RHSA-2026:66401
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat OpenStack Platform 17.1 security and bug fix advisory
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Systems
- redhat•ansible-collection-ansible-posix
< 0:1.2.0-1.4.el9ost
- redhat•ansible-collections-openstack
< 0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost
- redhat•collectd-sensubility
< 0:0.2.1-6.el9ost
- redhat•collectd-sensubility-debuginfo
< 0:0.2.1-6.el9ost
- redhat•erlang
< 0:24.3.4.2-7.el9ost
- redhat•erlang-asn1
< 0:24.3.4.2-7.el9ost
- redhat•erlang-asn1-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-compiler
< 0:24.3.4.2-7.el9ost
- redhat•erlang-crypto
< 0:24.3.4.2-7.el9ost
- redhat•erlang-crypto-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-debugsource
< 0:24.3.4.2-7.el9ost
- redhat•erlang-eldap
< 0:24.3.4.2-7.el9ost
- redhat•erlang-erl_interface-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-erts
< 0:24.3.4.2-7.el9ost
- redhat•erlang-erts-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-inets
< 0:24.3.4.2-7.el9ost
- redhat•erlang-kernel
< 0:24.3.4.2-7.el9ost
- redhat•erlang-mnesia
< 0:24.3.4.2-7.el9ost
- redhat•erlang-odbc-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-os_mon
< 0:24.3.4.2-7.el9ost
- redhat•erlang-os_mon-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-parsetools
< 0:24.3.4.2-7.el9ost
- redhat•erlang-public_key
< 0:24.3.4.2-7.el9ost
- redhat•erlang-runtime_tools
< 0:24.3.4.2-7.el9ost
- redhat•erlang-runtime_tools-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-sasl
< 0:24.3.4.2-7.el9ost
- redhat•erlang-snmp
< 0:24.3.4.2-7.el9ost
- redhat•erlang-ssl
< 0:24.3.4.2-7.el9ost
- redhat•erlang-stdlib
< 0:24.3.4.2-7.el9ost
- redhat•erlang-syntax_tools
< 0:24.3.4.2-7.el9ost
- redhat•erlang-tools
< 0:24.3.4.2-7.el9ost
- redhat•erlang-tools-debuginfo
< 0:24.3.4.2-7.el9ost
- redhat•erlang-xmerl
< 0:24.3.4.2-7.el9ost
- redhat•etcd
< 0:3.4.26-9.6.el9ost
- redhat•etcd-debuginfo
< 0:3.4.26-9.6.el9ost
- redhat•etcd-debugsource
< 0:3.4.26-9.6.el9ost
- redhat•octavia-amphora-image-fips-x86_64
< 0:17.1-20260901.1.el9ost
- redhat•octavia-amphora-image-x86_64
< 0:17.1-20260901.1.el9ost
- redhat•openstack-cinder
< 1:18.2.2-17.1.20260702111621.f6b44fc.el9ost
- redhat•openstack-dashboard
< 1:19.4.1-17.1.20260630130603.9b1a13e.el9ost
- redhat•openstack-heat
< 1:16.1.1-17.1.20260713101101.edc6d60.el9ost
- redhat•openstack-heat-api
< 1:16.1.1-17.1.20260713101101.edc6d60.el9ost
- redhat•openstack-heat-api-cfn
< 1:16.1.1-17.1.20260713101101.edc6d60.el9ost
- redhat•openstack-heat-common
< 1:16.1.1-17.1.20260713101101.edc6d60.el9ost
- redhat•openstack-heat-engine
< 1:16.1.1-17.1.20260713101101.edc6d60.el9ost
- redhat•openstack-heat-monolith
< 1:16.1.1-17.1.20260713101101.edc6d60.el9ost
- redhat•openstack-ironic
< 1:17.1.1-17.1.20260721220909.c31db88.el9ost
- redhat•openstack-ironic-api
< 1:17.1.1-17.1.20260721220909.c31db88.el9ost
- redhat•openstack-ironic-common
< 1:17.1.1-17.1.20260721220909.c31db88.el9ost
Showing first 50 affected entries in server-rendered view.
References (62)
- https://access.redhat.com/errata/RHSA-2026:66401
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2430312
- https://bugzilla.redhat.com/show_bug.cgi?id=2434432
- https://bugzilla.redhat.com/show_bug.cgi?id=2437111
- https://bugzilla.redhat.com/show_bug.cgi?id=2445356
- https://bugzilla.redhat.com/show_bug.cgi?id=2456336
- https://bugzilla.redhat.com/show_bug.cgi?id=2456338
- https://bugzilla.redhat.com/show_bug.cgi?id=2456339
- https://issues.redhat.com/browse/OSPRH-19640
- https://issues.redhat.com/browse/OSPRH-23919
- https://issues.redhat.com/browse/OSPRH-25386
- https://issues.redhat.com/browse/OSPRH-25720
- https://issues.redhat.com/browse/OSPRH-25998
- https://issues.redhat.com/browse/OSPRH-26003
- https://issues.redhat.com/browse/OSPRH-29196
- https://issues.redhat.com/browse/OSPRH-31915
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66401.json
- https://access.redhat.com/security/cve/CVE-2025-61726
- https://www.cve.org/CVERecord?id=CVE-2025-61726
- https://nvd.nist.gov/vuln/detail/CVE-2025-61726
- https://go.dev/cl/736712
- https://go.dev/issue/77101
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
- https://pkg.go.dev/vuln/GO-2026-4341
- https://access.redhat.com/security/cve/CVE-2025-68121
- https://www.cve.org/CVERecord?id=CVE-2025-68121
- https://nvd.nist.gov/vuln/detail/CVE-2025-68121
- https://go.dev/cl/737700
- https://go.dev/issue/77217
- https://groups.google.com/g/golang-announce/c/K09ubi9FQFk
- https://pkg.go.dev/vuln/GO-2026-4337
- https://access.redhat.com/security/cve/CVE-2026-24708
- https://www.cve.org/CVERecord?id=CVE-2026-24708
- https://nvd.nist.gov/vuln/detail/CVE-2026-24708
- https://bugs.launchpad.net/nova/+bug/2137507
- https://access.redhat.com/security/cve/CVE-2026-25679
- https://www.cve.org/CVERecord?id=CVE-2026-25679
- https://nvd.nist.gov/vuln/detail/CVE-2026-25679
- https://go.dev/cl/752180
- https://go.dev/issue/77578
- https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk
- https://pkg.go.dev/vuln/GO-2026-4601
- https://access.redhat.com/security/cve/CVE-2026-32280
- https://www.cve.org/CVERecord?id=CVE-2026-32280
- https://nvd.nist.gov/vuln/detail/CVE-2026-32280
- https://go.dev/cl/758320
- https://go.dev/issue/78282
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://pkg.go.dev/vuln/GO-2026-4947
- https://access.redhat.com/security/cve/CVE-2026-32282
- https://www.cve.org/CVERecord?id=CVE-2026-32282
- https://nvd.nist.gov/vuln/detail/CVE-2026-32282
- https://go.dev/cl/763761
- https://go.dev/issue/78293
- https://pkg.go.dev/vuln/GO-2026-4864
- https://access.redhat.com/security/cve/CVE-2026-32283
- https://www.cve.org/CVERecord?id=CVE-2026-32283
- https://nvd.nist.gov/vuln/detail/CVE-2026-32283
- https://go.dev/cl/763767
- https://go.dev/issue/78334
- https://pkg.go.dev/vuln/GO-2026-4870