Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update
Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version.
AI Analysis
Technical Summary
This advisory covers a security update for Red Hat Update Infrastructure (RHUI) 5.1 container images, which are based on the latest RHUI RPM packages and ubi9 or ubi9-init base images. Among the addressed vulnerabilities is CVE-2025-11187, a flaw in OpenSSL versions 3.4, 3.5, and 3.6 where improper validation of PBMAC1 parameters in PKCS#12 MAC verification can cause a stack buffer overflow or NULL pointer dereference. This vulnerability can lead to denial of service or, in some cases, arbitrary code execution if an application processes a maliciously crafted PKCS#12 file. The advisory notes that exploitation requires processing untrusted PKCS#12 files, which is uncommon. The update includes multiple CVEs but does not explicitly list individual fixes. The updated container images should be deployed using the rhui-installer utility according to Red Hat's official documentation.
Potential Impact
The impact includes potential denial of service and possible arbitrary code execution due to vulnerabilities in OpenSSL and other components included in RHUI container images. The CVE-2025-11187 vulnerability specifically can cause application crashes or code execution when processing malicious PKCS#12 files. However, exploitation requires local processing of crafted files, which are typically trusted and not commonly untrusted. No known exploits in the wild have been reported. The update mitigates these risks by providing updated container images with the latest security patches.
Mitigation Recommendations
Deploy the updated Red Hat Update Infrastructure 5.1 container images provided by this release using the rhui-installer utility as described in the official Red Hat documentation. Avoid processing untrusted PKCS#12 files to mitigate the OpenSSL vulnerability CVE-2025-11187. Since this is a container image update, applying the updated images replaces vulnerable components. No additional immediate actions are specified in the advisory.
Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update
Description
Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers a security update for Red Hat Update Infrastructure (RHUI) 5.1 container images, which are based on the latest RHUI RPM packages and ubi9 or ubi9-init base images. Among the addressed vulnerabilities is CVE-2025-11187, a flaw in OpenSSL versions 3.4, 3.5, and 3.6 where improper validation of PBMAC1 parameters in PKCS#12 MAC verification can cause a stack buffer overflow or NULL pointer dereference. This vulnerability can lead to denial of service or, in some cases, arbitrary code execution if an application processes a maliciously crafted PKCS#12 file. The advisory notes that exploitation requires processing untrusted PKCS#12 files, which is uncommon. The update includes multiple CVEs but does not explicitly list individual fixes. The updated container images should be deployed using the rhui-installer utility according to Red Hat's official documentation.
Potential Impact
The impact includes potential denial of service and possible arbitrary code execution due to vulnerabilities in OpenSSL and other components included in RHUI container images. The CVE-2025-11187 vulnerability specifically can cause application crashes or code execution when processing malicious PKCS#12 files. However, exploitation requires local processing of crafted files, which are typically trusted and not commonly untrusted. No known exploits in the wild have been reported. The update mitigates these risks by providing updated container images with the latest security patches.
Mitigation Recommendations
Deploy the updated Red Hat Update Infrastructure 5.1 container images provided by this release using the rhui-installer utility as described in the official Red Hat documentation. Avoid processing untrusted PKCS#12 files to mitigate the OpenSSL vulnerability CVE-2025-11187. Since this is a container image update, applying the updated images replaces vulnerable components. No additional immediate actions are specified in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:4943
- Cve Count
- 32
- Additional Cves
- ["CVE-2025-9820","CVE-2025-11187","CVE-2025-12084","CVE-2025-13836","CVE-2025-14104","CVE-2025-14831","CVE-2025-15281","CVE-2025-15366","CVE-2025-15367","CVE-2025-15467","CVE-2025-15468","CVE-2025-15469","CVE-2025-61726","CVE-2025-66199","CVE-2025-68160","CVE-2025-69418","CVE-2025-69419","CVE-2025-69420","CVE-2025-69421","CVE-2026-0861","CVE-2026-0865","CVE-2026-0915","CVE-2026-1299","CVE-2026-1642","CVE-2026-2003","CVE-2026-2004","CVE-2026-2005","CVE-2026-2006","CVE-2026-22795","CVE-2026-22796","CVE-2026-23490"]
Threat ID: 6a160964e29bf47b50629671
Added to database: 05/26/2026, 20:58:12 UTC
Last enriched: 08/14/2026, 20:03:43 UTC
Last updated: 09/13/2026, 00:47:04 UTC
Views: 132
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.