Skip to main content
EPSS 0.7%top 48%

Red Hat Security Advisory: rhc security update

0
High
Published: 04/22/2026 (04/22/2026, 11:44:28 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

rhc is a client tool and daemon that connects the system to Red Hat hosted services enabling system and subscription management. Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
>=10.0Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v. 10.0)srcgolang-github-openprinting-ipp-usb-0:0.9.27-3.el10_0.3.srcyggdrasil-worker-package-manager-0:0.2.3-5.el10_0.srcRed Hat Enterprise Linux AppStream EUS (v.9.4)git-lfs-0:3.4.1-4.el9_4.5.srcRed Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)Red Hat Enterprise Linux AppStream (v. 10)yggdrasil-worker-package-manager-0:0.2.3-5.el10_1.srcRed Hat Enterprise Linux CodeReady Linux Builder (v. 10)Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 2.6amd64registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:a0578780579fcd74c269dca0087dd97382e45bc684d99c362c99922849efd2e1_amd64image-builder-0:31-5.el10_1.srcRed Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:7c721b3e96083fffbede7c3e313b9a2609dd620086d8c3a6c92faa06eb78306b_amd64osbuild-composer-0:149-6.el10_1.srcRed Hat Enterprise Linux AppStream (v. 9)image-builder-0:31-4.el9_7.srcgrafana-pcp-0:5.3.0-4.el10_2.srcgrafana-0:10.2.6-25.el10_2.srcskopeo-2:1.22.2-1.el10_2.srcbuildah-2:1.43.1-1.el10_2.srcyggdrasil-worker-package-manager-0:0.2.3-6.el10_2.srcrhc-1:0.3.8-3.el10_2.srcrhc-worker-playbook-0:0.2.3-4.el10_1.srcgrafana-pcp-0:5.1.1-14.el9_8.srcgrafana-0:10.2.6-21.el9_8.srcRed Hat Enterprise Linux AppStream AUS (v.8.4)Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)Red Hat Enterprise Linux AppStream AUS (v.8.6)Red Hat Enterprise Linux AppStream E4S (v.8.6)Red Hat Enterprise Linux AppStream TUS (v.8.6)Red Hat Enterprise Linux AppStream E4S (v.8.8)Red Hat Enterprise Linux AppStream TUS (v.8.8)Red Hat Enterprise Linux AppStream E4S (v.9.4)osbuild-composer-0:101.3-4.el9_4.1.srcRed Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.16podman-6:5.8.2-2.el9_8.srcRed Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:59:42 UTC

Technical Analysis

The vulnerability CVE-2026-25679 concerns the golang-github-openprinting-ipp-usb package, which provides an HTTP reverse proxy backed by IPP-over-USB connections enabling driverless support for USB devices using the IPP-over-USB protocol. The security flaw lies in the net/url package's incorrect parsing of IPv6 host literals, potentially leading to security issues. Red Hat has released security updates for Red Hat Enterprise Linux 10.0 Extended Update Support across multiple architectures to fix this issue. The advisory references the net/url parsing bug and provides updated packages to remediate the vulnerability.

Potential Impact

The vulnerability could allow incorrect handling of IPv6 host literals, which may lead to security issues such as improper URL parsing. The exact impact details are not fully described in the advisory, but Red Hat rates the security impact as Important (high). There are no known exploits in the wild currently reported.

Mitigation Recommendations

Red Hat has released official security updates for the golang-github-openprinting-ipp-usb package in Red Hat Enterprise Linux 10.0 Extended Update Support. Users should apply these updates as per Red Hat's guidance available at https://access.redhat.com/articles/11258. The vendor advisory confirms the availability of patches and recommends updating affected packages to remediate the vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:9695
Cve Count
1
State
PUBLISHED

Threat ID: 6a16097ee29bf47b5064ab02

Added to database: 05/26/2026, 20:58:38 UTC

Last enriched: 08/14/2026, 23:59:42 UTC

Last updated: 09/12/2026, 10:01:30 UTC

Views: 109

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:10701https://access.redhat.com/security/updates/classification/#important2445356Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10133Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10712Canonical URLhttps://access.redhat.com/errata/RHSA-2026:11375Canonical URLhttps://access.redhat.com/errata/RHSA-2026:11413Canonical URLhttps://access.redhat.com/errata/RHSA-2026:17287245547024563382456339Canonical URLhttps://access.redhat.com/errata/RHSA-2026:11412Canonical URLhttps://access.redhat.com/errata/RHSA-2026:11686https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/cve-2026-25679https://access.redhat.com/security/updates/classificationhttps://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7259Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7005Canonical URLhttps://access.redhat.com/errata/RHSA-2026:13642Canonical URLhttps://access.redhat.com/errata/RHSA-2026:13643Canonical URLhttps://access.redhat.com/errata/RHSA-2026:13671Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19026Canonical URLhttps://access.redhat.com/errata/RHSA-2026:52391Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6341Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19027Canonical URLhttps://access.redhat.com/errata/RHSA-2026:8851Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19031RHEL-168168Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19032RHEL-164030Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19128Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19055Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19184Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19185Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20581Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20582Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20584Canonical URLhttps://access.redhat.com/errata/RHSA-2026:22733Canonical URLhttps://access.redhat.com/errata/RHSA-2026:9461Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24386Canonical URLhttps://access.redhat.com/errata/RHSA-2026:25043Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26445Canonical URLhttps://access.redhat.com/errata/RHSA-2026:52389Canonical URLhttps://access.redhat.com/errata/RHSA-2026:52390Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6344Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6382Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6383Canonical URLhttps://access.redhat.com/errata/RHSA-2026:101692445345Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6388Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7009Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7011Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7315Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7328Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7665Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7669Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7674Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7992Canonical URLhttps://access.redhat.com/errata/RHSA-2026:9695Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses