Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2042 - Security Advisory
Issued:
2026-02-05
Updated:
2026-02-05

RHSA-2026:2042 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: brotli security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for brotli is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression.

Security Fix(es):

  • Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS (CVE-2025-6176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2408762 - CVE-2025-6176 Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS

CVEs

  • CVE-2025-6176

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
brotli-1.0.9-9.el9_7.src.rpm SHA-256: 814868e0bec831c79d3e12ff76d31e06e5e62c462a1a4b6607b1f3cab7014438
x86_64
brotli-1.0.9-9.el9_7.i686.rpm SHA-256: 888d514c699db5eab3730eb368b25d118e9debb81997d94a7c8f14791f6b8beb
brotli-1.0.9-9.el9_7.x86_64.rpm SHA-256: 07e6fdb11f8d87999a602c08d2c30c1d028b41c1da70e2d1a3378ddc34bc2545
brotli-debuginfo-1.0.9-9.el9_7.i686.rpm SHA-256: 970f98c5ce87b0e3385a770eace0aeae3d756bada76803e1b8c8df5360411d54
brotli-debuginfo-1.0.9-9.el9_7.i686.rpm SHA-256: 970f98c5ce87b0e3385a770eace0aeae3d756bada76803e1b8c8df5360411d54
brotli-debuginfo-1.0.9-9.el9_7.x86_64.rpm SHA-256: 8d23cfd1cd217e83c0c97ca03e30c44ad783fa3d1d572c50e302afad76ac5e8b
brotli-debuginfo-1.0.9-9.el9_7.x86_64.rpm SHA-256: 8d23cfd1cd217e83c0c97ca03e30c44ad783fa3d1d572c50e302afad76ac5e8b
brotli-debugsource-1.0.9-9.el9_7.i686.rpm SHA-256: 933b10a9c43534223802affa66c58ece578a4d58a12bd02349aae96ab90a5fce
brotli-debugsource-1.0.9-9.el9_7.i686.rpm SHA-256: 933b10a9c43534223802affa66c58ece578a4d58a12bd02349aae96ab90a5fce
brotli-debugsource-1.0.9-9.el9_7.x86_64.rpm SHA-256: 56bb314baf10beab25ac27edf9e1c5413754f894d07d270221af48f418fc84f4
brotli-debugsource-1.0.9-9.el9_7.x86_64.rpm SHA-256: 56bb314baf10beab25ac27edf9e1c5413754f894d07d270221af48f418fc84f4
brotli-devel-1.0.9-9.el9_7.i686.rpm SHA-256: 8e5d62deba3d96dabe4fcfb9373fae5fb0e75d602935f6d2f3ce92956b6a5810
brotli-devel-1.0.9-9.el9_7.x86_64.rpm SHA-256: de65824d0eb3fa3e4720623ee878d6cb98e9ab32df4da460d8eaf3854faf2388
libbrotli-1.0.9-9.el9_7.i686.rpm SHA-256: 9e8df66061133f3a05b4da4f8b3cdb310781736bfb5e39cd5ec2ca337e983c81
libbrotli-1.0.9-9.el9_7.x86_64.rpm SHA-256: 81096e6aed022489306e2fe1d1496b2b689d8f0bf6c70a94b5bddb82356eeda1
libbrotli-debuginfo-1.0.9-9.el9_7.i686.rpm SHA-256: 1ca1f2f3a7ec90bd3408545e2278ee27b9ec1c286405fc6ce857138b17382ab8
libbrotli-debuginfo-1.0.9-9.el9_7.i686.rpm SHA-256: 1ca1f2f3a7ec90bd3408545e2278ee27b9ec1c286405fc6ce857138b17382ab8
libbrotli-debuginfo-1.0.9-9.el9_7.x86_64.rpm SHA-256: 305a8d55022b0093723d5b109eca1633d53ae1c844abedff6d52140d9e197d1c
libbrotli-debuginfo-1.0.9-9.el9_7.x86_64.rpm SHA-256: 305a8d55022b0093723d5b109eca1633d53ae1c844abedff6d52140d9e197d1c
python3-brotli-1.0.9-9.el9_7.x86_64.rpm SHA-256: eaedfa9f26a3428f6dbcdef8354a6fb01699c3d71ca16993d0cfdb5f99369414
python3-brotli-debuginfo-1.0.9-9.el9_7.i686.rpm SHA-256: e6e2a00f69e9913721a5a19e67c8b2f110944230e92724ddfd8c1c9383cd0e6d
python3-brotli-debuginfo-1.0.9-9.el9_7.i686.rpm SHA-256: e6e2a00f69e9913721a5a19e67c8b2f110944230e92724ddfd8c1c9383cd0e6d
python3-brotli-debuginfo-1.0.9-9.el9_7.x86_64.rpm SHA-256: a87c6ade2161bbaee8786a42313f0b99dc671f12e3140fbfa27129d50cf6aecb
python3-brotli-debuginfo-1.0.9-9.el9_7.x86_64.rpm SHA-256: a87c6ade2161bbaee8786a42313f0b99dc671f12e3140fbfa27129d50cf6aecb

