Skip to main content
EPSS 0.3%top 83%

Red Hat Security Advisory: General availability of the satellite/iop-host-inventory-rhel9 container image

0
High
Published: 06/16/2026 (06/16/2026, 09:06:21 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings. When you install Red Hat Lightspeed in Satellite locally, you can generate Red Hat Lightspeed recommendations without sending system data to Red Hat services.

Affected software

Affected versions
>=6.18 <=6.18Red HatRed Hat SatelliteRed Hat Satellite 6.18amd64registry.redhat.io/satellite/iop-host-inventory-rhel9@sha256:fe7bad4091d1e22b940b6f5cda351b4f0e92c0ff6107cf38041c5371ecef817a_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 19:40:54 UTC

Technical Analysis

Red Hat Satellite 6.18 includes Red Hat Lightspeed, which analyzes system health locally. A vulnerability identified as CVE-2026-28684 exists in the python-dotenv library, where the set_key() and unset_key() functions follow symbolic links when rewriting .env files. This behavior can be exploited by a local attacker to overwrite arbitrary files on the system, potentially impacting integrity and availability. The vulnerability is associated with CWE-59 (Improper Link Resolution Before File Access). Red Hat has not provided an official patch or fix that meets their criteria but has released the satellite/iop-host-inventory-rhel9 container image generally available. The advisory references multiple CVEs but focuses on this specific flaw. Red Hat scores this vulnerability as high severity with a CVSS base score of 7.1, emphasizing local attack vector, low complexity, and low privileges required. No known exploits are reported in the wild. The advisory includes links to Red Hat documentation and the container image registry.

Potential Impact

The vulnerability allows a local attacker to overwrite arbitrary files on the affected system by exploiting symbolic link following in python-dotenv's set_key() and unset_key() functions. This can lead to integrity and availability impacts, such as unauthorized modification of files and potential disruption of system operations. Confidentiality is not impacted. The flaw could also enable bypassing of security mechanisms if critical files are overwritten. The attack requires local access with low privileges and has low complexity. No remote exploitation or known active exploitation in the wild has been reported.

Mitigation Recommendations

Currently, no official fix or patch meeting Red Hat's criteria for ease of use, applicability, or stability is available. Users should follow Red Hat Satellite documentation to install and configure Red Hat Lightspeed locally to generate recommendations without sending system data externally. Customers are advised to monitor Red Hat advisories for future updates or fixes. If possible, restrict local access to trusted users to reduce risk. Customers with Red Hat Technical Account Managers (TAM) can consult them for tailored guidance. No additional mitigations are specified in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:26226
Cve Count
4
Additional Cves
["CVE-2026-32597","CVE-2026-44431","CVE-2026-48710"]
State
PUBLISHED

Threat ID: 6a32705a0b89be68881d41f1

Added to database: 06/17/2026, 10:00:58 UTC

Last enriched: 08/12/2026, 19:40:54 UTC

Last updated: 09/15/2026, 22:01:33 UTC

Views: 71

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses