RHSA-2026:54168: Important: rhc-worker-playbook security update
A worker for yggdrasil that receives Ansible playbooks and executes them against the local host.Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: rhc-worker-playbook security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rhc-worker-playbookto a version that resolves this vulnerability.Fixed in 0.2.3-6.el10_0 - Upgrade
Upgrade
redhat/rhc-worker-playbook-debuginfoto a version that resolves this vulnerability.Fixed in 0.2.3-6.el10_0 - Upgrade
Upgrade
redhat/rhc-worker-playbook-debugsourceto a version that resolves this vulnerability.Fixed in 0.2.3-6.el10_0 - Upgrade
Upgrade
redhat/rhc-worker-playbookto a version that resolves this vulnerability.Fixed in 0.2.3-6.el10_0.aa - Upgrade
Upgrade
redhat/rhc-worker-playbook-debuginfoto a version that resolves this vulnerability.Fixed in 0.2.3-6.el10_0.aa - Upgrade
Upgrade
redhat/rhc-worker-playbook-debugsourceto a version that resolves this vulnerability.Fixed in 0.2.3-6.el10_0.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54168?
The severity of RHSA-2026:54168 is rated as high with a score of 7.
What security vulnerabilities are addressed in RHSA-2026:54168?
RHSA-2026:54168 addresses Denial of Service vulnerabilities in the golang net package and the golang crypto/x509 library.
How do I fix RHSA-2026:54168?
To fix RHSA-2026:54168, you should update the affected packages for rhc-worker-playbook as recommended by Red Hat.
Which software is affected by RHSA-2026:54168?
The affected software includes redhat/rhc-worker-playbook and its related debug packages on supported Red Hat Enterprise Linux systems.
What are the potential impacts of not addressing RHSA-2026:54168?
Failing to address RHSA-2026:54168 could lead to Denial of Service attacks, impacting the availability of systems using the affected packages.