RHSA-2026:54757: Important: Red Hat OpenStack Platform 16.2 security advisory
Red Hat OpenStack Platform provides the facilities for building, deploying and monitoring a private or public infrastructure-as-a-service (IaaS) cloud running on commonly available physical hardware.Security Fix(es): crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova (CVE-2026-24708) pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) openstack-glance: OpenStack Glance: Server-Side Request Forgery leading to unauthorized internal network access (CVE-2026-34881) crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) etcd: etcd: Authorization bypass allows information disclosure and denial of service (CVE-2026-33413) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) erlang: Erlang OTP publickey: Certificate chain forgery via improper trust chain validation (CVE-2026-42789) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) oslo.messaging: openstack: OpenStack oslo.messaging: Man-in-the-middle attack via improper TLS hostname verification (CVE-2026-44393) erlang: Erlang OTP publickey: Certificate validation bypass allows hostname spoofing (CVE-2026-42790) openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signature validation flaw (CVE-2025-65073) OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-43001) openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation (CVE-2026-33551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/collectd-sensubilityto a version that resolves this vulnerability.Fixed in 0.2.1-1.1.el8 - Upgrade
Upgrade
redhat/erlangto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 3.3.23-22.el8 - Upgrade
Upgrade
redhat/openstack-cinderto a version that resolves this vulnerability.Fixed in 15.6.1-2.20250708154832.299553a.el8 - Upgrade
Upgrade
redhat/openstack-glanceto a version that resolves this vulnerability.Fixed in 19.0.5-2.20260512165254.eb6ad61.el8 - Upgrade
Upgrade
redhat/openstack-keystoneto a version that resolves this vulnerability.Fixed in 16.0.3-2.20260616134936.9d699a7.el8 - Upgrade
Upgrade
redhat/openstack-novato a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-swiftto a version that resolves this vulnerability.Fixed in 2.23.4-2.20260121154927.70b68db.el8 - Upgrade
Upgrade
redhat/openstack-tempestto a version that resolves this vulnerability.Fixed in 26.1.0-2.20250728145114.271f820.el8 - Upgrade
Upgrade
redhat/openstack-tripleo-commonto a version that resolves this vulnerability.Fixed in 11.7.1-2.20251029134905.e189622.el8 - Upgrade
Upgrade
redhat/openstack-tripleo-heat-templatesto a version that resolves this vulnerability.Fixed in 11.6.1-2.20251125134914.9adcac6.el8 - Upgrade
Upgrade
redhat/puppet-apacheto a version that resolves this vulnerability.Fixed in 5.1.1-2.20250728133931.1fa9b1c.el8 - Upgrade
Upgrade
redhat/puppet-concatto a version that resolves this vulnerability.Fixed in 6.1.1-2.20250728133127.9baa8fc.el8 - Upgrade
Upgrade
redhat/puppet-corosyncto a version that resolves this vulnerability.Fixed in 6.0.2-2.20250728134759.961add3.el8 - Upgrade
Upgrade
redhat/puppet-datacatto a version that resolves this vulnerability.Fixed in 0.6.3-2.20250728140400.5cce8f2.el8 - Upgrade
Upgrade
redhat/puppet-firewallto a version that resolves this vulnerability.Fixed in 3.4.1-2.20250728144450.94f707c.el8 - Upgrade
Upgrade
redhat/puppet-gitto a version that resolves this vulnerability.Fixed in 0.5.0-2.20250728140843.4e4498e.el8 - Upgrade
Upgrade
redhat/puppet-haproxyto a version that resolves this vulnerability.Fixed in 4.1.1-2.20250728141134.df96ffc.el8 - Upgrade
Upgrade
redhat/puppet-inifileto a version that resolves this vulnerability.Fixed in 3.1.1-2.20250728133040.91efced.el8 - Upgrade
Upgrade
redhat/puppet-ipaclientto a version that resolves this vulnerability.Fixed in 2.5.2-2.20250728141812.b086731.el8 - Upgrade
Upgrade
redhat/puppet-javato a version that resolves this vulnerability.Fixed in 5.0.2-2.20250804144904.e57cbc8.el8 - Upgrade
Upgrade
