Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.7 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:043fdd995b92bb8de99305c0706c8c30ea505617838fc256573e1dadc58ab1c7_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:2538ee857314137edcc6a184097dcc21ccb1a9dbc395d267f0ce179fba7cc14a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:5253bac1b2be6561be31d3f56f61e7b07ada0a62b52a7352030a8b73633af456_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:af15879f51c9aa43ffe58357abae03abb9cb729a5185a1e8f72fa8179a56a6e9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:19dc88a8f608bd96b9fe11d1cdd42f6527c0cd70c13be30f588e73b0d832769e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:2370d3428537913384401d6f1dc8d44eb14ae642098763cfa301f857d1a3b135_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:77cfbb1c84f68a4a2d1ec54c11dc9ba0c1316bd301918c774d518bac0bcab175_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:a7d4fad17aeb4bd672aac7e006bc2b6816b055216b3ba64c634bae8cedd91e83_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:461f8037072b78a3b3048fab8f209a484b2d72cf43b9f32c3729d313e6bae6d7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:4dd222544e7714eb0f8fbd72be7335077f443fc13ec59ed5f9756603af01ed2a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:6727082c33b52637a98fd499a77c0aea38c9e83b247889fc8fcc9ef45c42d9b5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:73846338ba7724cc836a987290cc06e18f8397df2ad3d5767f6472d9365e2255_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:1a5b4bbd98f02b300ca09c4bbb2b625ffb5700f26b20ccbb378875393dcf9cf1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:5c90599d4c9df3a7baa0780ffb79e23bb7a36fa56d9c349b1d6257d0cd03c2da_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:651a1fa516117a04a7743e8f72ad545b6df291dd9a43893fcf448c7dfc1a3ff6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:96a3572e35b4f3544d18c62718acdb3d421f60ca01d68fe76a67d75d085c4654_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:201f814daf6724ce4c2bc95916922d33543dc0c8ef8abc196fbc45813429be0b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:7f0c275334e105895a3454197097078d04d61d1899cbac95626270ed016d9319_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:801ec23e664181002fc5ba2b52e387b52b44d8b51896b94206ca61c95814374e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:b0207b6faa155f91251907c3097562c0053c47fd4b59a22507801e8a51c88e8a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:2f6940517e76a511d351b71c8ceca099280eed22286e1d63ead94f660afc5086_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:3f64af82cdb6a93d677e94b95a991cc05e32fac463f0c8427e415c4fa3e4fc46_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b66bd56b401b7cfc1a84166fdcb2e8e84c96e9965ea3dceca456a682dd13ea02_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:bfb908dd5799d6f1cfaae01ceed9b4e0ee18b083eb1fc268cb9d227ce7c1eee2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:2a69b03d181ef542adbc817d1f2a647770da27f6908cfb1bd8582d86601d4a29_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:7d14314e6f9875c51144c5ed515f2413da0d7d087ccf980d9530f040cd2523e8_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:7e4a0ab7fe232fa99fd24b9b19680102a23acf6b81d670a73b4b251be6333f54_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:f5f549d2af3d1d213732f1de8397d01e84178d9561e52e981e42dc8eb3d14e48_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0df3e454a792183cfbedcff1f3fd12cf8c5a9740d839dca3c4b4726a5af9da62_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:17704
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17704.json