RHSA-2026:54757
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 security advisory
CVSS Metrics
- v3.1•CRITICAL•Score: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Systems
- redhat•collectd-sensubility
< 0:0.2.1-1.1.el8ost
- redhat•collectd-sensubility-debuginfo
< 0:0.2.1-1.1.el8ost
- redhat•erlang
< 0:23.3.4.18-2.el8ost
- redhat•erlang-asn1
< 0:23.3.4.18-2.el8ost
- redhat•erlang-asn1-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-compiler
< 0:23.3.4.18-2.el8ost
- redhat•erlang-crypto
< 0:23.3.4.18-2.el8ost
- redhat•erlang-crypto-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-debugsource
< 0:23.3.4.18-2.el8ost
- redhat•erlang-eldap
< 0:23.3.4.18-2.el8ost
- redhat•erlang-erl_interface-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-erts
< 0:23.3.4.18-2.el8ost
- redhat•erlang-erts-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-hipe
< 0:23.3.4.18-2.el8ost
- redhat•erlang-inets
< 0:23.3.4.18-2.el8ost
- redhat•erlang-kernel
< 0:23.3.4.18-2.el8ost
- redhat•erlang-mnesia
< 0:23.3.4.18-2.el8ost
- redhat•erlang-odbc-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-os_mon
< 0:23.3.4.18-2.el8ost
- redhat•erlang-os_mon-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-parsetools
< 0:23.3.4.18-2.el8ost
- redhat•erlang-public_key
< 0:23.3.4.18-2.el8ost
- redhat•erlang-runtime_tools
< 0:23.3.4.18-2.el8ost
- redhat•erlang-runtime_tools-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-sasl
< 0:23.3.4.18-2.el8ost
- redhat•erlang-snmp
< 0:23.3.4.18-2.el8ost
- redhat•erlang-ssl
< 0:23.3.4.18-2.el8ost
- redhat•erlang-stdlib
< 0:23.3.4.18-2.el8ost
- redhat•erlang-syntax_tools
< 0:23.3.4.18-2.el8ost
- redhat•erlang-tools
< 0:23.3.4.18-2.el8ost
- redhat•erlang-tools-debuginfo
< 0:23.3.4.18-2.el8ost
- redhat•erlang-xmerl
< 0:23.3.4.18-2.el8ost
- redhat•etcd
< 0:3.3.23-22.el8ost
- redhat•etcd-debuginfo
< 0:3.3.23-22.el8ost
- redhat•etcd-debugsource
< 0:3.3.23-22.el8ost
- redhat•openstack-glance
< 1:19.0.5-2.20260512165254.eb6ad61.el8ost
- redhat•openstack-keystone
< 1:16.0.3-2.20260616134936.9d699a7.el8ost
- redhat•openstack-nova
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-api
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-common
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-compute
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-conductor
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-console
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-migration
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-novncproxy
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-scheduler
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-serialproxy
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•openstack-nova-spicehtml5proxy
< 1:20.6.2-2.20260317135026.8a24acd.el8ost
- redhat•python-oslo-messaging
< 0:10.2.4-2.20260710155333.82281a0.el8ost
Showing first 50 affected entries in server-rendered view.
References (175)
- https://access.redhat.com/errata/RHSA-2026:54757
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2415344
- https://bugzilla.redhat.com/show_bug.cgi?id=2418462
- https://bugzilla.redhat.com/show_bug.cgi?id=2430312
- https://bugzilla.redhat.com/show_bug.cgi?id=2430472
- https://bugzilla.redhat.com/show_bug.cgi?id=2434432
- https://bugzilla.redhat.com/show_bug.cgi?id=2437111
- https://bugzilla.redhat.com/show_bug.cgi?id=2440368
- https://bugzilla.redhat.com/show_bug.cgi?id=2445345
- https://bugzilla.redhat.com/show_bug.cgi?id=2445356
- https://bugzilla.redhat.com/show_bug.cgi?id=2449833
- https://bugzilla.redhat.com/show_bug.cgi?id=2451037
- https://bugzilla.redhat.com/show_bug.cgi?id=2451728
- https://bugzilla.redhat.com/show_bug.cgi?id=2456333
- https://bugzilla.redhat.com/show_bug.cgi?id=2456335
- https://bugzilla.redhat.com/show_bug.cgi?id=2456336
- https://bugzilla.redhat.com/show_bug.cgi?id=2456338
- https://bugzilla.redhat.com/show_bug.cgi?id=2456339
- https://bugzilla.redhat.com/show_bug.cgi?id=2464305
- https://bugzilla.redhat.com/show_bug.cgi?id=2467822
- https://bugzilla.redhat.com/show_bug.cgi?id=2480756
- https://bugzilla.redhat.com/show_bug.cgi?id=2482093
- https://bugzilla.redhat.com/show_bug.cgi?id=2482286
- https://bugzilla.redhat.com/show_bug.cgi?id=2484207
- https://bugzilla.redhat.com/show_bug.cgi?id=2484835
- https://issues.redhat.com/browse/OSPRH-20808
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54757.json
- https://access.redhat.com/security/cve/CVE-2025-61726
- https://www.cve.org/CVERecord?id=CVE-2025-61726
- https://nvd.nist.gov/vuln/detail/CVE-2025-61726
- https://go.dev/cl/736712
- https://go.dev/issue/77101
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
- https://pkg.go.dev/vuln/GO-2026-4341
- https://access.redhat.com/security/cve/CVE-2025-61729
- https://www.cve.org/CVERecord?id=CVE-2025-61729
- https://nvd.nist.gov/vuln/detail/CVE-2025-61729
- https://go.dev/cl/725920
- https://go.dev/issue/76445
- https://groups.google.com/g/golang-announce/c/8FJoBkPddm4
- https://pkg.go.dev/vuln/GO-2025-4155
- https://access.redhat.com/security/cve/CVE-2025-65073
- https://www.cve.org/CVERecord?id=CVE-2025-65073
- https://nvd.nist.gov/vuln/detail/CVE-2025-65073
- https://security.openstack.org/ossa/OSSA-2025-002.html
- https://www.openwall.com/lists/oss-security/2025/11/04/2
- https://access.redhat.com/security/cve/CVE-2025-68121
- https://www.cve.org/CVERecord?id=CVE-2025-68121
- https://nvd.nist.gov/vuln/detail/CVE-2025-68121
- https://go.dev/cl/737700
- https://go.dev/issue/77217
- https://groups.google.com/g/golang-announce/c/K09ubi9FQFk
- https://pkg.go.dev/vuln/GO-2026-4337
- https://access.redhat.com/security/cve/CVE-2026-23490
- https://www.cve.org/CVERecord?id=CVE-2026-23490
- https://nvd.nist.gov/vuln/detail/CVE-2026-23490
- https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq
- https://access.redhat.com/security/cve/CVE-2026-24708
- https://www.cve.org/CVERecord?id=CVE-2026-24708
- https://nvd.nist.gov/vuln/detail/CVE-2026-24708
- https://bugs.launchpad.net/nova/+bug/2137507
- https://access.redhat.com/security/cve/CVE-2026-25679
- https://www.cve.org/CVERecord?id=CVE-2026-25679
- https://nvd.nist.gov/vuln/detail/CVE-2026-25679
- https://go.dev/cl/752180
- https://go.dev/issue/77578
- https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk
- https://pkg.go.dev/vuln/GO-2026-4601
- https://access.redhat.com/security/cve/CVE-2026-27137
- https://www.cve.org/CVERecord?id=CVE-2026-27137
- https://nvd.nist.gov/vuln/detail/CVE-2026-27137
- https://go.dev/cl/752182
- https://go.dev/issue/77952
- https://pkg.go.dev/vuln/GO-2026-4599
- https://access.redhat.com/security/cve/CVE-2026-27145
- https://www.cve.org/CVERecord?id=CVE-2026-27145
- https://nvd.nist.gov/vuln/detail/CVE-2026-27145
- https://go.dev/cl/783621
- https://go.dev/issue/79694
- https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw
- https://pkg.go.dev/vuln/GO-2026-5037
- https://access.redhat.com/security/cve/CVE-2026-32280
- https://www.cve.org/CVERecord?id=CVE-2026-32280
- https://nvd.nist.gov/vuln/detail/CVE-2026-32280
- https://go.dev/cl/758320
- https://go.dev/issue/78282
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://pkg.go.dev/vuln/GO-2026-4947
- https://access.redhat.com/security/cve/CVE-2026-32281
- https://www.cve.org/CVERecord?id=CVE-2026-32281
- https://nvd.nist.gov/vuln/detail/CVE-2026-32281
- https://go.dev/cl/758061
- https://go.dev/issue/78281
- https://pkg.go.dev/vuln/GO-2026-4946
- https://access.redhat.com/security/cve/CVE-2026-32282
- https://www.cve.org/CVERecord?id=CVE-2026-32282
- https://nvd.nist.gov/vuln/detail/CVE-2026-32282
- https://go.dev/cl/763761
- https://go.dev/issue/78293
- https://pkg.go.dev/vuln/GO-2026-4864
- https://access.redhat.com/security/cve/CVE-2026-32283
- https://www.cve.org/CVERecord?id=CVE-2026-32283
- https://nvd.nist.gov/vuln/detail/CVE-2026-32283
- https://go.dev/cl/763767
- https://go.dev/issue/78334
- https://pkg.go.dev/vuln/GO-2026-4870
- https://access.redhat.com/security/cve/CVE-2026-33186
- https://www.cve.org/CVERecord?id=CVE-2026-33186
- https://nvd.nist.gov/vuln/detail/CVE-2026-33186
- https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3
- https://access.redhat.com/security/cve/CVE-2026-33413
- https://www.cve.org/CVERecord?id=CVE-2026-33413
- https://nvd.nist.gov/vuln/detail/CVE-2026-33413
- https://github.com/etcd-io/etcd/security/advisories/GHSA-q8m4-xhhv-38mg
- https://access.redhat.com/security/cve/CVE-2026-33551
- https://www.cve.org/CVERecord?id=CVE-2026-33551
- https://nvd.nist.gov/vuln/detail/CVE-2026-33551
- http://www.openwall.com/lists/oss-security/2026/04/07/12
- https://security.openstack.org/ossa/OSSA-2026-005.html
- https://www.openwall.com/lists/oss-security/2026/04/07/12
- https://access.redhat.com/security/cve/CVE-2026-33810
- https://www.cve.org/CVERecord?id=CVE-2026-33810
- https://nvd.nist.gov/vuln/detail/CVE-2026-33810
- https://go.dev/cl/763763
- https://go.dev/issue/78332
- https://pkg.go.dev/vuln/GO-2026-4866
- https://access.redhat.com/security/cve/CVE-2026-33811
- https://www.cve.org/CVERecord?id=CVE-2026-33811
- https://nvd.nist.gov/vuln/detail/CVE-2026-33811
- https://go.dev/cl/767860
- https://go.dev/issue/78803
- https://groups.google.com/g/golang-announce/c/qcCIEXso47M
- https://pkg.go.dev/vuln/GO-2026-4981
- https://access.redhat.com/security/cve/CVE-2026-34881
- https://www.cve.org/CVERecord?id=CVE-2026-34881
- https://nvd.nist.gov/vuln/detail/CVE-2026-34881
- https://bugs.launchpad.net/glance/+bug/2138602
- https://access.redhat.com/security/cve/CVE-2026-39821
- https://www.cve.org/CVERecord?id=CVE-2026-39821
- https://nvd.nist.gov/vuln/detail/CVE-2026-39821
- https://go.dev/cl/767220
- https://go.dev/issue/78760
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
- https://pkg.go.dev/vuln/GO-2026-5026
- https://access.redhat.com/security/cve/CVE-2026-42789
- https://www.cve.org/CVERecord?id=CVE-2026-42789
- https://nvd.nist.gov/vuln/detail/CVE-2026-42789
- https://cna.erlef.org/cves/CVE-2026-42789.html
- https://github.com/erlang/otp/commit/471cd2f664300a95353c467873800bbe706005db
- https://github.com/erlang/otp/commit/59c8d824386b2eb1614ff9340624843ef6aca0fd
- https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq
- https://osv.dev/vulnerability/EEF-CVE-2026-42789
- https://www.erlang.org/doc/system/versions.html#order-of-versions
- https://access.redhat.com/security/cve/CVE-2026-42790
- https://www.cve.org/CVERecord?id=CVE-2026-42790
- https://nvd.nist.gov/vuln/detail/CVE-2026-42790
- https://cna.erlef.org/cves/CVE-2026-42790.html
- https://github.com/erlang/otp/commit/0769050c69d73762672b0db1347b6993a5b31759
- https://github.com/erlang/otp/commit/21abed64eb2026b5f82f432709e4e932f9be389a
- https://github.com/erlang/otp/commit/fb67c6d1836f51105a96d8b769e71e4215a79457
- https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447
- https://osv.dev/vulnerability/EEF-CVE-2026-42790
- https://access.redhat.com/security/cve/CVE-2026-43001
- https://www.cve.org/CVERecord?id=CVE-2026-43001
- https://nvd.nist.gov/vuln/detail/CVE-2026-43001
- https://bugs.launchpad.net/keystone/+bug/2149775
- https://review.opendev.org/c/openstack/keystone/+/985804
- https://access.redhat.com/security/cve/CVE-2026-44393
- https://www.cve.org/CVERecord?id=CVE-2026-44393
- https://nvd.nist.gov/vuln/detail/CVE-2026-44393
- https://bugs.launchpad.net/oslo.messaging/+bug/2150316
- https://wiki.openstack.org/wiki/OSSN/OSSN-0096