RHSA-2025:23529HighCVSS 7.7

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11.9 security update

Published
December 17, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-7783 — form-data: Unsafe random function in form-data CVE-2025-9287 — cipher-base: Cipher-base hash manipulation CVE-2025-9288 — sha.js: Missing type checks leading to hash rewind and passing on crafted data

🎯 Affected products165

  • Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:0b87fe3f20693cc52fc7cee32b8af9499819faabd7f81553484bd95e5eef7a7b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:84563892488b4c96d215ec814353883629c7d87a3d2af5ee9bd62e09ad903552_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:925323c7e59b56c392b458d781625c5b91dac487f9f07df711d90166851f283e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ae4841cd71e614cce07c9b7dfbe548e3690257a232bb768abccafb75e5c29031_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:7b1cbfbb25d30d995c3016569e2ad3220ba3554be9005fbbffe7d0cb6a8686ef_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:802affdac6ba2cee4c0e5ec637386628836792c0579d4e16148f66af9f5fc344_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:8b8a5e2602eab8f93cc2dd5de49b4e9799d83d88766cd09ca8585bfc2b99cf7c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:feeafd2a3d9d118ec5a93e7d4f6a9c1e48cdecf6d2b9f0cbb04624867ec6fd81_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:0e15fa990b11ff182c0b188f68839c412dba54c497f5b7c809885e81095f8f35_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:88c8057db27c52c4ab61e0313bbfc3888d81bbd9f96c41472ea7f1640b9b44b6_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:8ed199735d34f052e9605c0efb0162cc0d09482cf19241cd598dfbe42238429a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:e180d34760c2ae081cf89a8a502187dd5117baa3dc70c8098bcc75c1d57e7c51_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:36dd085e7a02807fe3871317084f2a0d16ef3a86caacfdbe9b1e30b5be17dc54_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6b5f0997888832eba63d67bf802128eb15f7cb178b082f090b95db4224a3bc5d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9b72a0f4d070bdeb75c6b037b9f05d3d025c638f896716e59d598ff1e83334ad_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:e4a59fa9706305e2a77d7e40fe1836f2b6e11b1f86aa573f3b9623df6a625b1f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:1015b6e12be6e66174d47e4ad8c855338c8d3d032b7be693859d6628c5d4cd2d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:be8f137f4c4e9af41450dd053fb10c18ab344e5da8ce599795b6f28c68481dbe_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c4aab9174329d8a7a2dab9dd9cfa7b5d11a4e2c6827ae3ab65202599cf015b0a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:d2a97d5084c669a6fd18673a4b11e37a58bdca0b06a38f29cd69b949130c9932_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:14c6f451d09207d38a04efb81e0161465cc78567c924050691180076a1f1c426_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:41f7eaf1e029318f58e9befb5abd7b6ffce586f7c634a10b0191f43affa4ee80_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:b49bb48219e727d7577d204773c6373504958554d8238ebbdce033a7ac2c4cd6_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:f3fd783852c69fe69b182b88915abfe2e5083b987c7178e7859c76e07ddb9c96_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:7dca2cb41aae3b06aeca027ac3a1cbac182b011e7d10d85764b7e24099cfee7c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:839e1939a16228e836bcbd49bb289b6b2c9638d21feda1b78f0f7ce191723673_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:b5e02f1aa67e33b975521b9ab1a7808fa52ce14b99f59daeac11934d3423cd5b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:fc3eddbd0fd81fbeb3c5b79fbb56edde4d0449dc9ba389f6650dd74126c13498_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:2c228215a5bb61c1a0c82d6f2545746fa731c8390a67b2e3afb3a3c6e91c5cb7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • +135 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)