Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:42082 - Security Advisory
Issued:
2026-07-20
Updated:
2026-07-20

RHSA-2026:42082 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Satellite 6.16.11 Async Update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat Satellite 6.16 for RHEL 8 and RHEL 9.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

  • yggdrasil-worker-forwarder: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)
  • yggdrasil-worker-forwarder: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  • yggdrasil-worker-forwarder: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  • python-pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701)

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Satellite Extended Update Support 6.16 for RHEL 9 x86_64
  • Red Hat Satellite Extended Update Support 6.16 for RHEL 8 x86_64
  • Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 9 x86_64
  • Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 8 x86_64

Fixes

  • BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
  • BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
  • BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
  • BZ - 2490703 - CVE-2026-12701 pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport

CVEs

  • CVE-2026-12701
  • CVE-2026-27145
  • CVE-2026-33811
  • CVE-2026-39821

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
satellite-6.16.11-1.el9sat.src.rpm SHA-256: 03fd577a020a131ca24b6cfc0fa71a61ea9759b2c0d07e43025b7a67a668b347
x86_64
satellite-cli-6.16.11-1.el9sat.noarch.rpm SHA-256: 3073f32445847be2986b13585dad4edfae4cb14b6827ea934ba02c8b5a9eac56

Red Hat Enterprise Linux for x86_64 8

SRPM
satellite-6.16.11-1.el8sat.src.rpm SHA-256: 241f2c06b5cbad8aa87dfbdff62bd3d095c09ec652a10a80114f8b9a9b57f27d
x86_64
satellite-cli-6.16.11-1.el8sat.noarch.rpm SHA-256: 3dffebd45b3aaa63fe8daf8446626ca43a8990334e90bacb7d2993959c38d58c

Red Hat Satellite Extended Update Support 6.16 for RHEL 9

SRPM
python-pulpcore-3.49.39-2.el9pc.src.rpm SHA-256: 792184c358dc5825d3bf65fe0b5ddbf8a6633be301eeb68ff6705cae7ecd0ea1
satellite-6.16.11-1.el9sat.src.rpm SHA-256: 03fd577a020a131ca24b6cfc0fa71a61ea9759b2c0d07e43025b7a67a668b347
yggdrasil-worker-forwarder-0.0.4-1.el9sat.src.rpm SHA-256: 387ba25ee571ab79cedbe84491b639b0b98ffee8afeee5345159fba35dff0567
x86_64
python3.11-pulpcore-3.49.39-2.el9pc.noarch.rpm SHA-256: 1eda8e1ec69e618533413e4f81f7dfdab807374e1d86f8266520fb563095882b
satellite-6.16.11-1.el9sat.noarch.rpm SHA-256: 281f6ce67f6314dffbfc337894785dd76dd50d3aa3db476b10715e2ef0e66f8c
satellite-cli-6.16.11-1.el9sat.noarch.rpm SHA-256: 3073f32445847be2986b13585dad4edfae4cb14b6827ea934ba02c8b5a9eac56
satellite-common-6.16.11-1.el9sat.noarch.rpm SHA-256: f65dbdf2010da5213f828fce1d08f5575631b88b6385e729e9d39a55ba1aae6d
yggdrasil-worker-forwarder-0.0.4-1.el9sat.x86_64.rpm SHA-256: 85f1a904da0474f9c0a22fcc78ca237be1fece967d10f0ca86ba1487b9244daf

Red Hat Satellite Extended Update Support 6.16 for RHEL 8

SRPM
python-pulpcore-3.49.39-2.el8pc.src.rpm SHA-256: 19003e1a515a2413227791af0886d26153119a7cd9824db66b94445ce5ed9519
satellite-6.16.11-1.el8sat.src.rpm SHA-256: 241f2c06b5cbad8aa87dfbdff62bd3d095c09ec652a10a80114f8b9a9b57f27d
yggdrasil-worker-forwarder-0.0.4-1.el8sat.src.rpm SHA-256: 6828d064d6a3fe21fce3b364608665a266706270819e523f6e055d455143797f
x86_64
python3.11-pulpcore-3.49.39-2.el8pc.noarch.rpm SHA-256: 71191c8d6550d8ce3cf022f24f12eadd4d4ea13fc9d50c8ce74e2d7cedf524d7
satellite-6.16.11-1.el8sat.noarch.rpm SHA-256: 4efaa0baac415b196c82aae798d29d0a83e8eaef4d4311bc774606e1fac5484b
satellite-cli-6.16.11-1.el8sat.noarch.rpm SHA-256: 3dffebd45b3aaa63fe8daf8446626ca43a8990334e90bacb7d2993959c38d58c
satellite-common-6.16.11-1.el8sat.noarch.rpm SHA-256: 5c054be690a0aef37ef2080471fd1f42b3b0e63d28a69e4d56c140598ca56e90
yggdrasil-worker-forwarder-0.0.4-1.el8sat.x86_64.rpm SHA-256: b6ec16f8db3671358559dfa48cc91a3dae7012024964082a2c87b4fca01c82f4

Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 9

SRPM
python-pulpcore-3.49.39-2.el9pc.src.rpm SHA-256: 792184c358dc5825d3bf65fe0b5ddbf8a6633be301eeb68ff6705cae7ecd0ea1
satellite-6.16.11-1.el9sat.src.rpm SHA-256: 03fd577a020a131ca24b6cfc0fa71a61ea9759b2c0d07e43025b7a67a668b347
x86_64
python3.11-pulpcore-3.49.39-2.el9pc.noarch.rpm SHA-256: 1eda8e1ec69e618533413e4f81f7dfdab807374e1d86f8266520fb563095882b
satellite-capsule-6.16.11-1.el9sat.noarch.rpm SHA-256: cf8f1cee8ec0f1cce086ed603596490b29f0eaa4a5d7552f228f50558e873567
satellite-common-6.16.11-1.el9sat.noarch.rpm SHA-256: f65dbdf2010da5213f828fce1d08f5575631b88b6385e729e9d39a55ba1aae6d

Red Hat Satellite Capsule Extended Update Support 6.16 for RHEL 8

SRPM
python-pulpcore-3.49.39-2.el8pc.src.rpm SHA-256: 19003e1a515a2413227791af0886d26153119a7cd9824db66b94445ce5ed9519
satellite-6.16.11-1.el8sat.src.rpm SHA-256: 241f2c06b5cbad8aa87dfbdff62bd3d095c09ec652a10a80114f8b9a9b57f27d
x86_64
python3.11-pulpcore-3.49.39-2.el8pc.noarch.rpm SHA-256: 71191c8d6550d8ce3cf022f24f12eadd4d4ea13fc9d50c8ce74e2d7cedf524d7
satellite-capsule-6.16.11-1.el8sat.noarch.rpm SHA-256: 252921d3a2db98bfbfa9d9aa44deb156699392c6cc18c6d5eb3f1491aa5c24bf
satellite-common-6.16.11-1.el8sat.noarch.rpm SHA-256: 5c054be690a0aef37ef2080471fd1f42b3b0e63d28a69e4d56c140598ca56e90

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility