live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

RHEL 10.0 EUS updates Ignition against certificate and hostname validation flaws

The fixed build covers four architectures; operators should update before the next provisioning run and verify that Ignition reports the corrected package release.

Old Ignition accepts bad inputs; updated Ignition validates them before provisioning.
Side by side: what changed
By The News Desk· Aug 25, 2026

Red Hat has shipped an Important-rated Ignition security update for Red Hat Enterprise Linux 10.0 Extended Update Support, rebuilding the first-boot provisioning utility against fixes for two Go certificate and hostname-processing flaws. The advisory was issued Aug. 25 and supplies ignition-2.21.0-2.el10_0.3 for x86_64, AArch64, IBM Z and little-endian IBM Power systems.

Where the exposure sits

Ignition runs in the initramfs and applies machine configuration during first boot. Its inputs can arrive through a remote URL, a network metadata service or a hypervisor bridge, after which it can partition disks, format filesystems, write files and systemd units, and configure users. That makes the trust checks around an external configuration source part of the provisioning boundary.

One corrected flaw, CVE-2026-33810, is in Go's crypto/x509. Red Hat says excluded DNS constraints were not correctly applied to wildcard Subject Alternative Names when the SAN and constraint used different letter case. A malicious certificate from an otherwise trusted chain could therefore be accepted when it should have been rejected. Red Hat scores the issue 8.8, with network access and user interaction in its vector.

The second flaw, CVE-2026-39821, affects golang.org/x/net/idna. Crafted Punycode labels could pass an ASCII hostname authorization check and then normalize to a restricted hostname. Red Hat scores it 8.2 and says exploitation requires network reachability, high attack complexity and low privileges, but no user interaction.

For an Ignition deployment, practical exposure depends on whether the provisioning path consumes attacker-influenced hostnames, certificates or remote configuration sources. The advisory does not claim that every Ignition run is directly exploitable; it does state that earlier packages in the listed RHEL 10.0 EUS streams should be treated as vulnerable unless Red Hat explicitly marks them otherwise.

Fixed builds and verification

The update covers both the standard RHEL 10.0 EUS channels and the corresponding four-year update or support channels for all four architectures. The corrected binary package release is 2.21.0-2.el10_0.3; the advisory also rebuilds ignition-edge and ignition-validate at the same release.

Operators should apply the update before the next affected provisioning workflow. Red Hat's package-update guidance uses dnf upgrade for a full RHEL update or dnf upgrade ignition for the specific package. After repository metadata and updates are current, rpm -q ignition should report ignition-2.21.0-2.el10_0.3 or a later build from the same supported stream. Teams that stage immutable or installation images should also check the Ignition package embedded in those artifacts rather than only a long-running host, because the utility executes at first boot.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.