Red Hat Security Advisory: container-tools:rhel8 security update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
CVE-2026-33811 is a denial of service vulnerability in the Go net package's LookupCNAME function, triggered by processing a long CNAME DNS response. This can cause excessive CPU or resource consumption, impacting availability of systems using the rhc client tool and daemon that connects to Red Hat hosted services. The issue is addressed in updated golang1.26 packages released by Red Hat as part of their Hardened Images RPM update. The advisory also references related DoS vulnerabilities in the golang MIME package (CVE-2026-42504) and others. Red Hat's advisory provides updated golang1.26-1.26.4-2.hum1 packages for multiple architectures to remediate these issues.
Potential Impact
Successful exploitation of CVE-2026-33811 can cause denial of service by exhausting CPU or other platform resources when processing maliciously crafted DNS CNAME responses. This impacts service availability of affected systems using the vulnerable Go net package. The vulnerability affects Red Hat Hardened Images and related products that include golang1.26. No known active exploits have been reported, but the impact is rated high due to potential service disruption.
Mitigation Recommendations
Red Hat has released updated golang1.26 packages (version 1.26.4-2.hum1) that fix this vulnerability. Users should apply these official updates to affected products as soon as possible. For systems unable to immediately update, restricting network access to services processing DNS or MIME data from untrusted sources can reduce exposure. Input validation and sanitization are recommended to mitigate malformed data processing. The vendor advisory does not indicate any temporary fixes or workarounds beyond patching.
Red Hat Security Advisory: container-tools:rhel8 security update
Description
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-33811 is a denial of service vulnerability in the Go net package's LookupCNAME function, triggered by processing a long CNAME DNS response. This can cause excessive CPU or resource consumption, impacting availability of systems using the rhc client tool and daemon that connects to Red Hat hosted services. The issue is addressed in updated golang1.26 packages released by Red Hat as part of their Hardened Images RPM update. The advisory also references related DoS vulnerabilities in the golang MIME package (CVE-2026-42504) and others. Red Hat's advisory provides updated golang1.26-1.26.4-2.hum1 packages for multiple architectures to remediate these issues.
Potential Impact
Successful exploitation of CVE-2026-33811 can cause denial of service by exhausting CPU or other platform resources when processing maliciously crafted DNS CNAME responses. This impacts service availability of affected systems using the vulnerable Go net package. The vulnerability affects Red Hat Hardened Images and related products that include golang1.26. No known active exploits have been reported, but the impact is rated high due to potential service disruption.
Mitigation Recommendations
Red Hat has released updated golang1.26 packages (version 1.26.4-2.hum1) that fix this vulnerability. Users should apply these official updates to affected products as soon as possible. For systems unable to immediately update, restricting network access to services processing DNS or MIME data from untrusted sources can reduce exposure. Input validation and sanitization are recommended to mitigate malformed data processing. The vendor advisory does not indicate any temporary fixes or workarounds beyond patching.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:23264
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-39826"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a294f758dd33fbd853d3b9a
Added to database: 06/10/2026, 11:50:13 UTC
Last enriched: 08/14/2026, 23:41:42 UTC
Last updated: 09/13/2026, 22:01:33 UTC
Views: 3101
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.