RHSA-2026:0406CriticalCVSS 9.3

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Container Release Update

Published
January 8, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-68664 — langchain-core: LangChain: Arbitrary code execution via serialization injection

🎯 Affected products7

  • Red Hat Ansible Automation Platform 2.4
  • registry.redhat.io/ansible-automation-platform-24/lightspeed-rhel8@sha256:0bb8228df7b60eb4bb4380fab098600ce5016702ca28972f5f94849bb87754d4_amd64 as a component of Red Hat Ansible Automation Platform 2.4
  • registry.redhat.io/ansible-automation-platform-24/lightspeed-rhel8@sha256:a1f1aafd41f628d0e7d2e4a8cab367a390619b1b21594c99932bc1b3fb18f94d_arm64 as a component of Red Hat Ansible Automation Platform 2.4
  • registry.redhat.io/ansible-automation-platform-24/lightspeed-rhel8@sha256:c119e0c4cb1cca9081a30abfec209ae540e8966645c2815703390a654993fe3c_ppc64le as a component of Red Hat Ansible Automation Platform 2.4
  • registry.redhat.io/ansible-automation-platform-24/lightspeed-rhel8@sha256:dc488fda76effe0b112c876d1cd22dda60c3296afb268379675243a539e04941_s390x as a component of Red Hat Ansible Automation Platform 2.4
  • registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:876e816eff5c92c30026a2ff2eea045b91b7cda01ee949f081d6c3b9a33e32fd_amd64 as a component of Red Hat Ansible Automation Platform 2.4
  • registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:ef1ca7ef90b6fadc5cd9a5a8bac1d0fe29b78514cba562413961a567c84f615d_amd64 as a component of Red Hat Ansible Automation Platform 2.4

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.4#Installation%20and%20upgrade

🔗 References (5)