Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 08/14/2026 (08/14/2026, 02:49:19 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has issued a security advisory (RHSA-2026:54836) addressing multiple vulnerabilities in Red Hat Hardened Images RPMs, specifically related to golang1.25 packages. Among the included CVEs is CVE-2026-56853, a high-severity flaw in the Go net/http library that can lead to Denial of Service (DoS) by allowing remote attackers to maintain open connections indefinitely due to improper application of ReadHeaderTimeout during HTTP/2 preface detection. The update provides bug fixes and enhancements for various golang1.25 RPMs across multiple architectures. No explicit patch versions are stated, but the advisory references updated package versions. No known exploits in the wild have been reported.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 01:11:18 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:54836) updates Red Hat Hardened Images RPMs, including golang1.25 packages, to address six CVEs, notably CVE-2026-56853. The CVE-2026-56853 vulnerability exists in the Go standard library's net/http component where the ReadHeaderTimeout is not properly enforced during unencrypted HTTP/2 connection preface detection. This flaw allows remote attackers to keep connections open indefinitely, potentially causing resource exhaustion and Denial of Service (DoS). The advisory lists updated golang1.25 RPMs (version 1.25.13-0.1.hum1) for aarch64 and x86_64 architectures. The advisory does not explicitly state fixed version ranges but provides updated package versions. No exploits in the wild are known. The CVSS score for CVE-2026-56853 is preliminarily rated 7.5 by Red Hat, indicating high severity. Other CVEs addressed are not detailed in this input. The advisory recommends applying the update from https://images.redhat.com/.

Potential Impact

The primary impact is a high-severity Denial of Service (DoS) vulnerability (CVE-2026-56853) in the Go net/http library that can be exploited remotely without authentication to exhaust server resources by maintaining open connections indefinitely. This can degrade or disrupt service availability. The advisory addresses multiple CVEs affecting Red Hat Hardened Images RPMs, which may impact systems using these golang1.25 packages. No known active exploitation has been reported.

Mitigation Recommendations

Red Hat has released updated golang1.25 RPM packages (version 1.25.13-0.1.hum1) that fix the vulnerabilities described in this advisory. Users should apply these updates to affected systems as soon as possible. Detailed update instructions and packages are available at https://images.redhat.com/. No alternative mitigations or workarounds are specified in the advisory. Since this is a packaged update, applying the official fix is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:54836
Cve Count
6
Additional Cves
["CVE-2026-56853","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862"]
Cvss Version
null

Threat ID: 6a825c60bf8831d539f21ebc

Added to database: 08/17/2026, 00:57:04 UTC

Last enriched: 08/17/2026, 01:11:18 UTC

Last updated: 08/17/2026, 02:41:00 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses