RHSA-2026:54883: Important: Red Hat build of MicroShift 4.19.43 security update
Important: Red Hat build of MicroShift 4.19.43 security update
Other sources
Red Hat build of MicroShift is Red Hat's light-weight Kubernetesorchestration solution designed for edge device deployments and is builtfrom the edge capabilities of Red Hat OpenShift Container Platform.MicroShift is an application that is deployed on top of Red Hat EnterpriseLinux devices at the edge, providing an efficient way to operatesingle-node clusters in these low-resource environments.This advisory contains the RPM packages for Red Hat build of MicroShift4.19.43. Read the following advisory for the container images for thisrelease:https://access.redhat.com/errata/RHSA-2026:54555 Security Fix(es): net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)All Red Hat build of MicroShift 4.19 users are advised to use these updatedpackages and images when they are available in the RPM repository.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/microshiftto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-ai-model-servingto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-ai-model-serving-release-infoto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-gateway-apito a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-gateway-api-release-infoto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-greenbootto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-low-latencyto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-multusto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-multus-release-infoto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-networkingto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-observabilityto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-olmto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-olm-release-infoto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-release-infoto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshift-selinuxto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9 - Upgrade
Upgrade
redhat/microshiftto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9.aa - Upgrade
Upgrade
redhat/microshift-gateway-apito a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9.aa - Upgrade
Upgrade
redhat/microshift-multusto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9.aa - Upgrade
Upgrade
redhat/microshift-networkingto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9.aa - Upgrade
Upgrade
redhat/microshift-olmto a version that resolves this vulnerability.Fixed in 4.19.43-202608141837.p0.gcd3decf.assembly.4.19.43.el9.aa - Upgrade
Upgrade
MicroShift 4.19to a version that resolves this vulnerability.Fixed in 4.19.43Patch RHSA-2026:54555 - Compensating control
After applying the RHSA-2026:54555 update for MicroShift 4.19.43, ensure you are using the updated container images provided in the advisory (for Go net/mail DoS via crafted email inputs, CVE-2026-39820) from the available RPM repository/errata contents.
Event History
Frequently Asked Questions
Which deployments should be prioritized for this update?
Deployments running Red Hat build of MicroShift 4.19 should be prioritized. The advisory recommends updating the RPM packages and associated images when they become available in the RPM repository.
What condition is required to trigger the reported vulnerability?
The documented issue is a denial of service in Go's net/mail component caused by crafted email inputs. The advisory does not provide further details about the affected MicroShift component, exposure path, or required attacker access.
What should be updated besides the RPM packages?
The advisory states that container images for this release are covered by a separate advisory, RHSA-2026:54555. Update both the available MicroShift RPM packages and the corresponding release images.