Red Hat Security Advisory: multicluster engine for Kubernetes v2.7.7 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http
🎯 Affected products109
- multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:1c49bf643ea000a0f92a1d93114a4a866ff51f47947c6a7102fb8e200ae57e8a_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:4122c38381cc2bc9fe06efee1b3d2d8ea908a5cfcaf74686734f9933c1f033ce_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:d64f8dd4bc9c3c9cd4cde0d9c824a5554d3e3bad10cc45259f0cae1b49d60d72_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:dd99548b21e36ba637fbf8e44f6062d2fec98abd536dba16e10475648664984e_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:547db048159c84228eee682df6c0fa6e45660d0ec27f6288e67c21640d5b0606_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:6ce6ad329546167b7e5541cb196df837a5c0012c0d9a153acd2237f91a43d2a7_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:7df678c748d401575521ad69982bbb194e951f77af958e1ea168a603eb0672fb_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:c58d1015f276eb00d204e4e76c31862e83896697d145f2b02ade216a47fb13f5_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:29b02c2440139782938353206584bf71cc8e99b1f8536592d83e25f91731946b_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:946f78e153fe85ec4066297fdb64cedc7e67ca4e68b685f25b28d3042991ca4a_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:9917cda15f25447457552022bef52012a53d66e5f3d837ddec58a47dbadd1341_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:a58058bc3f0fb97590bd4519c82394511c00a59bed2205faf7d4dafdcf495102_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:1138ac7b417ea51bcfe37732c4cc91515d5eaba1c534ceed6dc1eda216136bb3_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:2ed8c05413a5bcece9c400b456dbe65c815c834d7cd9ebcbfe22be6477e243c4_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:715e58b0900c72ddd2e12e0ef2119c0fe45f36192e9e13debf3d34880abc5216_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:a41375e857a8766ab2d82e296900fed5cdb4540c32e7386f100c5b3e1009fd99_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:1d8cbc41e44f8b099bac2403c7a45b8f4ecc08eb8c28d2a18d8d2d74f64df9fd_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:25998e11ea2f8ad8635613187377f2bcdf14c06dbbb8324d37ea802ab53ab4ea_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:832f42e8ca9c824498089a09520228ff246c1591c3852f887e531ebd2a93c269_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:8ae392d24c0b33e18573f5ca71c092248d31b4814f81c534f99629a207d9e31f_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:39d0950969b8d78b1088632f5c170bc52f76b529adb76cbfd09f6c44eb8ae91e_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:428cf53e9df3832d4b5b22b936e61372cdee0f0af8652432dd0e205f76762bed_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:792fd2f5f20714b75f8bec25b6f678ad8d3aff06a70480204cb71ae9f38546ee_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:799050e70c61dcdaf18919b968c5cedf4efa32fe8dbd11cb70fefbe1c500e389_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:263985d221ed49eaaca8f790b347c1bcab78fdff509f0e00fbf45599f720c32d_amd64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:8989808fd9a73ca0a5ff97b420a8ede8b56efac5fe203deae5972412a51fe499_s390x as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:998a81a18a3ca73421c633171ca4950c857af557e464f8b55ef05a7721cb031c_arm64 as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:c200e777e61c1c020519a4c1d4349e7dd48b9487dd16b2c01702101bfee1b9cb_ppc64le as a component of multicluster engine for Kubernetes 2.7
- registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:399a470cd568c52ce90801aedaafdcbbc7541fd091dba253475f1e071859bc8b_ppc64le as a component of multicluster engine for Kubernetes 2.7
- +79 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:22683
- externalhttps://access.redhat.com/security/cve/CVE-2022-21698
- externalhttps://access.redhat.com/security/cve/CVE-2024-24786
- externalhttps://access.redhat.com/security/cve/CVE-2025-22871
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22683.json