- Issued:
- 2026-07-08
- Updated:
- 2026-07-08
RHSA-2026:36796 - Important: Red Hat Edge Manager Version 1.0.3 Security Update
Synopsis
Important: Red Hat Edge Manager Version 1.0.3 Security Update
Type/Severity
Security Advisory Important
Topic
Red Hat Edge Manager Version 1.0.3 Security Update
Description
Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes.
RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms:
Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation.
This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors.
Value for customers and partners:
- This solution not only helps customers manage thousands of devices but helps scale operations.
- To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics.
- Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices.
This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location.
Security fixes:
- golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
- golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)
- golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
- golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions (CVE-2026-39828)
- golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)
- golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
- golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
- golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
- Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
- Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
- Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
- Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
- Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
- Go crypto/x509: Incorrect enforcement of email constraints (CVE-2026-27137)
- Go net/url: Incorrect parsing of IPv6 host literals (CVE-2026-25679)
- golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
- github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815)
- github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816)
- gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
- Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
- Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
- Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
- Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469)
Solution
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.0
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Edge Manager | 1.0 | x86_64 |
| Red Hat Edge Manager | 1.0 | s390x |
| Red Hat Edge Manager | 1.0 | ppc64le |
| Red Hat Edge Manager | 1.0 | aarch64 |
Updated Packages
- flightctl-cli-1.0.3-1.el9em.s390x.rpm
- flightctl-cli-1.0.3-1.el9em.aarch64.rpm
- flightctl-observability-1.0.3-1.el9em.aarch64.rpm
- flightctl-services-1.0.3-1.el9em.aarch64.rpm
- flightctl-services-1.0.3-1.el9em.x86_64.rpm
- flightctl-agent-1.0.3-1.el9em.x86_64.rpm
- flightctl-agent-1.0.3-1.el9em.ppc64le.rpm
- flightctl-telemetry-gateway-1.0.3-1.el9em.ppc64le.rpm
- flightctl-telemetry-gateway-1.0.3-1.el9em.x86_64.rpm
- flightctl-observability-1.0.3-1.el9em.s390x.rpm
- flightctl-cli-1.0.3-1.el9em.x86_64.rpm
- flightctl-agent-1.0.3-1.el9em.s390x.rpm
- flightctl-cli-1.0.3-1.el9em.ppc64le.rpm
- flightctl-services-1.0.3-1.el9em.ppc64le.rpm
- flightctl-services-1.0.3-1.el9em.s390x.rpm
- flightctl-observability-1.0.3-1.el9em.x86_64.rpm
- flightctl-telemetry-gateway-1.0.3-1.el9em.aarch64.rpm
- flightctl-agent-1.0.3-1.el9em.aarch64.rpm
- flightctl-selinux-1.0.3-1.el9em.noarch.rpm
- flightctl-observability-1.0.3-1.el9em.ppc64le.rpm
- flightctl-telemetry-gateway-1.0.3-1.el9em.s390x.rpm
- flightctl-1.0.3-1.el9em.src.rpm
Fixes
- This content is not included.BZ - 2418462
- This content is not included.BZ - 2445345
- This content is not included.BZ - 2445356
- This content is not included.BZ - 2449833
- This content is not included.BZ - 2455972
- This content is not included.BZ - 2455975
- This content is not included.BZ - 2456333
- This content is not included.BZ - 2456335
- This content is not included.BZ - 2456336
- This content is not included.BZ - 2456338
- This content is not included.BZ - 2456339
- This content is not included.BZ - 2457729
- This content is not included.BZ - 2466505
- This content is not included.BZ - 2466507
- This content is not included.BZ - 2467822
- This content is not included.BZ - 2480680
- This content is not included.BZ - 2480681
- This content is not included.BZ - 2480684
- This content is not included.BZ - 2480685
- This content is not included.BZ - 2480687
- This content is not included.BZ - 2480688
- This content is not included.BZ - 2480689
- This content is not included.BZ - 2480756
CVEs
- CVE-2025-61729
- CVE-2026-25679
- CVE-2026-27137
- CVE-2026-32280
- CVE-2026-32281
- CVE-2026-32282
- CVE-2026-32283
- CVE-2026-33186
- CVE-2026-33810
- CVE-2026-33811
- CVE-2026-33815
- CVE-2026-33816
- CVE-2026-35469
- CVE-2026-39821
- CVE-2026-39828
- CVE-2026-39829
- CVE-2026-39830
- CVE-2026-39832
- CVE-2026-39835
- CVE-2026-42151
- CVE-2026-42154
- CVE-2026-42508
- CVE-2026-46595
References
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/managing_device_fleets_with_the_red_hat_edge_manager/assembly-edge-manager-intro
- https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/edge_manager/index#edge-mgr-intro
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.