RHSA-2026:54757: Important: Red Hat OpenStack Platform 16.2 security advisory

Published Aug 13, 2026
·
Updated

Red Hat OpenStack Platform provides the facilities for building, deploying and monitoring a private or public infrastructure-as-a-service (IaaS) cloud running on commonly available physical hardware.Security Fix(es): crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova (CVE-2026-24708) pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) openstack-glance: OpenStack Glance: Server-Side Request Forgery leading to unauthorized internal network access (CVE-2026-34881) crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) etcd: etcd: Authorization bypass allows information disclosure and denial of service (CVE-2026-33413) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) erlang: Erlang OTP publickey: Certificate chain forgery via improper trust chain validation (CVE-2026-42789) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) oslo.messaging: openstack: OpenStack oslo.messaging: Man-in-the-middle attack via improper TLS hostname verification (CVE-2026-44393) erlang: Erlang OTP publickey: Certificate validation bypass allows hostname spoofing (CVE-2026-42790) openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signature validation flaw (CVE-2025-65073) OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-43001) openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation (CVE-2026-33551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Affected Software

93 affected componentsFixes available
redhat/collectd-sensubility<0.2.1-1.1.el8
0.2.1-1.1.el8
redhat/erlang<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/etcd<3.3.23-22.el8
3.3.23-22.el8
redhat/openstack-cinder<15.6.1-2.20250708154832.299553a.el8
15.6.1-2.20250708154832.299553a.el8
redhat/openstack-glance<19.0.5-2.20260512165254.eb6ad61.el8
19.0.5-2.20260512165254.eb6ad61.el8
redhat/openstack-keystone<16.0.3-2.20260616134936.9d699a7.el8
16.0.3-2.20260616134936.9d699a7.el8
redhat/openstack-nova<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-swift<2.23.4-2.20260121154927.70b68db.el8
2.23.4-2.20260121154927.70b68db.el8
redhat/openstack-tempest<26.1.0-2.20250728145114.271f820.el8
26.1.0-2.20250728145114.271f820.el8
redhat/openstack-tripleo-common<11.7.1-2.20251029134905.e189622.el8
11.7.1-2.20251029134905.e189622.el8
redhat/openstack-tripleo-heat-templates<11.6.1-2.20251125134914.9adcac6.el8
11.6.1-2.20251125134914.9adcac6.el8
redhat/puppet-apache<5.1.1-2.20250728133931.1fa9b1c.el8
5.1.1-2.20250728133931.1fa9b1c.el8
redhat/puppet-concat<6.1.1-2.20250728133127.9baa8fc.el8
6.1.1-2.20250728133127.9baa8fc.el8
redhat/puppet-corosync<6.0.2-2.20250728134759.961add3.el8
6.0.2-2.20250728134759.961add3.el8
redhat/puppet-datacat<0.6.3-2.20250728140400.5cce8f2.el8
0.6.3-2.20250728140400.5cce8f2.el8
redhat/puppet-firewall<3.4.1-2.20250728144450.94f707c.el8
3.4.1-2.20250728144450.94f707c.el8
redhat/puppet-git<0.5.0-2.20250728140843.4e4498e.el8
0.5.0-2.20250728140843.4e4498e.el8
redhat/puppet-haproxy<4.1.1-2.20250728141134.df96ffc.el8
4.1.1-2.20250728141134.df96ffc.el8
redhat/puppet-inifile<3.1.1-2.20250728133040.91efced.el8
3.1.1-2.20250728133040.91efced.el8
redhat/puppet-ipaclient<2.5.2-2.20250728141812.b086731.el8
2.5.2-2.20250728141812.b086731.el8
redhat/puppet-java<5.0.2-2.20250804144904.e57cbc8.el8
5.0.2-2.20250804144904.e57cbc8.el8
redhat/puppet-keepalived<0.0.2-2.20250728142002.bbca37a.el8
0.0.2-2.20250728142002.bbca37a.el8
redhat/puppet-module-data<0.5.1-2.20250728142646.28dafce.el8
0.5.1-2.20250728142646.28dafce.el8
redhat/puppet-rabbitmq<10.1.2-2.20250728144344.8b9b006.el8
10.1.2-2.20250728144344.8b9b006.el8
redhat/puppet-remote<10.0.0-2.20250728135533.7420908.el8
10.0.0-2.20250728135533.7420908.el8
redhat/puppet-snmp<3.9.1-2.20250728142735.5d73485.el8
3.9.1-2.20250728142735.5d73485.el8
redhat/puppet-staging<1.0.5-2.20250728134218.b466d93.el8
1.0.5-2.20250728134218.b466d93.el8
redhat/puppet-stdlib<6.1.1-2.20250728131928.5aa891c.el8
6.1.1-2.20250728131928.5aa891c.el8
redhat/puppet-tomcat<3.1.1-2.20250804144904.a3f92d1.el8
3.1.1-2.20250804144904.a3f92d1.el8
redhat/puppet-vcsrepo<3.0.1-2.20250728140014.b06d5d3.el8
3.0.1-2.20250728140014.b06d5d3.el8
redhat/puppet-xinetd<3.3.1-2.20250728135145.d768da2.el8
3.3.1-2.20250728135145.d768da2.el8
redhat/python-collectd-gnocchi<1.7.2-2.20250728143604.de115a7.el8
1.7.2-2.20250728143604.de115a7.el8
redhat/python-gnocchiclient<7.0.4-2.20250728131928.64814b9.el8
7.0.4-2.20250728131928.64814b9.el8
redhat/python-oslo-messaging<10.2.4-2.20260710155333.82281a0.el8
