RHSA-2026:0722HighCVSS 7.7

Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.4 security update

Published
January 15, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-9287 — cipher-base: Cipher-base hash manipulation CVE-2025-9288 — sha.js: Missing type checks leading to hash rewind and passing on crafted data CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map

🎯 Affected products109

  • multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:4730066d796726424abb881b2564bb7e313237ac877284c206c8aee3e3843b2e_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:6fdd58915b503cf194ccfb2475db55fb74f6d6b8033e71c16ea35f6291f5ad9e_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:e69f76da9ffe324bd5b82eaf453bf36198dfc593e2646a81efc157b386e92734_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:f98a63dc667c978870e3c7de4fb1eecdaa792e496acf76ab2572d10c73fede97_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1504f6b9df9757c616f09856741b2a4df7dd48bc01e38f403334b953552aa4db_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:4c2d5515cd5c2d71327cf767260b9e9ea498f74bd628d00e16ebccce49fd775f_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:6fffb75e88a35ab4e447bd02f7a64b2830963745cf09a4f1741f3fd10762cc01_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:bf0822de14769aa5746e48a6b3da9bd00bffdbfcec7af44882c62f5422a3437c_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:2c8ddf681d24c855164993316ae09e7c790952c28e89f0155c8c9c72ad385d01_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:9342bfe02cb24d81f62bf48a437f1b2f1e58663f4ed13e27084762bfc4180988_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:e5b99a4b4ff96f7ae3cd5b6e45f7270fe0ce62446cdc14236180504b844875d5_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:f35dd312d4befc12ea1e4147f638c140c8f0a1fc6e62db9a8e40f018618047da_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:6d85caeef93000977432bfc544a2195968287a0c18fbb851f3ac02b476a4b95b_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:6dcdd90306fb028aef7cce6965a3c315dcd22c192c6738d993f38a75f42b5929_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:bf7751ba0f228b076832d287f1fe39c5ddc0757ef8ab24085f02a106f23dad55_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:ec18711854511959194df677eb57f543b570009f76a674b10c84f7c8c8e22f3f_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:4324d92ac7c3800b69320269da831dd1791e50c6793f6fd383f008db990139d4_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:b876cd5f7e959f7b6a3806c076a45640aea561388cfa1d2ee63693b2668ed6fa_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:bb3fc940d29dda5218e177232585504c0381597cb5eafd2a6ae7d61ada6a478c_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:fd512224832abaf339bd77d592e19af9b72447fc62fa083c28ad7a29ef7cf143_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:14a25702ce0f3daa11002ab8372f72f68e064b46e74189c4b6873291d5326730_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:2e49e880bbeda2fa86eaa67bb167664e27c7b3c7500fe626195650a34834c7a1_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:4b3088119684f6d8fc3e67c7bb9de32f5071d9c3861a98152e85bc471bbbd326_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:e30eb0e43c0ccc6d21414e3cc1cf8350c709e385dfef22e3df4ed7398555e275_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:2f2e2c858937b028615a4261f1edc8b9b96eb6e48cd2fc3cfd578ad947853a1c_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:389dc9a9ebd1662ae67f7add2e833df6c95f881a7bc98dd34c7cc7d62751dd55_arm64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:8398a34a0191a3c87f86eb5be06c24d6ec5a21cefbb22e83e05d8d093ffa3667_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:92c31993c20311df6355ebc516959b4f4904f244261682b7859b099f0ab8e1f9_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:1302065f09074b5c39c0d1b82f38424dea4d0beaf4cc7a28cc1a1219396eff0c_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • +79 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (12)