Skip to main content
EPSS 0.8%top 45%

Red Hat Security Advisory: Technical preview of the satellite/iop-vmaas-rhel9 container image

0
Critical
Published: 09/17/2026 (09/17/2026, 20:30:11 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings.

Affected software

Bitnamimore threats →ghsa
golang
pkg:bitnami/golang
Affected versions
<1.25.10>=1.26.0-0 <1.26.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 16:15:20 UTC

Technical Analysis

The vulnerability identified as CVE-2026-39820 affects the Go net/mail package utilized in Red Hat build of MicroShift 4.19. This flaw enables denial of service attacks through specially crafted email inputs. Red Hat has issued security updates in MicroShift 4.19.43 RPM packages and container images to remediate this issue. The advisory references Red Hat OpenShift Container Platform 4.19 for RHEL 9 across multiple architectures as affected products. The fix is available and users should update to the patched versions to resolve the vulnerability.

Potential Impact

The vulnerability allows an attacker to cause a denial of service condition by sending crafted email inputs to the affected Go net/mail component within Red Hat build of MicroShift. This could disrupt the normal operation of MicroShift clusters deployed on edge devices, potentially impacting availability.

Mitigation Recommendations

A patch is available and has been released by Red Hat in MicroShift 4.19.43 RPM packages and container images. Users should apply these updates as per Red Hat's official guidance to fully remediate the vulnerability. No additional mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:54883
Cve Count
1
State
PUBLISHED

Threat ID: 6a870a76acd9273b49b58b0e

Added to database: 08/20/2026, 14:08:54 UTC

Last enriched: 09/30/2026, 16:15:20 UTC

Last updated: 10/05/2026, 06:48:16 UTC

Views: 74

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:54883https://access.redhat.com/security/updates/classification/#important2467820Canonical URLReference 5Reference 6Reference 7Reference 8Reference 9Reference 10Reference 11Reference 12Reference 13Reference 14Reference 15Reference 16Reference 17Reference 18Reference 19Reference 20Reference 21Reference 22Reference 23Reference 24Reference 25Reference 26Reference 27Reference 28Reference 29Reference 30Reference 31Reference 32Reference 33Reference 34Reference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47Reference 48Reference 49Reference 50Reference 51https://access.redhat.com/errata/RHSA-2026:579142467809Canonical URLReference 55Reference 56Reference 57Reference 58Reference 59Reference 60Reference 61Reference 62Reference 63https://access.redhat.com/errata/RHSA-2026:57401Canonical URLReference 66Reference 67Reference 68Reference 69Reference 70Reference 71Reference 72Reference 73Reference 74CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring SystemReference 78Reference 79Reference 80Reference 81Reference 82Reference 83Reference 84Reference 85Reference 86Reference 87Reference 88Reference 89Reference 90Reference 91Reference 92Reference 93Reference 94Reference 95Reference 96https://access.redhat.com/errata/RHSA-2026:68764https://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/indexhttps://access.redhat.com/security/cve/CVE-2026-42215https://access.redhat.com/security/cve/CVE-2026-42284https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-44244https://access.redhat.com/security/cve/CVE-2026-54876https://access.redhat.com/security/cve/CVE-2026-56852https://access.redhat.com/security/cve/CVE-2026-56853https://access.redhat.com/security/cve/CVE-2026-56859https://access.redhat.com/security/cve/CVE-2026-73620https://access.redhat.com/security/cve/CVE-2026-73622https://access.redhat.com/security/cve/CVE-2026-73623https://access.redhat.com/security/cve/CVE-2026-73624https://access.redhat.com/security/cve/CVE-2026-73625https://access.redhat.com/security/cve/CVE-2026-76218https://access.redhat.com/security/cve/CVE-2026-76219https://access.redhat.com/security/cve/CVE-2026-76220https://access.redhat.com/security/cve/CVE-2026-76221Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses