Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:54637 - Security Advisory
Issued:
2026-08-13
Updated:
2026-08-13

RHSA-2026:54637 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: yelp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for yelp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Yelp is the help browser for the GNOME desktop. It is designed to help you browse all the documentation on your system in one central tool, including traditional man pages, info pages and documentation written in DocBook.

Security Fix(es):

  • yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications (CVE-2026-13601)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x

Fixes

  • BZ - 2494110 - CVE-2026-13601 yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications

CVEs

  • CVE-2026-13601

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
x86_64
yelp-40.3-2.el9_2.2.x86_64.rpm SHA-256: b9254e1365c784edeca56f04728461390f9235eef677ee10e198320dc9b34486
yelp-debuginfo-40.3-2.el9_2.2.i686.rpm SHA-256: 90a61ca5109490b17af8a75d2ab47b674b2dc7b2d6a897a19018f51299dd74a4
yelp-debuginfo-40.3-2.el9_2.2.x86_64.rpm SHA-256: 1ce73fbf95fd97e6f3d58d16af6e37801895752e32a4b04640748fc6ee2ddfe9
yelp-debugsource-40.3-2.el9_2.2.i686.rpm SHA-256: 0c01c416fbc6eaf0438d0d8c5aad9f2d90ac6fb6d3b9fee23bc4223911c8c9eb
yelp-debugsource-40.3-2.el9_2.2.x86_64.rpm SHA-256: 7a3be431bba32421ae301756af1411b396646a74c3cff2604b89048ef874a336
yelp-libs-40.3-2.el9_2.2.i686.rpm SHA-256: 63193792762cf0a1a8b002e7e6efefd24b301079d14f6f58c280704083093484
yelp-libs-40.3-2.el9_2.2.x86_64.rpm SHA-256: 0d84ecd1974260d07e811e386ed9946a061ee910dc426c8d0d2b63c0c9528e50
yelp-libs-debuginfo-40.3-2.el9_2.2.i686.rpm SHA-256: 57e07ad1751f9e433ed636d17fa611a81a94be0a2e12aae208ac2ac6b5649554
yelp-libs-debuginfo-40.3-2.el9_2.2.x86_64.rpm SHA-256: c1646c636ff5e6261601bb0e438c0920faf9a1e4ded034f01e36ceea0ecbcd9a

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
ppc64le
yelp-40.3-2.el9_2.2.ppc64le.rpm SHA-256: 01c52b987dc37ffa7003b83389c9f25e79ffb3d908239b63c935755e0ac6093f
yelp-debuginfo-40.3-2.el9_2.2.ppc64le.rpm SHA-256: b26e93aaf1fff116bd78771d5e6363ce273b0379eb1c8865f516b6e4c4909fe2
yelp-debugsource-40.3-2.el9_2.2.ppc64le.rpm SHA-256: bbbb3e6d838da222c526d936c87ed7f2822d2a3ca22454e4556bf65445b51037
yelp-libs-40.3-2.el9_2.2.ppc64le.rpm SHA-256: 9444bbfca2638dc919d05b99bc8083421a77316d2f638eae0d8952a2e7ca692c
yelp-libs-debuginfo-40.3-2.el9_2.2.ppc64le.rpm SHA-256: bf726583998ccae5322a83d4a6050531a540e113ecbda4382aeebc45a422ab70

