RHSA-2026:11803HighCVSS 9.1

Red Hat Security Advisory: VolSync v0.15 security fixes and container updates

Published
April 29, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products6

  • Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:16fe25978a2667b08c64fdc291cf49f360f734ec4904888f819cc0a563f39b36_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:035aff4df7d0f68580d1592dc48b44af82df171b12de09b5bb7df9842877edcb_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:0a771130ae9933c3458a1f2630b755d039cabac0bd8ff3613080a17b57bbc62e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:74d79d9a7f8a625cc84c53329e84b30e8de5ae166614cd9417136f0c3d5664e8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:ed5cef307a8d15acef1805e358ef28d844858f5e87c4ea891675b3d9321a6314_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/business_continuity/business-cont-overview#volsync Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (5)