10.2.4-2.20260710155333.82281a0.el8
redhat/python-pyasn1<0.4.6-4.el8
0.4.6-4.el8
redhat/tripleo-ansible<0.8.1-2.20260112154909.123ce73.el8
0.8.1-2.20260112154909.123ce73.el8
redhat/collectd-sensubility-debuginfo<0.2.1-1.1.el8
0.2.1-1.1.el8
redhat/erlang-asn1<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-asn1-debuginfo<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-compiler<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-crypto<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-crypto-debuginfo<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-debuginfo<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-debugsource<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-eldap<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-erts<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-erts-debuginfo<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-hipe<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-inets<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-kernel<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-mnesia<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-odbc-debuginfo<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-parsetools<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-sasl<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-snmp<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-ssl<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-stdlib<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-tools<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-tools-debuginfo<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/erlang-xmerl<23.3.4.18-2.el8
23.3.4.18-2.el8
redhat/etcd-debuginfo<3.3.23-22.el8
3.3.23-22.el8
redhat/etcd-debugsource<3.3.23-22.el8
3.3.23-22.el8
redhat/openstack-nova-api<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-common<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-compute<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-conductor<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-console<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-migration<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-novncproxy<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-scheduler<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-serialproxy<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-nova-spicehtml5proxy<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/openstack-swift-account<2.23.4-2.20260121154927.70b68db.el8
2.23.4-2.20260121154927.70b68db.el8
redhat/openstack-swift-container<2.23.4-2.20260121154927.70b68db.el8
2.23.4-2.20260121154927.70b68db.el8
redhat/openstack-swift-object<2.23.4-2.20260121154927.70b68db.el8
2.23.4-2.20260121154927.70b68db.el8
redhat/openstack-swift-proxy<2.23.4-2.20260121154927.70b68db.el8
2.23.4-2.20260121154927.70b68db.el8
redhat/openstack-tempest-all<26.1.0-2.20250728145114.271f820.el8
26.1.0-2.20250728145114.271f820.el8
redhat/openstack-tripleo-common-container-base<11.7.1-2.20251029134905.e189622.el8
11.7.1-2.20251029134905.e189622.el8
redhat/openstack-tripleo-common-containers<11.7.1-2.20251029134905.e189622.el8
11.7.1-2.20251029134905.e189622.el8
redhat/openstack-tripleo-common-devtools<11.7.1-2.20251029134905.e189622.el8
11.7.1-2.20251029134905.e189622.el8
redhat/python3-cinder<15.6.1-2.20250708154832.299553a.el8
15.6.1-2.20250708154832.299553a.el8
redhat/python3-collectd-gnocchi<1.7.2-2.20250728143604.de115a7.el8
1.7.2-2.20250728143604.de115a7.el8
redhat/python3-glance<19.0.5-2.20260512165254.eb6ad61.el8
19.0.5-2.20260512165254.eb6ad61.el8
redhat/python3-gnocchiclient<7.0.4-2.20250728131928.64814b9.el8
7.0.4-2.20250728131928.64814b9.el8
redhat/python3-keystone<16.0.3-2.20260616134936.9d699a7.el8
16.0.3-2.20260616134936.9d699a7.el8
redhat/python3-nova<20.6.2-2.20260317135026.8a24acd.el8
20.6.2-2.20260317135026.8a24acd.el8
redhat/python3-oslo-messaging<10.2.4-2.20260710155333.82281a0.el8
10.2.4-2.20260710155333.82281a0.el8
redhat/python3-pyasn1<0.4.6-4.el8
0.4.6-4.el8
redhat/python3-pyasn1-modules<0.4.6-4.el8
0.4.6-4.el8
redhat/python3-swift<2.23.4-2.20260121154927.70b68db.el8
2.23.4-2.20260121154927.70b68db.el8
redhat/python3-tempest<26.1.0-2.20250728145114.271f820.el8
26.1.0-2.20250728145114.271f820.el8
redhat/python3-tempest-tests<26.1.0-2.20250728145114.271f820.el8
26.1.0-2.20250728145114.271f820.el8
redhat/python3-tripleo-common<11.7.1-2.20251029134905.e189622.el8
11.7.1-2.20251029134905.e189622.el8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/collectd-sensubility to a version that resolves this vulnerability.

