Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:41019 - Security Advisory
Issued:
2026-07-16
Updated:
2026-07-16

RHSA-2026:41019 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat Edge Manager Version 1.1.3 Security Update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat Edge Manager Version 1.1.3 Security Update

Description

Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused
management of edge devices and applications. It supports image-mode RHEL and
container workloads that run on Podman/Docker or Kubernetes.

RHEM is now available as a standalone feature, providing greater flexibility for
edge deployments. In addition to the standalone version, RHEM continues to be
offered as a plugin for the following platforms:

Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge
devices.
Red Hat Ansible Automation Platform (AAP): Integrates edge management with
Ansible automation.

This integration enables organizations to optimize the management and
orchestration of their fleets of edge devices; whether its thousands of
dispersed retail point-of-sale systems or industrial machinery on remote factory
floors.

Value for customers and partners:

  • This solution not only helps customers manage thousands of devices but helps

scale operations.

  • To manage large-scale deployments, customers need to be able to integrate with

their existing management systems, support remote configuration and over-the-air
updates, and collect telemetry data for advanced analytics.

  • Red Hat Edge Manager offers a simple and security-focused lifecycle

management, from onboarding to decommissioning of edge devices.

This complete end-to-end solution empowers organizations to gain the most value
from the fleets of devices that generate data, all from a centralized location.

Security fixes:

  • golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  • golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)
  • golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  • golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions (CVE-2026-39828)
  • golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)
  • golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  • golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
  • golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  • Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  • Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  • Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  • Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
  • Go crypto/x509: Incorrect enforcement of email constraints (CVE-2026-27137)
  • Go net/url: Incorrect parsing of IPv6 host literals (CVE-2026-25679)
  • golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816)
  • github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815)
  • gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
  • Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
  • Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
  • Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  • Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469)

Solution

See the following documentation for details on how to enable Red Hat Edge
Manager and more:
https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1

Affected Products

  • Red Hat Edge Manager 1.1 for RHEL 10 x86_64
  • Red Hat Edge Manager 1.1 for RHEL 10 s390x
  • Red Hat Edge Manager 1.1 for RHEL 10 ppc64le
  • Red Hat Edge Manager 1.1 for RHEL 10 aarch64
  • Red Hat Edge Manager 1.1 for RHEL 9 x86_64
  • Red Hat Edge Manager 1.1 for RHEL 9 s390x
  • Red Hat Edge Manager 1.1 for RHEL 9 ppc64le
  • Red Hat Edge Manager 1.1 for RHEL 9 aarch64

Fixes

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2445345 - CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
  • BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
  • BZ - 2449833 - CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
  • BZ - 2455972 - CVE-2026-33816 github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability
  • BZ - 2455975 - CVE-2026-33815 github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability
  • BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
  • BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
  • BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
  • BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
  • BZ - 2457729 - CVE-2026-35469 Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
  • BZ - 2466505 - CVE-2026-42154 github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
  • BZ - 2466507 - CVE-2026-42151 github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
  • BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
  • BZ - 2480680 - CVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
  • BZ - 2480681 - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
  • BZ - 2480684 - CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
  • BZ - 2480685 - CVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
  • BZ - 2480687 - CVE-2026-39828 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
  • BZ - 2480688 - CVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
  • BZ - 2480689 - CVE-2026-46595 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
  • BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing

CVEs

  • CVE-2025-61729
  • CVE-2026-25679
  • CVE-2026-27137
  • CVE-2026-32280
  • CVE-2026-32281
  • CVE-2026-32282
  • CVE-2026-32283
  • CVE-2026-33186
  • CVE-2026-33811
  • CVE-2026-33815
  • CVE-2026-33816
  • CVE-2026-35469
  • CVE-2026-39821
  • CVE-2026-39828
  • CVE-2026-39829
  • CVE-2026-39830
  • CVE-2026-39832
  • CVE-2026-39835
  • CVE-2026-42151
  • CVE-2026-42154
  • CVE-2026-42508
  • CVE-2026-46595

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_enterprise_linux/rhem-integrating-with-aap
  • https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_openshift_container_platform/edge-manager-install-rhem-ocp#edge-manager-verify-rhem-acm-console
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Edge Manager 1.1 for RHEL 10

