Red Hat rhc Updates Address Four Go Security Flaws on RHEL for SAP
Quick Answer
Red Hat published RHSA-2026:69105 and RHSA-2026:69104 for rhc builds on RHEL 9.4 and 9.2 Update Services for SAP Solutions. Four bundled Go component flaws can cause denial of service or cross-site scripting; official scores are 7.5 or 8.1 High.
Match The rhc Package To The SAP E4S Stream
What to do now: Identify RHEL for SAP systems with rhc, distinguish the 9.2 and 9.4 E4S streams, install the correct Red Hat build, and validate package state, registration, remote-management, and application behavior.
Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.
Scope And Authority
| Product scope | rhc on RHEL 9.4 and 9.2 Update Services for SAP Solutions |
|---|---|
| Advisory | RHSA-2026:69105 / RHSA-2026:69104 |
| CVEs | CVE-2026-33818, CVE-2026-56858, CVE-2026-56860, CVE-2026-56862 |
| Authoritative release date | RHSA-2026:69105 at 2026-09-21 03:08:41 UTC; RHSA-2026:69104 at 03:08:53 UTC |
| Authority revision date | 2026-09-21 03:10:39 UTC for both advisories |
| Affected versions | Entitled RHEL 9.4 and 9.2 E4S rhc streams before the advisory-listed builds |
| Fixed version | rhc 0.2.4-9.el9_4.1 (RHEL 9.4) / 0.2.2-1.el9_2.5 (RHEL 9.2) |
| CVSS base score | 7.5 / 8.1 / 7.5 / 7.5 (CVSS v3.1) |
| CVSS severity | High |
| Exploitation status | Not stated by Red Hat; no exploitation claim is inferred. |
What Changed
The update rebuilds rhc components for four Go vulnerabilities: ASN.1 recursive parsing denial of service, html/template cross-site scripting, quadratic net/url parsing, and TLS KeyUpdate denial of service. Red Hat provides branch-specific package builds; the advisory does not assert that each code path is reachable in every rhc deployment.
What To Validate Now
- Inventory. Locate entitled RHEL 9.2 and 9.4 Update Services for SAP Solutions systems with the rhc client or daemon and record registration and management roles.
- Establish applicability. Match each host to its E4S AppStream and installed rhc NVR; review whether affected ASN.1, URL, TLS, or HTML templating paths are reachable in local workflows.
- Remediate. Install rhc 0.2.2-1.el9_2.5 on the 9.2 stream or 0.2.4-9.el9_4.1 on the 9.4 stream, or a supported superseding package from Red Hat.
- Validate. Confirm the resulting NVR, rhc service and registration health, remote-management operations, SAP workload checks, logs, and rollback readiness.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Do not cross-install the 9.2 and 9.4 E4S packages. Coordinate validation with SAP and systems-management owners, and separate component severity from demonstrated exposure in the deployed rhc workflow.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