    Fixed in 0.2.1-1.1.el8
  2. Upgrade

    Upgrade redhat/erlang to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  3. Upgrade

    Upgrade redhat/etcd to a version that resolves this vulnerability.

    Fixed in 3.3.23-22.el8
  4. Upgrade

    Upgrade redhat/openstack-cinder to a version that resolves this vulnerability.

    Fixed in 15.6.1-2.20250708154832.299553a.el8
  5. Upgrade

    Upgrade redhat/openstack-glance to a version that resolves this vulnerability.

    Fixed in 19.0.5-2.20260512165254.eb6ad61.el8
  6. Upgrade

    Upgrade redhat/openstack-keystone to a version that resolves this vulnerability.

    Fixed in 16.0.3-2.20260616134936.9d699a7.el8
  7. Upgrade

    Upgrade redhat/openstack-nova to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  8. Upgrade

    Upgrade redhat/openstack-swift to a version that resolves this vulnerability.

    Fixed in 2.23.4-2.20260121154927.70b68db.el8
  9. Upgrade

    Upgrade redhat/openstack-tempest to a version that resolves this vulnerability.

    Fixed in 26.1.0-2.20250728145114.271f820.el8
  10. Upgrade

    Upgrade redhat/openstack-tripleo-common to a version that resolves this vulnerability.

    Fixed in 11.7.1-2.20251029134905.e189622.el8
  11. Upgrade

    Upgrade redhat/openstack-tripleo-heat-templates to a version that resolves this vulnerability.

    Fixed in 11.6.1-2.20251125134914.9adcac6.el8
  12. Upgrade

    Upgrade redhat/puppet-apache to a version that resolves this vulnerability.

    Fixed in 5.1.1-2.20250728133931.1fa9b1c.el8
  13. Upgrade

    Upgrade redhat/puppet-concat to a version that resolves this vulnerability.

