Skip to main content
EPSS 0.7%top 51%

Red Hat Security Advisory: container-tools:rhel8 security update

0
High
Published: 07/06/2026 (07/06/2026, 05:18:01 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
=1.41.8-3.el9_7=1.41.8-3.el9_7.src=1.41.8-3.el9_7.x86_64=1.41.8-3.el9_7.s390x=1.41.8-3.el9_7.ppc64le=1.41.8-3.el9_7.aarch64=1.41.8-3.el9_7.src.rpm=5.8.2-1.el9_8.src=1.43.1-1.el9_8.srcRed HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)srcbuildah-2:1.41.8-3.el9_7.srcmulticluster engine for Kubernetesmulticluster engine for Kubernetes 2.6amd64registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:d33bfbf1e1978964c03159d0b706b84befc89d3ca10ca096883d98fd422bea31_amd64podman-6:5.8.2-1.el9_8.srcbuildah-2:1.43.1-1.el9_8.srcRed Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.3registry.redhat.io/rhtas/rekor-monitor-rhel9@sha256:ee4e7f982a2087e2936326ac71dd2c7229e4b6f3ebd0600a2791421e123922be_amd64Red Hat Enterprise Linux AppStream E4S (v.9.4)x86_64osbuild-composer-0:101.3-4.el9_4.2.x86_64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:f41ad8cd68a90ea80b0f3d4e82eebd88a33737b0692d27a42650a4bdffc5f009_amd64Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:14d3506a84c56ce94db20e3ed1763deb9f72d0febc1a7bb2c8c8c6edfb30c9cd_amd64Red Hat Enterprise Linux AppStream (v. 8)aardvark-dns-2:1.10.1-2.module+el8.10.0+24482+e50f4e4f.src::container-tools:rhel8<0.48.1-r0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 00:27:52 UTC

Technical Analysis

The vulnerability CVE-2026-34986 affects the buildah package, which facilitates building OCI container images on Red Hat Enterprise Linux 9 and related platforms. The issue is a denial of service vulnerability in the Go JOSE library (versions 3 and 4) triggered by crafted JSON Web Encryption (JWE) objects. Red Hat has issued security advisories (RHSA-2026:10135 and RHSA-2026:17458) and released patched versions of buildah (1.41.8-3.el9_7) to remediate this vulnerability. The affected products include multiple Red Hat Enterprise Linux 9 variants and related container and Kubernetes management components. No active exploitation has been reported.

Potential Impact

Successful exploitation of this vulnerability could allow an attacker to cause a denial of service condition in the buildah tool by processing specially crafted JWE objects. This may disrupt container image building processes on affected systems. There are no reports of active exploitation in the wild. The vulnerability is rated as high severity by Red Hat Product Security.

Mitigation Recommendations

An official patch is available and has been released by Red Hat in buildah version 1.41.8-3.el9_7 and related packages. Users and administrators should apply the security updates provided by Red Hat as detailed in the advisories RHSA-2026:10135 and RHSA-2026:17458. No additional mitigation actions are specified or required beyond applying the official updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:10135
Cve Count
1

Threat ID: 6a16095ce29bf47b506253b8

Added to database: 05/26/2026, 20:58:04 UTC

Last enriched: 08/15/2026, 00:27:52 UTC

Last updated: 09/14/2026, 22:01:33 UTC

Views: 84

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:10135https://access.redhat.com/security/updates/classification/#important2455470Canonical URLhttps://access.redhat.com/errata/RHSA-2026:17458https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19173Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19186RHEL-95964Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24477https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexCanonical URLhttps://access.redhat.com/errata/RHSA-2026:25206Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27044https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-44496https://access.redhat.com/security/cve/CVE-2026-46579Canonical URLhttps://access.redhat.com/errata/RHSA-2026:32991Canonical URLhttps://access.redhat.com/errata/RHSA-2026:358332480681248068424806852480688Canonical URLReference 39Reference 40Reference 41Reference 42Reference 43Reference 44Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses