RHSA-2026:8322: Critical: rhc security update
Critical: rhc security update
Other sources
rhc is a client tool and daemon that connects the system to Red Hat hosted services enabling system and subscription management.Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:8322?
The severity of RHSA-2026:8322 is classified as critical.
How do I fix RHSA-2026:8322?
You can fix RHSA-2026:8322 by updating the 'rhc' package to version 0.2.2-1.el9_2.2 or later.
What is the main vulnerability addressed in RHSA-2026:8322?
RHSA-2026:8322 addresses a security issue with rapid stream resets in golang's net/http and x/net/http2.
Which systems are affected by RHSA-2026:8322?
RHSA-2026:8322 affects multiple Red Hat Enterprise Linux versions including IBM z Systems, ARM 64, and x86_64.
Is there a workaround for RHSA-2026:8322?
No specific workarounds are provided for RHSA-2026:8322; updating to the fixed version is recommended.