    Fixed in 6.1.1-2.20250728133127.9baa8fc.el8
  14. Upgrade

    Upgrade redhat/puppet-corosync to a version that resolves this vulnerability.

    Fixed in 6.0.2-2.20250728134759.961add3.el8
  15. Upgrade

    Upgrade redhat/puppet-datacat to a version that resolves this vulnerability.

    Fixed in 0.6.3-2.20250728140400.5cce8f2.el8
  16. Upgrade

    Upgrade redhat/puppet-firewall to a version that resolves this vulnerability.

    Fixed in 3.4.1-2.20250728144450.94f707c.el8
  17. Upgrade

    Upgrade redhat/puppet-git to a version that resolves this vulnerability.

    Fixed in 0.5.0-2.20250728140843.4e4498e.el8
  18. Upgrade

    Upgrade redhat/puppet-haproxy to a version that resolves this vulnerability.

    Fixed in 4.1.1-2.20250728141134.df96ffc.el8
  19. Upgrade

    Upgrade redhat/puppet-inifile to a version that resolves this vulnerability.

    Fixed in 3.1.1-2.20250728133040.91efced.el8
  20. Upgrade

    Upgrade redhat/puppet-ipaclient to a version that resolves this vulnerability.

    Fixed in 2.5.2-2.20250728141812.b086731.el8
  21. Upgrade

    Upgrade redhat/puppet-java to a version that resolves this vulnerability.

    Fixed in 5.0.2-2.20250804144904.e57cbc8.el8
  22. Upgrade

    Upgrade redhat/puppet-keepalived to a version that resolves this vulnerability.

    Fixed in 0.0.2-2.20250728142002.bbca37a.el8
  23. Upgrade

    Upgrade redhat/puppet-module-data to a version that resolves this vulnerability.

    Fixed in 0.5.1-2.20250728142646.28dafce.el8
  24. Upgrade

    Upgrade redhat/puppet-rabbitmq to a version that resolves this vulnerability.

    Fixed in 10.1.2-2.20250728144344.8b9b006.el8
  25. Upgrade

    Upgrade redhat/puppet-remote to a version that resolves this vulnerability.

    Fixed in 10.0.0-2.20250728135533.7420908.el8
  26. Upgrade

    Upgrade redhat/puppet-snmp to a version that resolves this vulnerability.

    Fixed in 3.9.1-2.20250728142735.5d73485.el8
  27. Upgrade

    Upgrade redhat/puppet-staging to a version that resolves this vulnerability.

    Fixed in 1.0.5-2.20250728134218.b466d93.el8
  28. Upgrade

    Upgrade redhat/puppet-stdlib to a version that resolves this vulnerability.

    Fixed in 6.1.1-2.20250728131928.5aa891c.el8
  29. Upgrade

    Upgrade redhat/puppet-tomcat to a version that resolves this vulnerability.

    Fixed in 3.1.1-2.20250804144904.a3f92d1.el8
  30. Upgrade

    Upgrade redhat/puppet-vcsrepo to a version that resolves this vulnerability.

    Fixed in 3.0.1-2.20250728140014.b06d5d3.el8
  31. Upgrade

    Upgrade redhat/puppet-xinetd to a version that resolves this vulnerability.

    Fixed in 3.3.1-2.20250728135145.d768da2.el8
  32. Upgrade

    Upgrade redhat/python-collectd-gnocchi to a version that resolves this vulnerability.

    Fixed in 1.7.2-2.20250728143604.de115a7.el8
  33. Upgrade

    Upgrade redhat/python-gnocchiclient to a version that resolves this vulnerability.

    Fixed in 7.0.4-2.20250728131928.64814b9.el8
  34. Upgrade

    Upgrade redhat/python-oslo-messaging to a version that resolves this vulnerability.

    Fixed in 10.2.4-2.20260710155333.82281a0.el8
  35. Upgrade

    Upgrade redhat/python-pyasn1 to a version that resolves this vulnerability.

    Fixed in 0.4.6-4.el8
  36. Upgrade

    Upgrade redhat/tripleo-ansible to a version that resolves this vulnerability.

    Fixed in 0.8.1-2.20260112154909.123ce73.el8
  37. Upgrade

    Upgrade redhat/collectd-sensubility-debuginfo to a version that resolves this vulnerability.

    Fixed in 0.2.1-1.1.el8
  38. Upgrade

    Upgrade redhat/erlang-asn1 to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  39. Upgrade

    Upgrade redhat/erlang-asn1-debuginfo to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  40. Upgrade

    Upgrade redhat/erlang-compiler to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  41. Upgrade

    Upgrade redhat/erlang-crypto to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  42. Upgrade

    Upgrade redhat/erlang-crypto-debuginfo to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  43. Upgrade

    Upgrade redhat/erlang-debuginfo to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  44. Upgrade

    Upgrade redhat/erlang-debugsource to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  45. Upgrade

    Upgrade redhat/erlang-eldap to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  46. Upgrade

    Upgrade redhat/erlang-erts to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  47. Upgrade

    Upgrade redhat/erlang-erts-debuginfo to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  48. Upgrade

    Upgrade redhat/erlang-hipe to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  49. Upgrade

    Upgrade redhat/erlang-inets to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  50. Upgrade

    Upgrade redhat/erlang-kernel to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  51. Upgrade

    Upgrade redhat/erlang-mnesia to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  52. Upgrade

    Upgrade redhat/erlang-odbc-debuginfo to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  53. Upgrade

    Upgrade redhat/erlang-parsetools to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  54. Upgrade

    Upgrade redhat/erlang-sasl to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  55. Upgrade

    Upgrade redhat/erlang-snmp to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  56. Upgrade

    Upgrade redhat/erlang-ssl to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  57. Upgrade

    Upgrade redhat/erlang-stdlib to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  58. Upgrade

    Upgrade redhat/erlang-tools to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  59. Upgrade

    Upgrade redhat/erlang-tools-debuginfo to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  60. Upgrade

    Upgrade redhat/erlang-xmerl to a version that resolves this vulnerability.

    Fixed in 23.3.4.18-2.el8
  61. Upgrade

    Upgrade redhat/etcd-debuginfo to a version that resolves this vulnerability.

    Fixed in 3.3.23-22.el8
  62. Upgrade

    Upgrade redhat/etcd-debugsource to a version that resolves this vulnerability.

    Fixed in 3.3.23-22.el8
  63. Upgrade

    Upgrade redhat/openstack-nova-api to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  64. Upgrade

    Upgrade redhat/openstack-nova-common to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  65. Upgrade

    Upgrade redhat/openstack-nova-compute to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  66. Upgrade

    Upgrade redhat/openstack-nova-conductor to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  67. Upgrade

    Upgrade redhat/openstack-nova-console to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  68. Upgrade

    Upgrade redhat/openstack-nova-migration to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  69. Upgrade

    Upgrade redhat/openstack-nova-novncproxy to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  70. Upgrade

    Upgrade redhat/openstack-nova-scheduler to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  71. Upgrade

    Upgrade redhat/openstack-nova-serialproxy to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  72. Upgrade

    Upgrade redhat/openstack-nova-spicehtml5proxy to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  73. Upgrade

    Upgrade redhat/openstack-swift-account to a version that resolves this vulnerability.

    Fixed in 2.23.4-2.20260121154927.70b68db.el8
  74. Upgrade

    Upgrade redhat/openstack-swift-container to a version that resolves this vulnerability.

    Fixed in 2.23.4-2.20260121154927.70b68db.el8
  75. Upgrade

    Upgrade redhat/openstack-swift-object to a version that resolves this vulnerability.

    Fixed in 2.23.4-2.20260121154927.70b68db.el8
  76. Upgrade

    Upgrade redhat/openstack-swift-proxy to a version that resolves this vulnerability.

