RHSA-2026:0677HighCVSS 8.8
Red Hat Security Advisory: OpenShift Container Platform 4.13.63 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-8677 — bind: Resource exhaustion via malformed DNSKEY handling CVE-2025-9714 — libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c CVE-2025-11561 — sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs CVE-2025-40780 — bind: Cache poisoning due to weak PRNG CVE-2025-59375 — firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:0677
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392605
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2395108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2402727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405827
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405830
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0677.json