Skip to main content
EPSS 1.4%top 29%

Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update

0
High
Published: 03/18/2026 (03/18/2026, 16:24:32 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version.

Affected software

Affected versions
>=5.1Red HatRed Hat Update InfrastructureRed Hat Update Infrastructure 5amd64registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64Red Hat Insights proxyRed Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab86ba36e62e8aec5ba48e9e0076b1f8086c48157c85990be0e2ce3e03273016_amd64Red Hat Hardened Imagesaarch64curl-main@aarch64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v.9.4)Red Hat Enterprise Linux BaseOS EUS (v.9.4)Red Hat Enterprise Linux AppStream EUS (v.9.6)Red Hat Enterprise Linux BaseOS EUS (v.9.6)Red Hat Enterprise Linux AppStream E4S (v.9.0)Red Hat Enterprise Linux BaseOS E4S (v.9.0)src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 20:03:43 UTC

Technical Analysis

This advisory covers a security update for Red Hat Update Infrastructure (RHUI) 5.1 container images, which are based on the latest RHUI RPM packages and ubi9 or ubi9-init base images. Among the addressed vulnerabilities is CVE-2025-11187, a flaw in OpenSSL versions 3.4, 3.5, and 3.6 where improper validation of PBMAC1 parameters in PKCS#12 MAC verification can cause a stack buffer overflow or NULL pointer dereference. This vulnerability can lead to denial of service or, in some cases, arbitrary code execution if an application processes a maliciously crafted PKCS#12 file. The advisory notes that exploitation requires processing untrusted PKCS#12 files, which is uncommon. The update includes multiple CVEs but does not explicitly list individual fixes. The updated container images should be deployed using the rhui-installer utility according to Red Hat's official documentation.

Potential Impact

The impact includes potential denial of service and possible arbitrary code execution due to vulnerabilities in OpenSSL and other components included in RHUI container images. The CVE-2025-11187 vulnerability specifically can cause application crashes or code execution when processing malicious PKCS#12 files. However, exploitation requires local processing of crafted files, which are typically trusted and not commonly untrusted. No known exploits in the wild have been reported. The update mitigates these risks by providing updated container images with the latest security patches.

Mitigation Recommendations

Deploy the updated Red Hat Update Infrastructure 5.1 container images provided by this release using the rhui-installer utility as described in the official Red Hat documentation. Avoid processing untrusted PKCS#12 files to mitigate the OpenSSL vulnerability CVE-2025-11187. Since this is a container image update, applying the updated images replaces vulnerable components. No additional immediate actions are specified in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:4943
Cve Count
32
Additional Cves
["CVE-2025-9820","CVE-2025-11187","CVE-2025-12084","CVE-2025-13836","CVE-2025-14104","CVE-2025-14831","CVE-2025-15281","CVE-2025-15366","CVE-2025-15367","CVE-2025-15467","CVE-2025-15468","CVE-2025-15469","CVE-2025-61726","CVE-2025-66199","CVE-2025-68160","CVE-2025-69418","CVE-2025-69419","CVE-2025-69420","CVE-2025-69421","CVE-2026-0861","CVE-2026-0865","CVE-2026-0915","CVE-2026-1299","CVE-2026-1642","CVE-2026-2003","CVE-2026-2004","CVE-2026-2005","CVE-2026-2006","CVE-2026-22795","CVE-2026-22796","CVE-2026-23490"]

Threat ID: 6a160964e29bf47b50629671

Added to database: 05/26/2026, 20:58:12 UTC

Last enriched: 08/14/2026, 20:03:43 UTC

Last updated: 09/13/2026, 00:47:04 UTC

Views: 132

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:4943https://access.redhat.com/products/red-hat-update-infrastructurehttps://access.redhat.com/security/cve/CVE-2025-11187https://access.redhat.com/security/cve/CVE-2025-12084https://access.redhat.com/security/cve/CVE-2025-13836https://access.redhat.com/security/cve/CVE-2025-14104https://access.redhat.com/security/cve/CVE-2025-14831https://access.redhat.com/security/cve/CVE-2025-15281https://access.redhat.com/security/cve/CVE-2025-15366https://access.redhat.com/security/cve/CVE-2025-15367https://access.redhat.com/security/cve/CVE-2025-15467https://access.redhat.com/security/cve/CVE-2025-15468https://access.redhat.com/security/cve/CVE-2025-15469https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2025-66199https://access.redhat.com/security/cve/CVE-2025-68160https://access.redhat.com/security/cve/CVE-2025-69418https://access.redhat.com/security/cve/CVE-2025-69419https://access.redhat.com/security/cve/CVE-2025-69420https://access.redhat.com/security/cve/CVE-2025-69421https://access.redhat.com/errata/RHSA-2026:6893https://images.redhat.com/https://access.redhat.com/security/cve/CVE-2025-9086https://access.redhat.com/security/updates/classification/https://access.redhat.com/security/cve/CVE-2025-10148https://access.redhat.com/security/cve/CVE-2025-10966https://access.redhat.com/security/cve/CVE-2025-15224https://access.redhat.com/security/cve/CVE-2025-15079https://access.redhat.com/security/cve/CVE-2025-14819https://access.redhat.com/security/cve/CVE-2025-14524https://access.redhat.com/security/cve/CVE-2025-13034https://access.redhat.com/security/cve/CVE-2026-3805https://access.redhat.com/security/cve/CVE-2026-3783https://access.redhat.com/security/cve/CVE-2026-3784https://access.redhat.com/security/cve/CVE-2026-1965https://access.redhat.com/security/cve/CVE-2025-14017Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2485https://access.redhat.com/security/cve/CVE-2025-13601https://access.redhat.com/security/cve/CVE-2025-68973https://access.redhat.com/security/cve/CVE-2026-22795https://access.redhat.com/security/cve/CVE-2026-22796Canonical URLhttps://access.redhat.com/errata/RHSA-2025:23125https://access.redhat.com/security/updates/classification/#moderate2394750Canonical URLhttps://access.redhat.com/errata/RHSA-2025:23043Canonical URLhttps://access.redhat.com/errata/RHSA-2025:23126Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses