RHSA-2026:38504HighCVSS 7.5

Red Hat Security Advisory: container-tools:rhel8 security update

Published
July 13, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-57231 — podman: Podman: Information disclosure via malicious container image environment variables

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 8)
  • aardvark-dns-2:1.10.1-2.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • aardvark-dns-2:1.10.1-2.module+el8.10.0+24510+6ea3880e.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • aardvark-dns-2:1.10.1-2.module+el8.10.0+24510+6ea3880e.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • aardvark-dns-2:1.10.1-2.module+el8.10.0+24510+6ea3880e.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • aardvark-dns-2:1.10.1-2.module+el8.10.0+24510+6ea3880e.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debugsource-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debugsource-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debugsource-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-debugsource-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • buildah-tests-debuginfo-2:1.33.14-4.module+el8.10.0+24510+6ea3880e.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • cockpit-podman-0:84.1-1.module+el8.10.0+24510+6ea3880e.noarch (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • cockpit-podman-0:84.1-1.module+el8.10.0+24510+6ea3880e.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • conmon-3:2.1.10-1.module+el8.10.0+24510+6ea3880e.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)