Red Hat rhc Updates Address Four Go Security Flaws on RHEL for SAP

P1 — VALIDATE AND UPDATEHigh · 7.5 / 8.1 / 7.5 / 7.5 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:69105 and RHSA-2026:69104 for rhc builds on RHEL 9.4 and 9.2 Update Services for SAP Solutions. Four bundled Go component flaws can cause denial of service or cross-site scripting; official scores are 7.5 or 8.1 High.

Match The rhc Package To The SAP E4S Stream

What to do now: Identify RHEL for SAP systems with rhc, distinguish the 9.2 and 9.4 E4S streams, install the correct Red Hat build, and validate package state, registration, remote-management, and application behavior.

Open the authoritative advisory

Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.

Scope And Authority

Product scoperhc on RHEL 9.4 and 9.2 Update Services for SAP Solutions
AdvisoryRHSA-2026:69105 / RHSA-2026:69104
CVEsCVE-2026-33818, CVE-2026-56858, CVE-2026-56860, CVE-2026-56862
Authoritative release dateRHSA-2026:69105 at 2026-09-21 03:08:41 UTC; RHSA-2026:69104 at 03:08:53 UTC
Authority revision date2026-09-21 03:10:39 UTC for both advisories
Affected versionsEntitled RHEL 9.4 and 9.2 E4S rhc streams before the advisory-listed builds
Fixed versionrhc 0.2.4-9.el9_4.1 (RHEL 9.4) / 0.2.2-1.el9_2.5 (RHEL 9.2)
CVSS base score7.5 / 8.1 / 7.5 / 7.5 (CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by Red Hat; no exploitation claim is inferred.

What Changed

The update rebuilds rhc components for four Go vulnerabilities: ASN.1 recursive parsing denial of service, html/template cross-site scripting, quadratic net/url parsing, and TLS KeyUpdate denial of service. Red Hat provides branch-specific package builds; the advisory does not assert that each code path is reachable in every rhc deployment.

What To Validate Now

  1. Inventory. Locate entitled RHEL 9.2 and 9.4 Update Services for SAP Solutions systems with the rhc client or daemon and record registration and management roles.
  2. Establish applicability. Match each host to its E4S AppStream and installed rhc NVR; review whether affected ASN.1, URL, TLS, or HTML templating paths are reachable in local workflows.
  3. Remediate. Install rhc 0.2.2-1.el9_2.5 on the 9.2 stream or 0.2.4-9.el9_4.1 on the 9.4 stream, or a supported superseding package from Red Hat.
  4. Validate. Confirm the resulting NVR, rhc service and registration health, remote-management operations, SAP workload checks, logs, and rollback readiness.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Do not cross-install the 9.2 and 9.4 E4S packages. Coordinate validation with SAP and systems-management owners, and separate component severity from demonstrated exposure in the deployed rhc workflow.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.