SRPM
flightctl-1.1.3-1.el10em.src.rpm SHA-256: 3ecdc6e393545cebcb8a3a7e3c0825ca4d027e8cd4ce172bfaac043cc3b0bb58
x86_64
flightctl-agent-1.1.3-1.el10em.x86_64.rpm SHA-256: 8bb2627fecd765fac266d530a3d80b26d881090de7afe539b1347bd92568bb60
flightctl-cli-1.1.3-1.el10em.x86_64.rpm SHA-256: 30fc5256f2164618201446a2cca7471f22ed453ffc2fad83f89bbf53fc28500f
flightctl-observability-1.1.3-1.el10em.x86_64.rpm SHA-256: 7ba13d36a09492e64141586b891e01c22a82e252f01cbf9c6e4c93418936e184
flightctl-selinux-1.1.3-1.el10em.noarch.rpm SHA-256: 010a75cd1936cde6cff13b350e7cd02994dda62ec25a29d45ac2f360b977ca05
flightctl-services-1.1.3-1.el10em.x86_64.rpm SHA-256: a4152dd6302b46d0393b83cf6b2b6f681d6c6f2dc57cfa29748dddd521468865
s390x
flightctl-agent-1.1.3-1.el10em.s390x.rpm SHA-256: e17bccc9bf09a99548e67fca5bb13b4b49bc73496437d0fbd7d9de4303020bf0
flightctl-cli-1.1.3-1.el10em.s390x.rpm SHA-256: f5096606822655c7a6ddf268955e6d17c13a3ee753901563647326b9de197ad1
flightctl-observability-1.1.3-1.el10em.s390x.rpm SHA-256: b05af3ac767f46a6cbfeb878b622f59d1f411bf41c027bc4103baad2e4dd24a8
flightctl-selinux-1.1.3-1.el10em.noarch.rpm SHA-256: 010a75cd1936cde6cff13b350e7cd02994dda62ec25a29d45ac2f360b977ca05
flightctl-services-1.1.3-1.el10em.s390x.rpm SHA-256: 0a3a38f4af76557b4f6c907988d779f0b527264ed39ac190d94e26fae0422f0f
ppc64le
flightctl-agent-1.1.3-1.el10em.ppc64le.rpm SHA-256: 4e3babfa13cd7eb6d431ab3a0761efb5e61b01748ef641069ce6e1a226a24cf9
flightctl-cli-1.1.3-1.el10em.ppc64le.rpm SHA-256: b4de5ae76a47acea8bd90e8009af74d67d02b96e8ddf2e96bde65f399826327f
flightctl-observability-1.1.3-1.el10em.ppc64le.rpm SHA-256: 75db599b201782595d7e4d779040136c186a6e170dd360975a2a5ba9fb2aa540
flightctl-selinux-1.1.3-1.el10em.noarch.rpm SHA-256: 010a75cd1936cde6cff13b350e7cd02994dda62ec25a29d45ac2f360b977ca05
flightctl-services-1.1.3-1.el10em.ppc64le.rpm SHA-256: e9bf642a122303caa6078b28a8d296e4faa33e4469216eb92324b07690bfd977
aarch64
flightctl-agent-1.1.3-1.el10em.aarch64.rpm SHA-256: 378222ce51a65adb321f55cd9cedcb3d2a0150c5de65711b154e0440a792faef
flightctl-cli-1.1.3-1.el10em.aarch64.rpm SHA-256: 8085cf15a1e4bf97ad127cc4a97593c65c17827ad849728db35959c15f5bada3
flightctl-observability-1.1.3-1.el10em.aarch64.rpm SHA-256: e66ed5f11baebf230d54880b566bcb7256f79c2b52e06afc928cba2970f79a53
flightctl-selinux-1.1.3-1.el10em.noarch.rpm SHA-256: 010a75cd1936cde6cff13b350e7cd02994dda62ec25a29d45ac2f360b977ca05
flightctl-services-1.1.3-1.el10em.aarch64.rpm SHA-256: cedda9b7410a451e5d6ad62f89deee88854eb467ff8ea0fc38297e957e3d7120

