Red Hat Security Advisory: rhc security update
A denial of service vulnerability (CVE-2026-84445) exists in the gRPC-Go library used by the Red Hat rhc client tool and daemon. This flaw allows malformed RPC requests to cause service disruption. Red Hat has issued an important security update for rhc in Red Hat Enterprise Linux 9 and related variants to address this issue.
AI Analysis
Technical Summary
The vulnerability CVE-2026-84445 affects the gRPC-Go component utilized by the rhc client tool and daemon, which connects systems to Red Hat hosted services for system and subscription management. The flaw enables denial of service via malformed RPC requests. Red Hat has released a security update for rhc in Red Hat Enterprise Linux 9 and its extended update support versions to remediate this issue.
Potential Impact
Successful exploitation of this vulnerability could cause denial of service conditions in the rhc client, potentially disrupting system and subscription management operations that rely on this tool. No evidence of active exploitation in the wild has been reported.
Mitigation Recommendations
Red Hat has provided an official security update that fixes this vulnerability. Users should apply the rhc package update available for Red Hat Enterprise Linux 9 and its variants as detailed in the Red Hat advisory RHSA-2026:72275. Refer to https://access.redhat.com/articles/11258 for update instructions.
Red Hat Security Advisory: rhc security update
Description
A denial of service vulnerability (CVE-2026-84445) exists in the gRPC-Go library used by the Red Hat rhc client tool and daemon. This flaw allows malformed RPC requests to cause service disruption. Red Hat has issued an important security update for rhc in Red Hat Enterprise Linux 9 and related variants to address this issue.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-84445 affects the gRPC-Go component utilized by the rhc client tool and daemon, which connects systems to Red Hat hosted services for system and subscription management. The flaw enables denial of service via malformed RPC requests. Red Hat has released a security update for rhc in Red Hat Enterprise Linux 9 and its extended update support versions to remediate this issue.
Potential Impact
Successful exploitation of this vulnerability could cause denial of service conditions in the rhc client, potentially disrupting system and subscription management operations that rely on this tool. No evidence of active exploitation in the wild has been reported.
Mitigation Recommendations
Red Hat has provided an official security update that fixes this vulnerability. Users should apply the rhc package update available for Red Hat Enterprise Linux 9 and its variants as detailed in the Red Hat advisory RHSA-2026:72275. Refer to https://access.redhat.com/articles/11258 for update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:72275
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6abb4182f7a7c54106cc2ec2
Added to database: 09/29/2026, 04:41:38 UTC
Last enriched: 09/29/2026, 04:45:50 UTC
Last updated: 09/29/2026, 18:13:13 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.