Red Hat has issued a broad set of Important security advisories for container-focused packages including podman, buildah, skopeo, runc, and containernetworking-plugins across RHEL 8, 9, and 10, fixing denial-of-service flaws inherited from Go libraries. The recurring issues include CVE-2026-32280, CVE-2026-32281, and CVE-2026-32283, which affect certificate chain building and validation in crypto/x509 and TLS 1.3 key update handling in crypto/tls; several advisories also include CVE-2026-25679 in net/url and CVE-2026-34986 in go-jose. Updated packages were released for multiple architectures and support channels, including standard, SAP, AUS, EUS, and Extended Life Cycle variants.
The updates follow earlier tracking of Go certificate-processing weaknesses, including CVE-2025-61729, a high-severity crypto/x509 denial-of-service bug in HostnameError.Error() that can be triggered by a crafted certificate to drive excessive CPU and memory consumption through unbounded host printing and quadratic string concatenation. Red Hat’s bug record linked that flaw to remediation across a wide range of products beyond container tooling, including Red Hat Enterprise Linux 7 through 10, OpenShift, Ansible Automation Platform, Ceph Storage, Satellite, OpenStack offerings, Cryostat, and Streams for Apache Kafka, underscoring the broad downstream impact of Go security defects on enterprise platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
26 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:37410 for buildah on RHEL 9.8 channels, releasing buildah version 1.43.1-3.el9_8 for multiple architectures. The advisory fixes CVE-2026-39835, a crafted-SSH-certificate denial of service in golang.org/x/crypto/ssh, and CVE-2026-39832, a security bypass in golang.org/x/crypto/ssh/agent.
Red Hat published RHSA-2026:25253 for runc in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related AUS, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go-related vulnerabilities. The update provided runc version 1.2.9-1.el9_2.2 for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:25250 for skopeo in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 AUS, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with several other Go-component vulnerabilities. The update provided skopeo version 1.11.4-0.1.el9_2.6 for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:25252 for buildah in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 channels, addressing CVE-2025-61729 along with several other Go-component vulnerabilities. The update provided buildah version 1.29.7-1.el9_2.5 for multiple architectures.
Red Hat published RHSA-2026:20608 for containernetworking-plugins on RHEL 9.6 channels, releasing version 1.6.2-3.el9_6.1 across x86_64, aarch64, ppc64le, and s390x. The advisory fixes Go-related denial-of-service flaws including CVE-2026-32283 and CVE-2026-32280, and also lists CVE-2026-32281.
Red Hat published RHSA-2026:20609 for skopeo in RHEL 9.6 channels, releasing version 1.18.1-5.el9_6.1 for x86_64, aarch64, ppc64le, and s390x. The advisory fixes multiple Go-related denial-of-service flaws including CVE-2026-34986, CVE-2026-32283, and CVE-2026-32280.
Red Hat published RHSA-2026:20607 for buildah on RHEL 9.6 channels, releasing buildah version 1.39.9-1.el9_6 across multiple architectures. The advisory fixes multiple Go-related denial-of-service flaws including CVE-2026-34986, CVE-2026-32283, CVE-2026-32280, and also lists CVE-2026-32281.
Red Hat's Bugzilla record 2480680 for CVE-2026-39835 was reported by OSIDB Bzimport and classified as a high-severity vulnerability. The bug tracks a denial-of-service flaw in golang.org/x/crypto/ssh where a crafted SSH certificate can panic affected servers using CertChecker without IsUserAuthority or IsHostAuthority set.
Red Hat's Bugzilla record 2480685 for CVE-2026-39832 was reported by OSIDB Bzimport and classified as a high-severity vulnerability. The bug tracks a security bypass in golang.org/x/crypto/ssh/agent where key restriction extensions were not serialized, allowing destination restrictions to be stripped during agent forwarding.
