Red Hat Security Advisory: Release of components for Service Telemetry Framework 1.5.7
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🎯 Affected products8
- Service Telemetry Framework 1.5
- registry.redhat.io/stf/prometheus-webhook-snmp-rhel9@sha256:f491bfd1f9829050d5ca68786aa1bdf74f1ce6e030b7c1112cc68b3858d83b88_amd64 as a component of Service Telemetry Framework 1.5
- registry.redhat.io/stf/service-telemetry-operator-bundle@sha256:1abefb6eb3d624f2b9b827f31ecae69a2c84e50a2fe91be81d01d6c2b4ec766b_amd64 as a component of Service Telemetry Framework 1.5
- registry.redhat.io/stf/service-telemetry-rhel9-operator@sha256:6a9a6329f33c56bd44d760fa0d80a6c34b6a5d5942cf5a32b46e49899f546483_amd64 as a component of Service Telemetry Framework 1.5
- registry.redhat.io/stf/sg-bridge-rhel9@sha256:58085c6b3136a28e803409d7203486650b276f2c7aaf124936b0166738a11f8b_amd64 as a component of Service Telemetry Framework 1.5
- registry.redhat.io/stf/sg-core-rhel9@sha256:73bbc51fe49e965907f35d7176759235bff876032e40616366093ead21372c71_amd64 as a component of Service Telemetry Framework 1.5
- registry.redhat.io/stf/smart-gateway-operator-bundle@sha256:fdff297b0f11bac06d6e4d82e1dc8724ab42f0be6a0fdcbc5cd6c80c7bc7bffe_amd64 as a component of Service Telemetry Framework 1.5
- registry.redhat.io/stf/smart-gateway-rhel9-operator@sha256:247fd48abbb8862bff7aa76d742a8edcbb4bc0cef35b5624c458a502cd709a8d_amd64 as a component of Service Telemetry Framework 1.5
✅ Remediation
The Service Telemetry Framework container image provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References). Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:14020
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-24049
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-30922
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_14020.json