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
x86_64
yelp-40.3-2.el9_2.2.x86_64.rpm SHA-256: b9254e1365c784edeca56f04728461390f9235eef677ee10e198320dc9b34486
yelp-debuginfo-40.3-2.el9_2.2.i686.rpm SHA-256: 90a61ca5109490b17af8a75d2ab47b674b2dc7b2d6a897a19018f51299dd74a4
yelp-debuginfo-40.3-2.el9_2.2.x86_64.rpm SHA-256: 1ce73fbf95fd97e6f3d58d16af6e37801895752e32a4b04640748fc6ee2ddfe9
yelp-debugsource-40.3-2.el9_2.2.i686.rpm SHA-256: 0c01c416fbc6eaf0438d0d8c5aad9f2d90ac6fb6d3b9fee23bc4223911c8c9eb
yelp-debugsource-40.3-2.el9_2.2.x86_64.rpm SHA-256: 7a3be431bba32421ae301756af1411b396646a74c3cff2604b89048ef874a336
yelp-libs-40.3-2.el9_2.2.i686.rpm SHA-256: 63193792762cf0a1a8b002e7e6efefd24b301079d14f6f58c280704083093484
yelp-libs-40.3-2.el9_2.2.x86_64.rpm SHA-256: 0d84ecd1974260d07e811e386ed9946a061ee910dc426c8d0d2b63c0c9528e50
yelp-libs-debuginfo-40.3-2.el9_2.2.i686.rpm SHA-256: 57e07ad1751f9e433ed636d17fa611a81a94be0a2e12aae208ac2ac6b5649554
yelp-libs-debuginfo-40.3-2.el9_2.2.x86_64.rpm SHA-256: c1646c636ff5e6261601bb0e438c0920faf9a1e4ded034f01e36ceea0ecbcd9a

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
aarch64
yelp-40.3-2.el9_2.2.aarch64.rpm SHA-256: 5e965f173d9eb3e3a74a7e43dccf8a279a2fea67a433a8adbea5fe001c644400
yelp-debuginfo-40.3-2.el9_2.2.aarch64.rpm SHA-256: e9188b5f769765cd49fec32c78208cae3173b79a8db7e5117d8f21a481678ef9
yelp-debugsource-40.3-2.el9_2.2.aarch64.rpm SHA-256: 9664701c0f76d614fecd378085cca0ea6983432abe1f38b053b5eec66e426341
yelp-libs-40.3-2.el9_2.2.aarch64.rpm SHA-256: da309d95f769c2ed61b15a1eba886e13bf05a5d57881c2ac78e7aedbcbe5d388
yelp-libs-debuginfo-40.3-2.el9_2.2.aarch64.rpm SHA-256: 26a23bf046f0992e8c6f2d007bd4e580d0a2590500a30d7d3b02948345a67764

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
s390x
yelp-40.3-2.el9_2.2.s390x.rpm SHA-256: 2071fd55733865fe33f2f584d86e287ef4b4b460d82ab24be913e0bee0264d7d
yelp-debuginfo-40.3-2.el9_2.2.s390x.rpm SHA-256: 39c7becfd6579e90376a8c863c7a7bd8a2a7e93d8705c95dec107b6520c4d866
yelp-debugsource-40.3-2.el9_2.2.s390x.rpm SHA-256: dcd8e6fc04b1788604eaec56f422daeef67a809b917b6e7ffb5d2b9f65f7e8a9
yelp-libs-40.3-2.el9_2.2.s390x.rpm SHA-256: b26bb8e5a4bd568c1460198b0fcd3e4c2ef32f810e3ed072061e0ea2b96b4571
yelp-libs-debuginfo-40.3-2.el9_2.2.s390x.rpm SHA-256: 8108c248235f966ae7c40b5a22adee3014ae8c1f240374fba1b0ff1fa055b442

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
x86_64
yelp-40.3-2.el9_2.2.x86_64.rpm SHA-256: b9254e1365c784edeca56f04728461390f9235eef677ee10e198320dc9b34486
yelp-debuginfo-40.3-2.el9_2.2.i686.rpm SHA-256: 90a61ca5109490b17af8a75d2ab47b674b2dc7b2d6a897a19018f51299dd74a4
yelp-debuginfo-40.3-2.el9_2.2.x86_64.rpm SHA-256: 1ce73fbf95fd97e6f3d58d16af6e37801895752e32a4b04640748fc6ee2ddfe9
yelp-debugsource-40.3-2.el9_2.2.i686.rpm SHA-256: 0c01c416fbc6eaf0438d0d8c5aad9f2d90ac6fb6d3b9fee23bc4223911c8c9eb
yelp-debugsource-40.3-2.el9_2.2.x86_64.rpm SHA-256: 7a3be431bba32421ae301756af1411b396646a74c3cff2604b89048ef874a336
yelp-libs-40.3-2.el9_2.2.i686.rpm SHA-256: 63193792762cf0a1a8b002e7e6efefd24b301079d14f6f58c280704083093484
yelp-libs-40.3-2.el9_2.2.x86_64.rpm SHA-256: 0d84ecd1974260d07e811e386ed9946a061ee910dc426c8d0d2b63c0c9528e50
yelp-libs-debuginfo-40.3-2.el9_2.2.i686.rpm SHA-256: 57e07ad1751f9e433ed636d17fa611a81a94be0a2e12aae208ac2ac6b5649554
yelp-libs-debuginfo-40.3-2.el9_2.2.x86_64.rpm SHA-256: c1646c636ff5e6261601bb0e438c0920faf9a1e4ded034f01e36ceea0ecbcd9a