redhat/puppet-keepalivedto a version that resolves this vulnerability.Fixed in 0.0.2-2.20250728142002.bbca37a.el8 - Upgrade
Upgrade
redhat/puppet-module-datato a version that resolves this vulnerability.Fixed in 0.5.1-2.20250728142646.28dafce.el8 - Upgrade
Upgrade
redhat/puppet-rabbitmqto a version that resolves this vulnerability.Fixed in 10.1.2-2.20250728144344.8b9b006.el8 - Upgrade
Upgrade
redhat/puppet-remoteto a version that resolves this vulnerability.Fixed in 10.0.0-2.20250728135533.7420908.el8 - Upgrade
Upgrade
redhat/puppet-snmpto a version that resolves this vulnerability.Fixed in 3.9.1-2.20250728142735.5d73485.el8 - Upgrade
Upgrade
redhat/puppet-stagingto a version that resolves this vulnerability.Fixed in 1.0.5-2.20250728134218.b466d93.el8 - Upgrade
Upgrade
redhat/puppet-stdlibto a version that resolves this vulnerability.Fixed in 6.1.1-2.20250728131928.5aa891c.el8 - Upgrade
Upgrade
redhat/puppet-tomcatto a version that resolves this vulnerability.Fixed in 3.1.1-2.20250804144904.a3f92d1.el8 - Upgrade
Upgrade
redhat/puppet-vcsrepoto a version that resolves this vulnerability.Fixed in 3.0.1-2.20250728140014.b06d5d3.el8 - Upgrade
Upgrade
redhat/puppet-xinetdto a version that resolves this vulnerability.Fixed in 3.3.1-2.20250728135145.d768da2.el8 - Upgrade
Upgrade
redhat/python-collectd-gnocchito a version that resolves this vulnerability.Fixed in 1.7.2-2.20250728143604.de115a7.el8 - Upgrade
Upgrade
redhat/python-gnocchiclientto a version that resolves this vulnerability.Fixed in 7.0.4-2.20250728131928.64814b9.el8 - Upgrade
Upgrade
redhat/python-oslo-messagingto a version that resolves this vulnerability.Fixed in 10.2.4-2.20260710155333.82281a0.el8 - Upgrade
Upgrade
redhat/python-pyasn1to a version that resolves this vulnerability.Fixed in 0.4.6-4.el8 - Upgrade
Upgrade
redhat/tripleo-ansibleto a version that resolves this vulnerability.Fixed in 0.8.1-2.20260112154909.123ce73.el8 - Upgrade
Upgrade
redhat/collectd-sensubility-debuginfoto a version that resolves this vulnerability.Fixed in 0.2.1-1.1.el8 - Upgrade
Upgrade
redhat/erlang-asn1to a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-asn1-debuginfoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-compilerto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-cryptoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-crypto-debuginfoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-debuginfoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-debugsourceto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-eldapto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-ertsto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-erts-debuginfoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-hipeto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-inetsto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-kernelto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-mnesiato a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-parsetoolsto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-saslto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-snmpto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-sslto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-stdlibto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-toolsto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-tools-debuginfoto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/erlang-xmerlto a version that resolves this vulnerability.Fixed in 23.3.4.18-2.el8 - Upgrade
Upgrade
redhat/etcd-debuginfoto a version that resolves this vulnerability.Fixed in 3.3.23-22.el8 - Upgrade
Upgrade
redhat/etcd-debugsourceto a version that resolves this vulnerability.Fixed in 3.3.23-22.el8 - Upgrade
Upgrade