Red Hat issued RHSA-2026:19634 for the container-tools:rhel8 module on RHEL 8.6 channels, fixing CVE-2025-61729 along with multiple other Go vulnerabilities. The update covered packages including podman, buildah, skopeo, and runc.
Red Hat published RHSA-2026:16696 for skopeo on RHEL 10.0 Extended Update Support and related 4-year update channels, addressing CVE-2025-61729 along with several other Go vulnerabilities. The update provided skopeo version 1.18.1-3.el10_0.1 for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:16102 for buildah in RHEL 9.0 Update Services for SAP Solutions, addressing CVE-2025-61729 and several other Go-component flaws. Updated buildah 1.26.11-1.el9_0 packages were released for x86_64, ppc64le, aarch64, and s390x.
Red Hat published RHSA-2026:14868 for buildah on RHEL 10.0 Extended Update Support and 4-year update/support channels, addressing CVE-2025-61729 along with several other Go vulnerabilities. The update provided buildah version 1.39.8-1.el10_0 for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:12032 for containernetworking-plugins in RHEL 9.4 Extended Update Support and related AUS, SAP, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go vulnerabilities. The update provided containernetworking-plugins version 1.4.0-6.el9_4.3 for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:12031 for runc in RHEL 9.4 Extended Update Support and related AUS, SAP, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go vulnerabilities. The update provided runc version 1.2.9-1.el9_4.1 for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:12030 for buildah in RHEL 9.4 Extended Update Support and related AUS, SAP, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go vulnerabilities. The update provided buildah version 1.33.13-3.el9_4.1 for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:12029 for skopeo in RHEL 9.4 Extended Update Support and related SAP, AUS, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go vulnerabilities. The update provided skopeo version 1.14.5-2.el9_4.4 for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:11749 for buildah on RHEL 9.6 channels, including a fix for CVE-2025-61729 alongside other Go vulnerabilities. The updated buildah package version was 1.39.6-2.el9_6 across multiple architectures and service channels.
Red Hat published RHSA-2026:9097 for runc in RHEL 9.6 Extended Update Support and related AUS, SAP, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go vulnerabilities. The update provided runc version 1.2.9-3.el9_6 for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:9098 for skopeo on RHEL 9.6 Extended Update Support and related AUS, SAP, 4-year update, and Extended Life Cycle channels, addressing CVE-2025-61729 along with other Go vulnerabilities. The update provided skopeo version 1.18.1-5.el9_6 for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:3340 for skopeo on RHEL 9.8-related RHEL 9 channels, addressing CVE-2025-61729 along with CVE-2025-61726 and CVE-2025-68121. The update released skopeo version 1.20.0-3.el9_7 for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:3297 for buildah on RHEL 10 channels, addressing CVE-2025-61729 along with CVE-2025-61726 and CVE-2025-68121. The update released buildah version 1.41.8-2.el10_1 for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:3298 for buildah on RHEL 9.8-related RHEL 9 support channels, addressing CVE-2025-61729 along with CVE-2025-61726 and CVE-2025-68121. The update released buildah version 1.41.8-2.el9_7 for x86_64, s390x, ppc64le, and aarch64.
Red Hat's Bugzilla record 2437111 for CVE-2025-68121 was reported by OSIDB Bzimport and classified as a medium-severity vulnerability. The bug tracks an incorrect certificate validation flaw in Go's crypto/tls during TLS session resumption when ClientCAs or RootCAs are changed between the initial and resumed handshakes.
Red Hat's Bugzilla record 2434432 for CVE-2025-61726 was reported by OSIDB Bzimport and classified as a high-severity vulnerability. The bug tracks a Go net/url memory exhaustion flaw caused by unbounded query parameter parsing that can lead to excessive memory consumption when large URL-encoded forms are processed.
Red Hat's Bugzilla record 2418462 for CVE-2025-61729 was reported by OSIDB Bzimport. The bug tracks a high-severity Go crypto/x509 denial-of-service flaw caused by excessive resource consumption when processing a crafted certificate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
39 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.