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
brotli-1.0.9-9.el9_7.src.rpm SHA-256: 814868e0bec831c79d3e12ff76d31e06e5e62c462a1a4b6607b1f3cab7014438
s390x
brotli-1.0.9-9.el9_7.s390x.rpm SHA-256: 31c73531fb26eb2a03dcda7c131f7bf818444727c69736a19ac9db69e1aa5671
brotli-debuginfo-1.0.9-9.el9_7.s390x.rpm SHA-256: 71923015a9cdb2f4555f7c02bdd08f153efe5e37e90a7933855a01535dbaf166
brotli-debuginfo-1.0.9-9.el9_7.s390x.rpm SHA-256: 71923015a9cdb2f4555f7c02bdd08f153efe5e37e90a7933855a01535dbaf166
brotli-debugsource-1.0.9-9.el9_7.s390x.rpm SHA-256: 1ef6558993f9c1d538474c3fa0d777805793d5e299ef3496325577040832f0ab
brotli-debugsource-1.0.9-9.el9_7.s390x.rpm SHA-256: 1ef6558993f9c1d538474c3fa0d777805793d5e299ef3496325577040832f0ab
brotli-devel-1.0.9-9.el9_7.s390x.rpm SHA-256: 0b38a5b72b00758e53ac04e217bfd3117330b95c035007a1d1986a5bf964f862
libbrotli-1.0.9-9.el9_7.s390x.rpm SHA-256: ea47c24d8670923c31472fac1c2887ee8124b0a142ffb8a3c4953da8bf65c238
libbrotli-debuginfo-1.0.9-9.el9_7.s390x.rpm SHA-256: 77d69b8ca75b5258e52ffb0a553ab64098dc9a49cf342fa165c1e8ea8e04927c
libbrotli-debuginfo-1.0.9-9.el9_7.s390x.rpm SHA-256: 77d69b8ca75b5258e52ffb0a553ab64098dc9a49cf342fa165c1e8ea8e04927c
python3-brotli-1.0.9-9.el9_7.s390x.rpm SHA-256: a11fadc28cd3047c9cc9bdeeec43757d1efaed1f94f8c821668dd9da37365032
python3-brotli-debuginfo-1.0.9-9.el9_7.s390x.rpm SHA-256: 7fc0ec897604e96552aabf3dd44f2940b93dd19892be06e19025704e80bb4461
python3-brotli-debuginfo-1.0.9-9.el9_7.s390x.rpm SHA-256: 7fc0ec897604e96552aabf3dd44f2940b93dd19892be06e19025704e80bb4461

