- What: Security update for RHUI 4.11.4 addressing a vulnerability in python-pyOpenSSL
- Impact: Systems using RHUI are advised to apply the update to mitigate the risk
Red Hat Product Errata RHSA-2026:10754 - Security Advisory Issued: 2026-04-27 Updated: 2026-04-27 RHSA-2026:10754 - Security Advisory Overview Updated Packages Synopsis Important: RHUI 4.11.4 security update - python-pyOpenSSL Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An updated version of Red Hat Update Infrastructure (RHUI) is now available. RHUI 4.11.4 resolves a security vulnerability in pyOpenSSL. Description Red Hat Update Infrastructure (RHUI) provides a highly scalable and redundant framework for managing repositories and content. It also allows cloud providers to deliver content and updates to Red Hat Enterprise Linux (RHEL) instances. Security Fixes: pyOpenSSL: DTLS cookie callback buffer overflow (CVE-2026-27459) Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions on how to apply this update, see: https://docs.redhat.com/en/documentation/red_hat_update_infrastructure/4/html/migrating_red_hat_update_infrastructure/assembly_upgrading-red-hat-update-infrastructure_migrating-red-hat-update-infrastructure Note: While there is no updated version of rhui-installer, for this update to take effect, it is necessary to rerun rhui-installer on the RHUA node and to reinstall the CDS nodes, as described in the documentation. For other information, see the product documentation: https://docs.redhat.com/en/documentation/red_hat_update_infrastructure/4 Affected Products Red Hat Update Infrastructure 4 x86_64 Fixes BZ - 2448503 - CVE-2026-27459 pyOpenSSL: DTLS cookie callback buffer overflow CVEs CVE-2026-27459 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Update Infrastructure 4 SRPM python-pyOpenSSL-24.1.0-2.el8ui.src.rpm SHA-256: b16be6d6f143657fd3191a96b815af9f00c13632683f7a9f3153659416861dbd x86_64 python3.11-pyOpenSSL-24.1.0-2.el8ui.noarch.rpm SHA-256: 3951cf5d5efe3e707b021696bff8e205399689e11745a5dfef4066e6f29a6687 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .