RHSA-2025:23236HighCVSS 8.7

Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0.0: new RHEL 9 container image security update

Published
December 16, 2025
Last Modified
August 9, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-11393 — insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: Improper Proxy Configuration Allows Unauthorized Administrative Commands CVE-2025-22874 — crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509

🎯 Affected products6

  • Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-operator-bundle@sha256:b5f0ff2579eaa5f85452b009a2f7735238f87a05c3f7d503218807f0741c1a9f_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:08f473dec97e110a73e1c9886ee31512bb6937f87bdb95fbe77cb2d85695b936_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:0abc9cd56597eb0983b4c50704f7dca6736e745710ba627fafa0c892f250ed49_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:33ddc7c7c65374ab7b2b2c02f6319e52fe33904a9d951791cefcd72a39b66453_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:72d4826d2f9da25cb841a0f71411ade99515d23efc13420f057cdc4f804f0302_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Add the following to the Cryostat or JWS subscription YAML: > spec: > config: > env: > - name: INSIGHTS_ENABLED > value: "false" This will disable the affected proxy server. (Note: due to a separate issue, the above step will cause a crash loop in the Insights container for the operator, but this is harmless).

🔗 References (6)