    Fixed in 2.23.4-2.20260121154927.70b68db.el8
  77. Upgrade

    Upgrade redhat/openstack-tempest-all to a version that resolves this vulnerability.

    Fixed in 26.1.0-2.20250728145114.271f820.el8
  78. Upgrade

    Upgrade redhat/openstack-tripleo-common-container-base to a version that resolves this vulnerability.

    Fixed in 11.7.1-2.20251029134905.e189622.el8
  79. Upgrade

    Upgrade redhat/openstack-tripleo-common-containers to a version that resolves this vulnerability.

    Fixed in 11.7.1-2.20251029134905.e189622.el8
  80. Upgrade

    Upgrade redhat/openstack-tripleo-common-devtools to a version that resolves this vulnerability.

    Fixed in 11.7.1-2.20251029134905.e189622.el8
  81. Upgrade

    Upgrade redhat/python3-cinder to a version that resolves this vulnerability.

    Fixed in 15.6.1-2.20250708154832.299553a.el8
  82. Upgrade

    Upgrade redhat/python3-collectd-gnocchi to a version that resolves this vulnerability.

    Fixed in 1.7.2-2.20250728143604.de115a7.el8
  83. Upgrade

    Upgrade redhat/python3-glance to a version that resolves this vulnerability.

    Fixed in 19.0.5-2.20260512165254.eb6ad61.el8
  84. Upgrade

    Upgrade redhat/python3-gnocchiclient to a version that resolves this vulnerability.

    Fixed in 7.0.4-2.20250728131928.64814b9.el8
  85. Upgrade

    Upgrade redhat/python3-keystone to a version that resolves this vulnerability.

    Fixed in 16.0.3-2.20260616134936.9d699a7.el8
  86. Upgrade

    Upgrade redhat/python3-nova to a version that resolves this vulnerability.

    Fixed in 20.6.2-2.20260317135026.8a24acd.el8
  87. Upgrade

    Upgrade redhat/python3-oslo-messaging to a version that resolves this vulnerability.

    Fixed in 10.2.4-2.20260710155333.82281a0.el8
  88. Upgrade

    Upgrade redhat/python3-pyasn1 to a version that resolves this vulnerability.

    Fixed in 0.4.6-4.el8
  89. Upgrade

    Upgrade redhat/python3-pyasn1-modules to a version that resolves this vulnerability.

    Fixed in 0.4.6-4.el8
  90. Upgrade

    Upgrade redhat/python3-swift to a version that resolves this vulnerability.

    Fixed in 2.23.4-2.20260121154927.70b68db.el8
  91. Upgrade

    Upgrade redhat/python3-tempest to a version that resolves this vulnerability.

    Fixed in 26.1.0-2.20250728145114.271f820.el8
  92. Upgrade

    Upgrade redhat/python3-tempest-tests to a version that resolves this vulnerability.

    Fixed in 26.1.0-2.20250728145114.271f820.el8
  93. Upgrade

    Upgrade redhat/python3-tripleo-common to a version that resolves this vulnerability.

    Fixed in 11.7.1-2.20251029134905.e189622.el8

Event History

Aug 13, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2026:54757?

The severity of RHSA-2026:54757 is rated as important.

2

What types of services are affected by RHSA-2026:54757?

RHSA-2026:54757 affects several Red Hat OpenStack Platform services including OpenStack Cinder, Glance, Keystone, Nova, and Swift.

3

How do I fix RHSA-2026:54757?

To address RHSA-2026:54757, it is recommended to update your Red Hat OpenStack Platform to the latest patched version.

4

What is the main vulnerability addressed in RHSA-2026:54757?

The main vulnerability in RHSA-2026:54757 is a Denial of Service caused by excessive resource consumption.

5

Is there a workaround for RHSA-2026:54757?

Currently, there is no specified workaround for RHSA-2026:54757, and applying the update is required to mitigate the risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203