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
aarch64
yelp-40.3-2.el9_2.2.aarch64.rpm SHA-256: 5e965f173d9eb3e3a74a7e43dccf8a279a2fea67a433a8adbea5fe001c644400
yelp-debuginfo-40.3-2.el9_2.2.aarch64.rpm SHA-256: e9188b5f769765cd49fec32c78208cae3173b79a8db7e5117d8f21a481678ef9
yelp-debugsource-40.3-2.el9_2.2.aarch64.rpm SHA-256: 9664701c0f76d614fecd378085cca0ea6983432abe1f38b053b5eec66e426341
yelp-libs-40.3-2.el9_2.2.aarch64.rpm SHA-256: da309d95f769c2ed61b15a1eba886e13bf05a5d57881c2ac78e7aedbcbe5d388
yelp-libs-debuginfo-40.3-2.el9_2.2.aarch64.rpm SHA-256: 26a23bf046f0992e8c6f2d007bd4e580d0a2590500a30d7d3b02948345a67764

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
ppc64le
yelp-40.3-2.el9_2.2.ppc64le.rpm SHA-256: 01c52b987dc37ffa7003b83389c9f25e79ffb3d908239b63c935755e0ac6093f
yelp-debuginfo-40.3-2.el9_2.2.ppc64le.rpm SHA-256: b26e93aaf1fff116bd78771d5e6363ce273b0379eb1c8865f516b6e4c4909fe2
yelp-debugsource-40.3-2.el9_2.2.ppc64le.rpm SHA-256: bbbb3e6d838da222c526d936c87ed7f2822d2a3ca22454e4556bf65445b51037
yelp-libs-40.3-2.el9_2.2.ppc64le.rpm SHA-256: 9444bbfca2638dc919d05b99bc8083421a77316d2f638eae0d8952a2e7ca692c
yelp-libs-debuginfo-40.3-2.el9_2.2.ppc64le.rpm SHA-256: bf726583998ccae5322a83d4a6050531a540e113ecbda4382aeebc45a422ab70

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2

SRPM
yelp-40.3-2.el9_2.2.src.rpm SHA-256: ab1da0bc062d013e4d10c89f8d198ba1c1ec7dd97ceb8224155ffab499969449
s390x
yelp-40.3-2.el9_2.2.s390x.rpm SHA-256: 2071fd55733865fe33f2f584d86e287ef4b4b460d82ab24be913e0bee0264d7d
yelp-debuginfo-40.3-2.el9_2.2.s390x.rpm SHA-256: 39c7becfd6579e90376a8c863c7a7bd8a2a7e93d8705c95dec107b6520c4d866
yelp-debugsource-40.3-2.el9_2.2.s390x.rpm SHA-256: dcd8e6fc04b1788604eaec56f422daeef67a809b917b6e7ffb5d2b9f65f7e8a9
yelp-libs-40.3-2.el9_2.2.s390x.rpm SHA-256: b26bb8e5a4bd568c1460198b0fcd3e4c2ef32f810e3ed072061e0ea2b96b4571
yelp-libs-debuginfo-40.3-2.el9_2.2.s390x.rpm SHA-256: 8108c248235f966ae7c40b5a22adee3014ae8c1f240374fba1b0ff1fa055b442

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility