Synopsis
Important: opentelemetry-collector security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
- google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
- github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
- crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
- crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
- golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
- crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
- crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x
Fixes
-
BZ - 2445356
- CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
-
BZ - 2449833
- CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
-
BZ - 2455470
- CVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
-
BZ - 2456333
- CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
-
BZ - 2456335
- CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
-
BZ - 2456336
- CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
-
BZ - 2456338
- CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
-
BZ - 2456339
- CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| x86_64 |
|
opentelemetry-collector-0.144.0-2.el9_8.x86_64.rpm
|
SHA-256: 301355352c8ef712b1c174b7c241ab3f3892d8d55ced36553824a3791da8ff92 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| x86_64 |
|
opentelemetry-collector-0.144.0-2.el9_8.x86_64.rpm
|
SHA-256: 301355352c8ef712b1c174b7c241ab3f3892d8d55ced36553824a3791da8ff92 |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| s390x |
|
opentelemetry-collector-0.144.0-2.el9_8.s390x.rpm
|
SHA-256: ef42ef820f5333bc9d799bce14d1c0040f284a482f76774865cdb7ab78aec609 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| s390x |
|
opentelemetry-collector-0.144.0-2.el9_8.s390x.rpm
|
SHA-256: ef42ef820f5333bc9d799bce14d1c0040f284a482f76774865cdb7ab78aec609 |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| ppc64le |
|
opentelemetry-collector-0.144.0-2.el9_8.ppc64le.rpm
|
SHA-256: a985c7d0c588a10b89c3a2d5940d1e53fee3501cd7c5379285cfbc942a4b0850 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| ppc64le |
|
opentelemetry-collector-0.144.0-2.el9_8.ppc64le.rpm
|
SHA-256: a985c7d0c588a10b89c3a2d5940d1e53fee3501cd7c5379285cfbc942a4b0850 |
Red Hat Enterprise Linux for ARM 64 9
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| aarch64 |
|
opentelemetry-collector-0.144.0-2.el9_8.aarch64.rpm
|
SHA-256: 82583ef71ca97d17307e0bdac5b480e757385c60414c15c4100d29e54dffd96b |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| aarch64 |
|
opentelemetry-collector-0.144.0-2.el9_8.aarch64.rpm
|
SHA-256: 82583ef71ca97d17307e0bdac5b480e757385c60414c15c4100d29e54dffd96b |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| ppc64le |
|
opentelemetry-collector-0.144.0-2.el9_8.ppc64le.rpm
|
SHA-256: a985c7d0c588a10b89c3a2d5940d1e53fee3501cd7c5379285cfbc942a4b0850 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| x86_64 |
|
opentelemetry-collector-0.144.0-2.el9_8.x86_64.rpm
|
SHA-256: 301355352c8ef712b1c174b7c241ab3f3892d8d55ced36553824a3791da8ff92 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| aarch64 |
|
opentelemetry-collector-0.144.0-2.el9_8.aarch64.rpm
|
SHA-256: 82583ef71ca97d17307e0bdac5b480e757385c60414c15c4100d29e54dffd96b |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| s390x |
|
opentelemetry-collector-0.144.0-2.el9_8.s390x.rpm
|
SHA-256: ef42ef820f5333bc9d799bce14d1c0040f284a482f76774865cdb7ab78aec609 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| x86_64 |
|
opentelemetry-collector-0.144.0-2.el9_8.x86_64.rpm
|
SHA-256: 301355352c8ef712b1c174b7c241ab3f3892d8d55ced36553824a3791da8ff92 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| aarch64 |
|
opentelemetry-collector-0.144.0-2.el9_8.aarch64.rpm
|
SHA-256: 82583ef71ca97d17307e0bdac5b480e757385c60414c15c4100d29e54dffd96b |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| ppc64le |
|
opentelemetry-collector-0.144.0-2.el9_8.ppc64le.rpm
|
SHA-256: a985c7d0c588a10b89c3a2d5940d1e53fee3501cd7c5379285cfbc942a4b0850 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8
| SRPM |
|
opentelemetry-collector-0.144.0-2.el9_8.src.rpm
|
SHA-256: 93d0e770a9100e1eb12838e9096b24e6afca8d5d231ce43b836291852d24daa0 |
| s390x |
|
opentelemetry-collector-0.144.0-2.el9_8.s390x.rpm
|
SHA-256: ef42ef820f5333bc9d799bce14d1c0040f284a482f76774865cdb7ab78aec609 |