Red Hat Edge Manager 1.1 for RHEL 9

SRPM
flightctl-1.1.3-1.el9em.src.rpm SHA-256: 34a92720125d2f706ab8101f293af75a82f0aebec7687d80178a9a60a3199e0b
x86_64
flightctl-agent-1.1.3-1.el9em.x86_64.rpm SHA-256: 76f978c679da2c01f866ef65c2e43dcc83f600e2391b81b97dcb5cb809003290
flightctl-cli-1.1.3-1.el9em.x86_64.rpm SHA-256: 75e4ac3d890a1e831992fa37f9f7428f627075cbf90ba092035a0e6ef01bb634
flightctl-observability-1.1.3-1.el9em.x86_64.rpm SHA-256: 980c984587cd6cf9a0ede18f779a12e019c8bea11689132d6a14999fc02bac72
flightctl-selinux-1.1.3-1.el9em.noarch.rpm SHA-256: 1ca878ba49df013279f0798c6926f7fe83e93c2a39bbc21400673dd87450eb81
flightctl-services-1.1.3-1.el9em.x86_64.rpm SHA-256: dc79bb5ce299b2a5027cfd668ca7f6b8d5f1e1d56af00b29e48ad537d8264129
s390x
flightctl-agent-1.1.3-1.el9em.s390x.rpm SHA-256: 34203a6e7143c269136207edc697dd40b005184367c6812d7dfc64bffc9671e1
flightctl-cli-1.1.3-1.el9em.s390x.rpm SHA-256: 21013d46fccf5da48e6858620431ae281cba78ee574ee4a6785e65a470283756
flightctl-observability-1.1.3-1.el9em.s390x.rpm SHA-256: efdc46b58914dcc7a83505234ac5c93ee36446b7a60a77fc98f5b0ee71b0a6b5
flightctl-selinux-1.1.3-1.el9em.noarch.rpm SHA-256: 1ca878ba49df013279f0798c6926f7fe83e93c2a39bbc21400673dd87450eb81
flightctl-services-1.1.3-1.el9em.s390x.rpm SHA-256: 679c1dbae31d1d92ebb5cf71d071726898a3d0b217cff8921d31cd4f909c3d8e
ppc64le
flightctl-agent-1.1.3-1.el9em.ppc64le.rpm SHA-256: 68cc7c993edc626510de775a0bd0c55dc8c016a2afd7ecb7047a37562afd907b
flightctl-cli-1.1.3-1.el9em.ppc64le.rpm SHA-256: 1ecb8d49479e87d3e0d90e604af8ba674877ea26658348d0a201e084018e1f7b
flightctl-observability-1.1.3-1.el9em.ppc64le.rpm SHA-256: 0d05434ceea2c927e9aee04b1fbd9e1d286e6133909c074dcc1350bed7dd2e7f
flightctl-selinux-1.1.3-1.el9em.noarch.rpm SHA-256: 1ca878ba49df013279f0798c6926f7fe83e93c2a39bbc21400673dd87450eb81
flightctl-services-1.1.3-1.el9em.ppc64le.rpm SHA-256: 6111dd53ea12f79a4d33fcb4cab11254e4d8a9ea76a5d2c8af92d34406d25f88
aarch64
flightctl-agent-1.1.3-1.el9em.aarch64.rpm SHA-256: 77fcb7d42f2483af385926eb99130e5b7f553a7fc0d53457c9a8b39000b7a875
flightctl-cli-1.1.3-1.el9em.aarch64.rpm SHA-256: dea8212e0a020e3c8e2b6e36d4f6497f1427db7b51599e99aa15ee64c860ec0d
flightctl-observability-1.1.3-1.el9em.aarch64.rpm SHA-256: 76e2809d9fd5f9bc96af0434ea790417c4c65d9d36ad10c4e4189fc2fba93eea
flightctl-selinux-1.1.3-1.el9em.noarch.rpm SHA-256: 1ca878ba49df013279f0798c6926f7fe83e93c2a39bbc21400673dd87450eb81
flightctl-services-1.1.3-1.el9em.aarch64.rpm SHA-256: c4f7b2451848990c2e3f201e1a8e72a62e4189fdb24c6f8e8cd4e055b59a225c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility