RHSA-2025:23528HighCVSS 7.7

Red Hat Security Advisory: multicluster engine for Kubernetes 2.6 security update

Published
December 17, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-7783 — form-data: Unsafe random function in form-data CVE-2025-9287 — cipher-base: Cipher-base hash manipulation CVE-2025-9288 — sha.js: Missing type checks leading to hash rewind and passing on crafted data

🎯 Affected products109

  • multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:27834804d5c56e017785cf9a8100ebb1989288241d8c1a08e296778d2bcf52f1_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:46013beb1d8f782e92088ad4ea2d10155c67edb8d613966a5c069340bcac5ddd_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:6575a549657eb7a0c51235fa9ce1ce4b601cd532e5a5e6e6a5a9513eda3215a3_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b927fed57e3e7e0775ec810400a068b3edaa36b9450628d6e1af097011759e95_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1244fdf2ecb4dcc1e14e9a34150d56941e4d6658803b8cb14885d032b8fd4443_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:56b2688587848e11ba6ef689f457bcc047a54da19a8323c135d1caa3df609a41_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:6662394b01a5c16bdaa1eaac7949d1f0abab4e3ae09daf77b096d73a07116682_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:ef46d89f31a9861d753af67acb704d542f1bc25f31cccf6a4b6cd843522a593c_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:4dff069722b5fc2940c5c42f48f5aa1172afdc7c8e19f35f639e757c2c878d11_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:5e7ecd32c4b3891bfe7aeff7b8fedcb85c0df2b312d2e62cb3b51a8ee5727c6c_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:8917c1b09e582743ed4ea5df46213685de969bfbff656d039c2bc6c848772711_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:d16cf9a7842db1d54beacd8a5494f0d708728fd4a587dfc594f5f9008ae1b7ed_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:2cc6f284e9f283da1a416bc2851e6e2ff89649d1357f6f3c728382de67dd6e82_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:6ec632cf9a4c5d4d5511213c1856ce90d95b78af538b30cea9893d67c1fcd5db_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:bc09ad649d7461a01374451ab2b9ad1926ad1436917f62f9d266c4eeb29cb3d4_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:c73e4d70ec9d0b9a7c14ba8ba9f151abf8998afe8ef60cc4d3658001f277080c_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:15cc2942b22ef3d55920bea831403728cd63f7d26304323612c8d4ff2d85c236_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:4ef5651b8c718bb5bc4ba299dfe22866a3d1d0504bdfaf9a54b6db2a750e0eaf_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:c01b60d63e12ff2538e4df40962c4a842ecbd5dabef3beccbbccc584f4373bcd_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:ccb348bc3884e8f3324d30cb2c7d7ac25f90310ae7a04860da7ce6edcdaa078b_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:16534b62e3f343cb50c2614e1f75cb76d3d5456bac9efcbac7745b8c04683cd1_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:285fa8334f5437b1e0f8e21c23bd474cdee6b383a3cc91a67e0c9a34f3bd31f3_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:6d5b0771a8af890087ab0ff850f31c386d2fe537f2436ca45b330b4d06d624ac_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:f8e8a5388c2c6ba1ebb2f42a0964d6734655565940527107a314eeedca39a23f_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:5f29999db5b07f727d3c4556dc5702808f4682e11796682eec47cef06af3da4d_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:8aa3516d4507c7db2ab74f9920c43bbf947051cda1786c5c846f4629c6389ba2_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:ba3cb0405e39b221a88fe5bfe1735a58ce33321e1ae93ea33c3ce00908f5fe47_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:d0fab77c60c8b0915844238a45af8467fd70ca3b61a5d7d1f6239dc2dc7ddf81_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:35139f01f0234131d8f2057ccd46697352c9c1e02a8e7ec70e30a367e06944ae_amd64 as a component of multicluster engine for Kubernetes 2.6
  • +79 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)