redhat/openstack-nova-apito a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-commonto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-computeto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-conductorto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-consoleto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-migrationto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-novncproxyto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-schedulerto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-serialproxyto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-nova-spicehtml5proxyto a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/openstack-swift-accountto a version that resolves this vulnerability.Fixed in 2.23.4-2.20260121154927.70b68db.el8 - Upgrade
Upgrade
redhat/openstack-swift-containerto a version that resolves this vulnerability.Fixed in 2.23.4-2.20260121154927.70b68db.el8 - Upgrade
Upgrade
redhat/openstack-swift-objectto a version that resolves this vulnerability.Fixed in 2.23.4-2.20260121154927.70b68db.el8 - Upgrade
Upgrade
redhat/openstack-swift-proxyto a version that resolves this vulnerability.Fixed in 2.23.4-2.20260121154927.70b68db.el8 - Upgrade
Upgrade
redhat/openstack-tempest-allto a version that resolves this vulnerability.Fixed in 26.1.0-2.20250728145114.271f820.el8 - Upgrade
Upgrade
redhat/openstack-tripleo-common-container-baseto a version that resolves this vulnerability.Fixed in 11.7.1-2.20251029134905.e189622.el8 - Upgrade
Upgrade
redhat/openstack-tripleo-common-containersto a version that resolves this vulnerability.Fixed in 11.7.1-2.20251029134905.e189622.el8 - Upgrade
Upgrade
redhat/openstack-tripleo-common-devtoolsto a version that resolves this vulnerability.Fixed in 11.7.1-2.20251029134905.e189622.el8 - Upgrade
Upgrade
redhat/python3-cinderto a version that resolves this vulnerability.Fixed in 15.6.1-2.20250708154832.299553a.el8 - Upgrade
Upgrade
redhat/python3-collectd-gnocchito a version that resolves this vulnerability.Fixed in 1.7.2-2.20250728143604.de115a7.el8 - Upgrade
Upgrade
redhat/python3-glanceto a version that resolves this vulnerability.Fixed in 19.0.5-2.20260512165254.eb6ad61.el8 - Upgrade
Upgrade
redhat/python3-gnocchiclientto a version that resolves this vulnerability.Fixed in 7.0.4-2.20250728131928.64814b9.el8 - Upgrade
Upgrade
redhat/python3-keystoneto a version that resolves this vulnerability.Fixed in 16.0.3-2.20260616134936.9d699a7.el8 - Upgrade
Upgrade
redhat/python3-novato a version that resolves this vulnerability.Fixed in 20.6.2-2.20260317135026.8a24acd.el8 - Upgrade
Upgrade
redhat/python3-oslo-messagingto a version that resolves this vulnerability.Fixed in 10.2.4-2.20260710155333.82281a0.el8 - Upgrade
Upgrade
redhat/python3-pyasn1to a version that resolves this vulnerability.Fixed in 0.4.6-4.el8 - Upgrade
Upgrade
redhat/python3-pyasn1-modulesto a version that resolves this vulnerability.Fixed in 0.4.6-4.el8 - Upgrade
Upgrade
redhat/python3-swiftto a version that resolves this vulnerability.Fixed in 2.23.4-2.20260121154927.70b68db.el8 - Upgrade
Upgrade
redhat/python3-tempestto a version that resolves this vulnerability.Fixed in 26.1.0-2.20250728145114.271f820.el8 - Upgrade
Upgrade
redhat/python3-tempest-teststo a version that resolves this vulnerability.Fixed in 26.1.0-2.20250728145114.271f820.el8 - Upgrade
Upgrade
redhat/python3-tripleo-commonto a version that resolves this vulnerability.Fixed in 11.7.1-2.20251029134905.e189622.el8
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54757?
The severity of RHSA-2026:54757 is rated as important.
What types of services are affected by RHSA-2026:54757?
RHSA-2026:54757 affects several Red Hat OpenStack Platform services including OpenStack Cinder, Glance, Keystone, Nova, and Swift.
How do I fix RHSA-2026:54757?
To address RHSA-2026:54757, it is recommended to update your Red Hat OpenStack Platform to the latest patched version.
What is the main vulnerability addressed in RHSA-2026:54757?
The main vulnerability in RHSA-2026:54757 is a Denial of Service caused by excessive resource consumption.
Is there a workaround for RHSA-2026:54757?
Currently, there is no specified workaround for RHSA-2026:54757, and applying the update is required to mitigate the risk.