Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Satellite 6.15.4 Security Update

0
Medium
Published: Thu Oct 10 2024 (10/10/2024, 20:31:33 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Satellite 6. 15. 4 includes security updates addressing four vulnerabilities: an HTTP request smuggling issue in python-gunicorn (CVE-2024-1135), unexpected behavior in golang net/netip methods (CVE-2024-24790), a NULL pointer dereference in python-cryptography (CVE-2024-26130), and a potential denial-of-service vulnerability in python-django (CVE-2024-41991). These vulnerabilities have been rated with moderate severity by Red Hat Product Security. The update fixes these issues and users are advised to upgrade to the updated packages. No known exploits in the wild have been reported. The advisory provides detailed instructions for applying the update to affected Red Hat Satellite 6. 15 for RHEL 8 systems.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 21:22:38 UTC

Technical Analysis

Red Hat Satellite 6.15.4 addresses multiple security vulnerabilities across components used by the product. CVE-2024-1135 is an HTTP request smuggling vulnerability in python-gunicorn caused by improper validation of Transfer-Encoding headers. CVE-2024-24790 involves unexpected behavior in golang's net/netip Is methods for IPv4-mapped IPv6 addresses. CVE-2024-26130 is a NULL pointer dereference in python-cryptography's pkcs12.serialize_key_and_certificates function when called with mismatched certificates and keys combined with an hmac_hash override. CVE-2024-41991 is a potential denial-of-service vulnerability in python-django's urlize() function and AdminURLFieldWidget. Red Hat has released updated packages fixing these issues and recommends users upgrade accordingly.

Potential Impact

The vulnerabilities fixed in this update have a moderate security impact. They include HTTP request smuggling, which can affect HTTP request handling; unexpected behavior in IP address handling functions; a NULL pointer dereference that could cause application crashes; and a potential denial-of-service condition in Django components. No known active exploitation has been reported. These issues could affect the stability and security of Red Hat Satellite systems if left unpatched.

Mitigation Recommendations

Red Hat has released official updates for Red Hat Satellite 6.15.4 that address these vulnerabilities. Users are advised to apply these updates promptly. Before updating, ensure all previously released errata relevant to the system are applied. Detailed update instructions are available in the Red Hat Satellite documentation. No additional mitigation steps are indicated beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:7987
Cve Count
4
Additional Cves
["CVE-2024-24790","CVE-2024-26130","CVE-2024-41991"]
Cvss Version
null

Threat ID: 6a1df669e29bf47b50461de0

Added to database: 6/1/2026, 9:15:21 PM

Last enriched: 6/1/2026, 9:22:38 PM

Last updated: 6/2/2026, 4:58:38 AM

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses