RHSA-2026:54191: Important: rhc-worker-script security update
Important: rhc-worker-script security update
Other sources
Remote Host Configuration (rhc) worker for executing scripts on hosts managed by Red Hat Lightspeed.Security Fix(es): net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rhc-worker-scriptto a version that resolves this vulnerability.Fixed in 0.11-1.el7_9
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54191?
The severity of RHSA-2026:54191 is classified as high (7).
What security issues does RHSA-2026:54191 address?
RHSA-2026:54191 addresses incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) among other issues.
How do I fix RHSA-2026:54191?
To fix RHSA-2026:54191, apply the latest security update for the rhc-worker-script package provided by Red Hat.
What systems are affected by RHSA-2026:54191?
RHSA-2026:54191 affects systems running Red Hat Enterprise Linux Server - Extended Life Cycle Support with the rhc-worker-script package.
When was RHSA-2026:54191 published?
RHSA-2026:54191 was published on August 12, 2026.