Red Hat Fixes mod_auth_openidc on RHEL 10

P1 — VALIDATE AND UPDATEHigh · 7.5 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:75581 for RHEL 10 mod_auth_openidc packages. Match entitled systems to the advisory scope, install mod_auth_openidc 2.4.16.11-1.el10_2.1, validate dependent operations, and retain change evidence.

Validate mod_auth_openidc Scope And Apply The Red Hat Fix

What to do now: Inventory RHEL 10 mod_auth_openidc packages, confirm the exact entitled branch and installed build, apply the advisory-listed content, validate representative services, and document exceptions.

Open the authoritative advisory

Last verified: 2026-10-05 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeRHEL 10 mod_auth_openidc packages
AdvisoryRHSA-2026:75581
CVECVE-2026-54789
Authoritative release date2026-10-05 05:14:24 UTC
Authority revision date2026-10-05 10:49:01 UTC
Affected versionsThe supported RHEL 10 mod_auth_openidc packages builds identified as affected in the advisory product-status relationships.
Fixed versionmod_auth_openidc 2.4.16.11-1.el10_2.1
CVSS base score7.5 (CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Red Hat published supported mod_auth_openidc replacement content for the advisory-listed CVEs and product branches.

What To Validate Now

  1. Inventory. Locate RHEL 10 mod_auth_openidc packages; record the installed build, repository and entitlement, owner, exposure, dependencies, and maintenance group.
  2. Establish applicability. Compare every system with the product and package relationships in RHSA-2026:75581. Do not infer applicability from the component name or CVSS rating alone.
  3. Remediate. Install mod_auth_openidc 2.4.16.11-1.el10_2.1 from the supported Red Hat channel for the exact branch.
  4. Validate. Confirm the installed package or image digest, exercise representative mod_auth_openidc functions and recovery paths, monitor for regressions, and record the result.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Test OpenID Connect login, logout, callback, session, and proxy behavior with a rollback path before broad deployment. Preserve pre-change versions, logs, installation output, validation evidence, and any rollback decision.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.