{"id":"RHSA-2026:66561","summary":"Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update","modified":"2026-09-23T10:14:02Z","published":"2026-09-22T10:18:14Z","related":["GO-2026-4978","GO-2026-4979","GO-2026-5015","GO-2026-5016","GO-2026-5020","GO-2026-5027","GO-2026-5030","GO-2026-5031","GO-2026-5033"],"upstream":["CVE-2026-27136","CVE-2026-39817","CVE-2026-39819","CVE-2026-39827","CVE-2026-39834","CVE-2026-39835","CVE-2026-42500","CVE-2026-42502","CVE-2026-46598"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66561"},{"type":"ARTICLE","url":"https://images.redhat.com/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42500"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-46598"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42502"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-39835"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-39834"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-39827"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-27136"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-39817"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-39819"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66561.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480757"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-27136"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27136"},{"type":"ARTICLE","url":"https://go.dev/cl/781685"},{"type":"ARTICLE","url":"https://go.dev/issue/79575"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5030"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467825"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-39817"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39817"},{"type":"ARTICLE","url":"https://go.dev/cl/767520"},{"type":"ARTICLE","url":"https://go.dev/issue/78778"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/qcCIEXso47M"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-4979"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467813"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-39819"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39819"},{"type":"ARTICLE","url":"https://go.dev/cl/763882"},{"type":"ARTICLE","url":"https://go.dev/issue/78584"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-4978"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480682"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-39827"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39827"},{"type":"ARTICLE","url":"https://go.dev/cl/781320"},{"type":"ARTICLE","url":"https://go.dev/issue/35127"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/a082jnz-LvI"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5016"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480676"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-39834"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39834"},{"type":"ARTICLE","url":"https://go.dev/cl/781663"},{"type":"ARTICLE","url":"https://go.dev/issue/79567"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5020"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480680"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-39835"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39835"},{"type":"ARTICLE","url":"https://go.dev/cl/781660"},{"type":"ARTICLE","url":"https://go.dev/issue/79563"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5015"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483431"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42500"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42500"},{"type":"ARTICLE","url":"https://go.dev/cl/781500"},{"type":"ARTICLE","url":"https://go.dev/issue/79576"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/uhYX90BlBvI"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5031"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480762"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42502"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42502"},{"type":"ARTICLE","url":"https://go.dev/cl/781701"},{"type":"ARTICLE","url":"https://go.dev/issue/79572"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5027"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480679"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-46598"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46598"},{"type":"ARTICLE","url":"https://go.dev/cl/781360"},{"type":"ARTICLE","url":"https://go.dev/issue/79596"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5033"}],"affected":[{"package":{"name":"golang1.27","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/golang1.27"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.27.1-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:66561.json"}},{"package":{"name":"golang1.27-bin","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/golang1.27-bin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.27.1-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:66561.json"}},{"package":{"name":"golang1.27-docs","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/golang1.27-docs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.27.1-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:66561.json"}},{"package":{"name":"golang1.27-misc","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/golang1.27-misc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.27.1-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:66561.json"}},{"package":{"name":"golang1.27-src","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/golang1.27-src"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.27.1-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:66561.json"}},{"package":{"name":"golang1.27-tests","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/golang1.27-tests"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.27.1-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:66561.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}