Red Hat Enterprise Linux for Power, little endian 9

SRPM
brotli-1.0.9-9.el9_7.src.rpm SHA-256: 814868e0bec831c79d3e12ff76d31e06e5e62c462a1a4b6607b1f3cab7014438
ppc64le
brotli-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 4f0739a863148d67f5010482df150aca400cbaee3d99d1eabb855eaf476a47aa
brotli-debuginfo-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 6eff592e544d6bc45cf7b60af1b1a6a6b5793096a4a7109a61c448186710e869
brotli-debuginfo-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 6eff592e544d6bc45cf7b60af1b1a6a6b5793096a4a7109a61c448186710e869
brotli-debugsource-1.0.9-9.el9_7.ppc64le.rpm SHA-256: dec4b22d5567b1d99ad96cc9e19049b6fa97639a825c53b51b8703e4ebebff08
brotli-debugsource-1.0.9-9.el9_7.ppc64le.rpm SHA-256: dec4b22d5567b1d99ad96cc9e19049b6fa97639a825c53b51b8703e4ebebff08
brotli-devel-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 2a1ba0a1da061d00fee876af72d333a92576f59dd4d9ae88cdc5d6aaccc1d93e
libbrotli-1.0.9-9.el9_7.ppc64le.rpm SHA-256: ff72df4a441c2f8ee8e1bcde8dcbd5bbd89250db9caf8792ff253b7af3e1c51c
libbrotli-debuginfo-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 9c6ec41f3755d4a5608aaa2b2de63eb14ab56ded6d713713c46c22aa8528b671
libbrotli-debuginfo-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 9c6ec41f3755d4a5608aaa2b2de63eb14ab56ded6d713713c46c22aa8528b671
python3-brotli-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 51d45025df01555b855998ea97b08521fc66e4a33dcd91eacd212deefdacdaf6
python3-brotli-debuginfo-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 8b0a1bab9cde085253e0bd163dd9903b74f5eca66ba82e40aad447f31826eecc
python3-brotli-debuginfo-1.0.9-9.el9_7.ppc64le.rpm SHA-256: 8b0a1bab9cde085253e0bd163dd9903b74f5eca66ba82e40aad447f31826eecc

Red Hat Enterprise Linux for ARM 64 9

SRPM
brotli-1.0.9-9.el9_7.src.rpm SHA-256: 814868e0bec831c79d3e12ff76d31e06e5e62c462a1a4b6607b1f3cab7014438
aarch64
brotli-1.0.9-9.el9_7.aarch64.rpm SHA-256: 9e297127b424f5421380599434a561e6dc03af242f10c52e68abcc249d568ff9
brotli-debuginfo-1.0.9-9.el9_7.aarch64.rpm SHA-256: 7bc443300d48685fe0c511e46cff08a74b3aabcf2171eac81a4a52b9f39e1e4f
brotli-debuginfo-1.0.9-9.el9_7.aarch64.rpm SHA-256: 7bc443300d48685fe0c511e46cff08a74b3aabcf2171eac81a4a52b9f39e1e4f
brotli-debugsource-1.0.9-9.el9_7.aarch64.rpm SHA-256: c8f364c406f4ddff30599c64abd910d16336f9ba5aeb765d1be14f7914682503
brotli-debugsource-1.0.9-9.el9_7.aarch64.rpm SHA-256: c8f364c406f4ddff30599c64abd910d16336f9ba5aeb765d1be14f7914682503
brotli-devel-1.0.9-9.el9_7.aarch64.rpm SHA-256: 51731d4a662422b238ee711360739abff827e010b895573d34149adbb3c7be22
libbrotli-1.0.9-9.el9_7.aarch64.rpm SHA-256: f5237abc90191238333c1214da97b5202c8a15c2be3ab401ee10d95343cfdf17
libbrotli-debuginfo-1.0.9-9.el9_7.aarch64.rpm SHA-256: 6d136434067bc0ca9b5c7ecd8021e6410a57f49bc3b7e40e4a9645ea7fdedeb9
libbrotli-debuginfo-1.0.9-9.el9_7.aarch64.rpm SHA-256: 6d136434067bc0ca9b5c7ecd8021e6410a57f49bc3b7e40e4a9645ea7fdedeb9
python3-brotli-1.0.9-9.el9_7.aarch64.rpm SHA-256: af220cad99b6b23cf01d0eed75d7d035e41abb1a233dd02096db3ac166cf68b8
python3-brotli-debuginfo-1.0.9-9.el9_7.aarch64.rpm SHA-256: b1ed60f8acd3e152c3e5ad34c654b6631c8a3ba464a2f1b108c573ef7ef68653
python3-brotli-debuginfo-1.0.9-9.el9_7.aarch64.rpm SHA-256: b1ed60f8acd3e152c3e5ad34c654b6631c8a3ba464a2f1b108c573ef7ef68653

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility