RHSA-2025:22684HighCVSS 8.5

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes 2.12.6 security update

Published
December 3, 2025
Last Modified
August 22, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-53547 — helm.sh/helm/v3: Helm Chart Code Execution CVE-2025-58754 — axios: Axios DoS via lack of data size check

🎯 Affected products177

  • Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:222f058d196372cae68f4c6e67892558982dbe75bcab1979aecca52ee62256d3_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:444fdbc901265457255cc7b587621c40b0a74474c9679fb0211678d09f4996a7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:81fa70801becedcb218cc38ced440ebe883fe4afdd54cba66c06fdf5a30d159d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f5308da552c1543d779dfce168f4f9ae1400bf54056e802d96614f930939f7ff_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:109bd95d99f98906c8a9cf3057f7d0a83ce18fa4f6733606dd3e98d2735312c4_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:192dd3dbdb51f41d9dadc73da2df6777e295a384102913ff78e1d1fb19a5e96f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:37c6415ccd9a7a41d99d67ebe5ffd33c54d723c23e9cb744ea0626a9ab5b7854_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:fb7e376d1a160e31066d1ddd1f1a9dff5fd73e641991c82766dac9cc7d93b5bc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:1e4aafc4ba6d421101a5b89b3a08540cb8007785bceab56c9ee92531deb76573_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:63a471062e882f7c945131b05c6cf0655a4d4f38dc52634951364361e7af13e4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:fab05be84c7a8e88c118235937dc2845a1c03eeb1fd8d334f3cdb9b98eb56cbd_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:fb5906271649725ce8448f60e3eba60ece2f8db1518a469df0755756cc38b9b7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:1b98cf52f4315a36ec93bd66b215ac6915812b9fa9a8b507ce30d2ae838c8147_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:2a3c064b955698480d24ea30096912f795fcf27008585e433611bad1329a378c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:7df685e817a6d2d186e6d60ce08b489bd7201464cf93509c23728567c3e9001d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:f873349390b3ff0592096ad9b1ab71ca0c5b87d998f52830a12ebd6b2029a924_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:987874f9b19ea441d376b526c5f09893f1ef639d74708e2beda820d4bcbe90b0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:a6232d939d9aa347d679cd525278ea5c7c2e9234de0df5af4afc6593404cd5c7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:a8cb246f2e9a64216a0f6e5bf861f423bd07160204a606cae0f997491745f20b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:d0915b44bd1df9253e9533bc5f3732c3458133082549def9be8e0829ae41267b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:1f5b97255c38dbf1c85c7b5dda43ece4d080c0f12fc25ef403e7f8a75168397a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:6dac5bffc394e9a58ec332e5ced2166734d539ac189393aadb1882b07a80f8a4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:9c9671e3a400a63acdffef37b0136a3fedd72a6c9e7845d3d1e53f6f961a2082_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:fe179e7b8dd40e78d668b3141d2c90b5baa2b2d1e595d53b2841ad9b101e297a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:549655096c9c77159b8e0d37fd17bcd88cc8852e0ee85a5bba54cfad486b6e81_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:635429e5ed36717bf6a017bc84bfcf07db3916e4fb2d4e37d718202cffaed8a9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:a57e6b80c004c9cc0873316a8ca61f2250a4afde402243d9486269f71f4ea7cb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:a7b30daaee886a374bb177177c7acabb5cd5f9f8a08fefeae11432e1837416ce_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:45a28bb546d030476bd4ea79f7a39953f15dcf0dae95bc8ab91c969e687356f7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • +147 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters.

🔗 References (11)