- What: Security update for oci-seccomp-bpf-hook in Red Hat Enterprise Linux 9.0
- Impact: Moderate security risk for systems using container security hooks
Red Hat Product Errata RHSA-2026:15940 - Security Advisory Issued: 2026-05-11 Updated: 2026-05-11 RHSA-2026:15940 - Security Advisory Overview Updated Packages Synopsis Moderate: oci-seccomp-bpf-hook security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for oci-seccomp-bpf-hook is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description OCI Hook to generate seccomp json files based on EBF syscalls used by container oci-seccomp-bpf-hook provides a library for applications looking to use the Container Pod concept popularized by Kubernetes. Security Fix(es): github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload (CVE-2025-65637) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x Fixes BZ - 2418900 - CVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVEs CVE-2025-65637 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 SRPM oci-seccomp-bpf-hook-1.2.10-1.el9_0.src.rpm SHA-256: 840982bd2837c997993718888897f26c272a2a4d772d7845f761278ce3691327 ppc64le oci-seccomp-bpf-hook-1.2.10-1.el9_0.ppc64le.rpm SHA-256: 73993aa94c507dd212e30bb92690fa62c4f6e90b896147b7bc8e2746886e82de oci-seccomp-bpf-hook-debuginfo-1.2.10-1.el9_0.ppc64le.rpm SHA-256: 8ee8f2c161bba04fe782439ce3f57d184e40e95c04c05c371752aa58c2123349 oci-seccomp-bpf-hook-debugsource-1.2.10-1.el9_0.ppc64le.rpm SHA-256: 3b448d87b143b23c7679516e3421a0402492ec6d940466fe33c7365d95977e26 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 SRPM oci-seccomp-bpf-hook-1.2.10-1.el9_0.src.rpm SHA-256: 840982bd2837c997993718888897f26c272a2a4d772d7845f761278ce3691327 x86_64 oci-seccomp-bpf-hook-1.2.10-1.el9_0.x86_64.rpm SHA-256: 5553e4311df381394380c0f277a4a09c20e1c05bf41869fdcaf6d7a92ae28d86 oci-seccomp-bpf-hook-debuginfo-1.2.10-1.el9_0.x86_64.rpm SHA-256: d2ecff30c745b0b652dbd9677a7f805f99f09bd47eb64f769ec5138d3825a94e oci-seccomp-bpf-hook-debugsource-1.2.10-1.el9_0.x86_64.rpm SHA-256: 3dfb41cee12759e6a4639ed9e653b03a3a65f8a637327689634dda5f1787d70c Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 SRPM oci-seccomp-bpf-hook-1.2.10-1.el9_0.src.rpm SHA-256: 840982bd2837c997993718888897f26c272a2a4d772d7845f761278ce3691327 aarch64 oci-seccomp-bpf-hook-1.2.10-1.el9_0.aarch64.rpm SHA-256: 55b05343b715891e39f965d0c4993370250877c62faa07a038d64e43cf2dbf61 oci-seccomp-bpf-hook-debuginfo-1.2.10-1.el9_0.aarch64.rpm SHA-256: d7f48af6b28f05c2b55b75305e223a8e7a42e07e96cec034d6e078c44b88e816 oci-seccomp-bpf-hook-debugsource-1.2.10-1.el9_0.aarch64.rpm SHA-256: cff037b606374cc8030d7fcf6b9d89e4a880c9813a863eea415caa5cc01cc0ba Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 SRPM oci-seccomp-bpf-hook-1.2.10-1.el9_0.src.rpm SHA-256: 840982bd2837c997993718888897f26c272a2a4d772d7845f761278ce3691327 s390x oci-seccomp-bpf-hook-1.2.10-1.el9_0.s390x.rpm SHA-256: 261ebf164c7a7be5ce31c5421627c2b9fc5eb25d36b7202b6d6f891dc6013ccb oci-seccomp-bpf-hook-debuginfo-1.2.10-1.el9_0.s390x.rpm SHA-256: 66c84b1ca72dfe430edf4105eacd88412b641b6c60905300044f3b342af13d6d oci-seccomp-bpf-hook-debugsource-1.2.10-1.el9_0.s390x.rpm SHA-256: 06c426952ec8366240684ac246908f3a1e32796bcb367f8d992e3e716047b5c9 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .