Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat has issued a security advisory (RHSA-2026:54836) addressing multiple vulnerabilities in Red Hat Hardened Images RPMs, specifically related to golang1.25 packages. Among the included CVEs is CVE-2026-56853, a high-severity flaw in the Go net/http library that can lead to Denial of Service (DoS) by allowing remote attackers to maintain open connections indefinitely due to improper application of ReadHeaderTimeout during HTTP/2 preface detection. The update provides bug fixes and enhancements for various golang1.25 RPMs across multiple architectures. No explicit patch versions are stated, but the advisory references updated package versions. No known exploits in the wild have been reported.
AI Analysis
Technical Summary
This Red Hat security advisory (RHSA-2026:54836) updates Red Hat Hardened Images RPMs, including golang1.25 packages, to address six CVEs, notably CVE-2026-56853. The CVE-2026-56853 vulnerability exists in the Go standard library's net/http component where the ReadHeaderTimeout is not properly enforced during unencrypted HTTP/2 connection preface detection. This flaw allows remote attackers to keep connections open indefinitely, potentially causing resource exhaustion and Denial of Service (DoS). The advisory lists updated golang1.25 RPMs (version 1.25.13-0.1.hum1) for aarch64 and x86_64 architectures. The advisory does not explicitly state fixed version ranges but provides updated package versions. No exploits in the wild are known. The CVSS score for CVE-2026-56853 is preliminarily rated 7.5 by Red Hat, indicating high severity. Other CVEs addressed are not detailed in this input. The advisory recommends applying the update from https://images.redhat.com/.
Potential Impact
The primary impact is a high-severity Denial of Service (DoS) vulnerability (CVE-2026-56853) in the Go net/http library that can be exploited remotely without authentication to exhaust server resources by maintaining open connections indefinitely. This can degrade or disrupt service availability. The advisory addresses multiple CVEs affecting Red Hat Hardened Images RPMs, which may impact systems using these golang1.25 packages. No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released updated golang1.25 RPM packages (version 1.25.13-0.1.hum1) that fix the vulnerabilities described in this advisory. Users should apply these updates to affected systems as soon as possible. Detailed update instructions and packages are available at https://images.redhat.com/. No alternative mitigations or workarounds are specified in the advisory. Since this is a packaged update, applying the official fix is the recommended remediation.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
Red Hat has issued a security advisory (RHSA-2026:54836) addressing multiple vulnerabilities in Red Hat Hardened Images RPMs, specifically related to golang1.25 packages. Among the included CVEs is CVE-2026-56853, a high-severity flaw in the Go net/http library that can lead to Denial of Service (DoS) by allowing remote attackers to maintain open connections indefinitely due to improper application of ReadHeaderTimeout during HTTP/2 preface detection. The update provides bug fixes and enhancements for various golang1.25 RPMs across multiple architectures. No explicit patch versions are stated, but the advisory references updated package versions. No known exploits in the wild have been reported.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory (RHSA-2026:54836) updates Red Hat Hardened Images RPMs, including golang1.25 packages, to address six CVEs, notably CVE-2026-56853. The CVE-2026-56853 vulnerability exists in the Go standard library's net/http component where the ReadHeaderTimeout is not properly enforced during unencrypted HTTP/2 connection preface detection. This flaw allows remote attackers to keep connections open indefinitely, potentially causing resource exhaustion and Denial of Service (DoS). The advisory lists updated golang1.25 RPMs (version 1.25.13-0.1.hum1) for aarch64 and x86_64 architectures. The advisory does not explicitly state fixed version ranges but provides updated package versions. No exploits in the wild are known. The CVSS score for CVE-2026-56853 is preliminarily rated 7.5 by Red Hat, indicating high severity. Other CVEs addressed are not detailed in this input. The advisory recommends applying the update from https://images.redhat.com/.
Potential Impact
The primary impact is a high-severity Denial of Service (DoS) vulnerability (CVE-2026-56853) in the Go net/http library that can be exploited remotely without authentication to exhaust server resources by maintaining open connections indefinitely. This can degrade or disrupt service availability. The advisory addresses multiple CVEs affecting Red Hat Hardened Images RPMs, which may impact systems using these golang1.25 packages. No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released updated golang1.25 RPM packages (version 1.25.13-0.1.hum1) that fix the vulnerabilities described in this advisory. Users should apply these updates to affected systems as soon as possible. Detailed update instructions and packages are available at https://images.redhat.com/. No alternative mitigations or workarounds are specified in the advisory. Since this is a packaged update, applying the official fix is the recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:54836
- Cve Count
- 6
- Additional Cves
- ["CVE-2026-56853","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862"]
- Cvss Version
- null
Threat ID: 6a825c60bf8831d539f21ebc
Added to database: 08/17/2026, 00:57:04 UTC
Last enriched: 08/17/2026, 01:11:18 UTC
Last updated: 08/17/2026, 02:41:00 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.