Skip to main content
EPSS 1.4%top 29%

Red Hat Security Advisory: Red Hat Update Infrastructure 5 security update

0
High
Published: 02/11/2026 (02/11/2026, 14:34:45 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version.

Affected software

Affected versions
Red HatRed Hat Update InfrastructureRed Hat Update Infrastructure 5amd64registry.redhat.io/rhui5/cds-rhel9@sha256:83e8b356eb4697a81ff8c6764dc976862800f4c78122a606173340a6e105a4fe_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 17:45:37 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:2563) covers a security update for Red Hat Update Infrastructure 5 container images, which are updated to the latest RHUI RPM packages and ubi9 or ubi9-init base images. The advisory addresses 21 CVEs including CVE-2025-9086 and CVE-2025-11187. CVE-2025-11187 is a moderate severity OpenSSL vulnerability affecting versions 3.4, 3.5, and 3.6, caused by improper validation of PBMAC1 parameters in PKCS#12 MAC verification, leading to stack buffer overflow or NULL pointer dereference. Exploitation requires processing a malicious PKCS#12 file, which is uncommon. The advisory recommends deploying updated container images via the rhui-installer utility but does not explicitly confirm a patch or fix status for all CVEs. No known exploits in the wild have been reported. The update is considered important and rated high severity overall.

Potential Impact

The vulnerabilities addressed include potential denial of service and arbitrary code execution risks, notably from CVE-2025-11187 in OpenSSL when processing malicious PKCS#12 files. The impact is rated high severity by Red Hat, indicating significant risk if exploited. However, exploitation requires local processing of crafted files, which are typically trusted, reducing likelihood. No known active exploits have been reported.

Mitigation Recommendations

The advisory recommends deploying the updated Red Hat Update Infrastructure 5 container images using the rhui-installer utility as per official documentation. For the OpenSSL vulnerability CVE-2025-11187, it is advised to avoid processing untrusted PKCS#12 files, as these files are typically trusted and used for private keys. Patch status is not explicitly confirmed in the advisory; therefore, users should follow Red Hat's official documentation and errata for updates and deployment instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2563
Cve Count
21
Additional Cves
["CVE-2025-11187","CVE-2025-12084","CVE-2025-13601","CVE-2025-13836","CVE-2025-14104","CVE-2025-15467","CVE-2025-15468","CVE-2025-15469","CVE-2025-66199","CVE-2025-66418","CVE-2025-66471","CVE-2025-68160","CVE-2025-68973","CVE-2025-69418","CVE-2025-69419","CVE-2025-69420","CVE-2025-69421","CVE-2026-21441","CVE-2026-22795","CVE-2026-22796"]

Threat ID: 6a16096be29bf47b50630e27

Added to database: 05/26/2026, 20:58:19 UTC

Last enriched: 08/17/2026, 17:45:37 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 138

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses