dc125a8c99538ac1abd156dd
foreman-ec2-3.12.0.11-1.el8sat.noarch.rpm SHA-256: b9140be8d16d5042691c33f1ce9c3be72e72d22cb4358534822acd1826d270ce
foreman-journald-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 9ae0335b0ab6cda5de563531ed55d9affc1c0cbb40085b2bddb56dd018e389d8
foreman-libvirt-3.12.0.11-1.el8sat.noarch.rpm SHA-256: c404a83746c2907b415d020a02bcd4466c3dd0ba53809e1c1bdf0dcaee69f2a9
foreman-openstack-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 011da438ec5e45dba7cf0d07dcc38cddfacf88adf96c574898aa248b258551c5
foreman-ovirt-3.12.0.11-1.el8sat.noarch.rpm SHA-256: c9ee433f7f141ca4603ddcc45fd720858d789def1af40d6375364c74c216aa2d
foreman-pcp-3.12.0.11-1.el8sat.noarch.rpm SHA-256: edbea972314b44ada386dc888c361dc63a07b91e70b38a70696fcb8518ed054e
foreman-postgresql-3.12.0.11-1.el8sat.noarch.rpm SHA-256: d4c9771572177667f887547fe271e03b447bf34d932936fa1d30432f893f885b
foreman-redis-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 97f5a0c0e56dd11b7e6aced8b18bba26c9ffe7ac6864c4259a4a7fba9f2b9d13
foreman-service-3.12.0.11-1.el8sat.noarch.rpm SHA-256: b78993dd0ec009a52fe80c2986a14508f913c39ffb244154bb6010560bf7dbc8
foreman-telemetry-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 889d5130945dc1b9dbb9f2b59b871d047751463c47c5b833cfb3d9674fbec431
foreman-vmware-3.12.0.11-1.el8sat.noarch.rpm SHA-256: f6c6e8b0d28296e6b865ba5147c29483a56d716eaaeeb30d8056ecc0b66668ba
rubygem-rack-2.2.20-1.el8sat.noarch.rpm SHA-256: 68ae53442c99ec2550962c7399a0007fdb5fd0bab88e6044623559465c3861c9
satellite-6.16.5.5-1.el8sat.noarch.rpm SHA-256: ca22ad782014ee3536a300ec850ebf3b7964be9d63c6d884e3d8ffd1a0c4dd1e
satellite-cli-6.16.5.5-1.el8sat.noarch.rpm SHA-256: 2de94a9fe4b65c88c76c61c1fd05915187e296bff8892d4aeba41209650ca664
satellite-common-6.16.5.5-1.el8sat.noarch.rpm SHA-256: 1e3cecc1a58b6e3ffc75df78744838d1ba7bcb1bd4ce02bd88044c828dd61b75

Red Hat Satellite Capsule 6.16 for RHEL 9

SRPM
foreman-3.12.0.11-1.el9sat.src.rpm SHA-256: edbb9703f0f2ae6c32f5b0bcd9e5021a82345c1a76438ee14ac18fa0b2e8a949
rubygem-rack-2.2.20-1.el9sat.src.rpm SHA-256: 90b55249cd79e2c97d422bd683ebfcf29d0c0b441c3fae2f231569c93dd42a82
satellite-6.16.5.5-1.el9sat.src.rpm SHA-256: b8d9b6e5b82459932dd59e2073b424ceb9e2f7f4ef5a5de2324276bcbe9cca1b
x86_64
foreman-debug-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 2d1e341e906f92aa4dd5d6517a6f1bc89d25590f4dae949c5b9f670fa2a158f6
foreman-pcp-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 6c7bbfc9707637f0b1c1d887777ecc3f7ea798abd19a8edca59fc4d10d194760
rubygem-rack-2.2.20-1.el9sat.noarch.rpm SHA-256: d078d57ed494f2751026286770bbaf4f5945eb34ed33cfb2f103fc60699d37a9
satellite-capsule-6.16.5.5-1.el9sat.noarch.rpm SHA-256: 8d8847abeb0bbfb4f9364cca83a34d025361476a100b8c2a636a28f6bd8e58d1
satellite-common-6.16.5.5-1.el9sat.noarch.rpm SHA-256: bb272ae5d899246dcac4ab2846acc347f38d52fd4160456899451c3cd0dceef4

Red Hat Satellite Capsule 6.16 for RHEL 8

SRPM
foreman-3.12.0.11-1.el8sat.src.rpm SHA-256: f784413c424715560d94c2ce3c1e656db08f1275f8709a056e92c9cf452f5dea
rubygem-rack-2.2.20-1.el8sat.src.rpm SHA-256: 60ad3ec844b2bf69e9aeccd73961ed25b2ac796fd0d0838be283eec6ff2d66f4
satellite-6.16.5.5-1.el8sat.src.rpm SHA-256: a8bedd22ef9317d123faaa50a6fc3f481cc323ada7949ea86d7fc36b6e1c69b3
x86_64
foreman-debug-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 7c3f10833e955cf842871030dd087721184857bc6ed852944af0784ba890c500
foreman-pcp-3.12.0.11-1.el8sat.noarch.rpm SHA-256: edbea972314b44ada386dc888c361dc63a07b91e70b38a70696fcb8518ed054e
rubygem-rack-2.2.20-1.el8sat.noarch.rpm SHA-256: 68ae53442c99ec2550962c7399a0007fdb5fd0bab88e6044623559465c3861c9
satellite-capsule-6.16.5.5-1.el8sat.noarch.rpm SHA-256: 0897ba770d3aaf5326111b5db8019aecb24ab65503d9254fa3e34389ddcab52e
satellite-common-6.16.5.5-1.el8sat.noarch.rpm SHA-256: 1e3cecc1a58b6e3ffc75df78744838d1ba7bcb1bd4ce02bd88044c828dd61b75

Red Hat Enterprise Linux for x86_64 9

SRPM
foreman-3.12.0.11-1.el9sat.src.rpm SHA-256: edbb9703f0f2ae6c32f5b0bcd9e5021a82345c1a76438ee14ac18fa0b2e8a949
satellite-6.16.5.5-1.el9sat.src.rpm SHA-256: b8d9b6e5b82459932dd59e2073b424ceb9e2f7f4ef5a5de2324276bcbe9cca1b
x86_64
foreman-cli-3.12.0.11-1.el9sat.noarch.rpm SHA-256: 6555682b6262318db0dacaadc811cb31dc0e210a311902b90298d9531c84c9bd
satellite-cli-6.16.5.5-1.el9sat.noarch.rpm SHA-256: 10c1ed054573bd067357640541a5437a28e4040506fde6465b43aac25792c86a

Red Hat Enterprise Linux for x86_64 8

SRPM
foreman-3.12.0.11-1.el8sat.src.rpm SHA-256: f784413c424715560d94c2ce3c1e656db08f1275f8709a056e92c9cf452f5dea
satellite-6.16.5.5-1.el8sat.src.rpm SHA-256: a8bedd22ef9317d123faaa50a6fc3f481cc323ada7949ea86d7fc36b6e1c69b3
x86_64
foreman-cli-3.12.0.11-1.el8sat.noarch.rpm SHA-256: 76f3d177fd84b32a1f820371839373de0b78fb3424f66562585f0735ad349fb4
satellite-cli-6.16.5.5-1.el8sat.noarch.rpm SHA-256: 2de94a9fe4b65c88c76c61c1fd05915187e296bff8892d4aeba41209650ca664

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility