Red Hat Security Advisory: Satellite 6.17.8 Async Update
Red Hat Satellite 6.17.8 for RHEL 9 includes multiple security fixes addressing vulnerabilities such as denial of service via malformed HTML-like sequences in python-markdown (CVE-2025-69534), out-of-bounds write in python-pillow, arbitrary code execution in candlepin, buffer overflow in python-pyOpenSSL, and denial of service in rubygem-activesupport. The update also resolves various functional bugs. These vulnerabilities affect system management and provisioning components used to maintain systems without public Internet access.
AI Analysis
Technical Summary
This advisory covers Red Hat Satellite 6.17.8 for RHEL 9, a system management solution, which addresses five CVEs: CVE-2025-69534 (denial of service via malformed HTML-like sequences in python-markdown), CVE-2026-25990 (out-of-bounds write in python-pillow), CVE-2026-27727 (arbitrary code execution via JNDI dereferencing in candlepin), CVE-2026-27459 (DTLS cookie callback buffer overflow in python-pyOpenSSL), and CVE-2026-33176 (denial of service via large scientific notation strings in rubygem-activesupport). The advisory also includes multiple bug fixes improving Satellite functionality. The vendor has released an updated version 6.17.8 that addresses these issues.
Potential Impact
The vulnerabilities include denial of service conditions and potential arbitrary code execution, which could disrupt system management operations or allow execution of malicious code within the affected environment. The denial of service vulnerabilities could impact availability, while the arbitrary code execution vulnerability poses a higher risk to system integrity. The overall impact affects the security and reliability of Red Hat Satellite deployments managing system provisioning and configuration.
Mitigation Recommendations
An official fix is available in Red Hat Satellite version 6.17.8 for RHEL 9. Users should apply this update after ensuring all previously released errata relevant to their system have been applied. Detailed update instructions are provided by Red Hat in their official documentation. No additional mitigations are specified beyond applying the vendor-provided update.
Red Hat Security Advisory: Satellite 6.17.8 Async Update
Description
Red Hat Satellite 6.17.8 for RHEL 9 includes multiple security fixes addressing vulnerabilities such as denial of service via malformed HTML-like sequences in python-markdown (CVE-2025-69534), out-of-bounds write in python-pillow, arbitrary code execution in candlepin, buffer overflow in python-pyOpenSSL, and denial of service in rubygem-activesupport. The update also resolves various functional bugs. These vulnerabilities affect system management and provisioning components used to maintain systems without public Internet access.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers Red Hat Satellite 6.17.8 for RHEL 9, a system management solution, which addresses five CVEs: CVE-2025-69534 (denial of service via malformed HTML-like sequences in python-markdown), CVE-2026-25990 (out-of-bounds write in python-pillow), CVE-2026-27727 (arbitrary code execution via JNDI dereferencing in candlepin), CVE-2026-27459 (DTLS cookie callback buffer overflow in python-pyOpenSSL), and CVE-2026-33176 (denial of service via large scientific notation strings in rubygem-activesupport). The advisory also includes multiple bug fixes improving Satellite functionality. The vendor has released an updated version 6.17.8 that addresses these issues.
Potential Impact
The vulnerabilities include denial of service conditions and potential arbitrary code execution, which could disrupt system management operations or allow execution of malicious code within the affected environment. The denial of service vulnerabilities could impact availability, while the arbitrary code execution vulnerability poses a higher risk to system integrity. The overall impact affects the security and reliability of Red Hat Satellite deployments managing system provisioning and configuration.
Mitigation Recommendations
An official fix is available in Red Hat Satellite version 6.17.8 for RHEL 9. Users should apply this update after ensuring all previously released errata relevant to their system have been applied. Detailed update instructions are provided by Red Hat in their official documentation. No additional mitigations are specified beyond applying the vendor-provided update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:14873
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-25990","CVE-2026-27459","CVE-2026-27727","CVE-2026-33176"]
- Cvss Version
- 3.1
Threat ID: 6a160980e29bf47b5064d07a
Added to database: 05/26/2026, 20:58:40 UTC
Last enriched: 07/30/2026, 12:11:40 UTC
Last updated: 07/31/2026, 19:22:56 UTC
Views: 108
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.