live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseJAVA

Red Hat refreshes JBoss EAP containers for SQLite code-execution fixes

Updated EAP 8.1 and 7.4 ELS images require consumers to pull new containers and rebuild anything derived from them.

Old and refreshed JBoss EAP container layers side by side.
Side by side: what changed
By The Release Desk· Aug 29, 2026the quick take — two AI hosts, this story only

Red Hat has published refreshed container images for JBoss Enterprise Application Platform 8.1 on RHEL 9 and JBoss EAP 7.4 Extended Life Cycle Support on RHEL 8. Both advisories were issued August 27 and direct users to replace affected images and rebuild downstream containers (EAP 8.1 advisory; EAP 7.4 ELS advisory).

What changed

The EAP 8.1 refresh updates OpenJDK 17 and OpenJDK 21 builder and runtime images across aarch64, ppc64le, s390x and x86_64. Red Hat says those images incorporate backported fixes from RHSA-2026:58936 (EAP 8.1 advisory).

The EAP 7.4 ELS refresh similarly updates OpenJDK 8, 11 and 17 image variants where available, with backported fixes tied to RHSA-2026:58938 (EAP 7.4 ELS advisory).

Both container advisories identify CVE-2026-11822 and CVE-2026-11824 in SQLite FTS5. Red Hat describes the flaws as allowing arbitrary code execution through crafted full-text-search data; the second also carries a heap-buffer-overflow crash path (EAP 8.1 advisory; EAP 7.4 ELS advisory).

Who it affects

The update applies to teams consuming the listed JBoss EAP container images from Red Hat’s registry. It also affects application images built FROM those EAP images, because replacing the base image does not update already-built descendants (EAP 8.1 advisory).

What to do

Red Hat advises users to pull the updated images and amend Dockerfiles or build scripts to select the new image specifically or track the latest image. Teams should then rebuild and redeploy every dependent application image so the corrected SQLite packages reach running workloads (EAP 8.1 advisory; EAP 7.4 ELS advisory).

Filed by The Release Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.