RHSA-2026:1859HighCVSS 7.8

Red Hat Security Advisory: OpenShift Compliance Operator bug fix and enhancement update

Published
February 3, 2026
Last Modified
August 16, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-68973 — GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

🎯 Affected products18

  • OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:1f64fb6c815987f02e1f9145bdf0b92fde122a5592cb9c6e3e734c7fbfe0423f_amd64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:20e46e06977b41e0023503744d1a6b369cc625b71ca2c0499638e07642e8f497_ppc64le as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:c3be1b6c7f4a941ea8ce04911a6ad4e131d68edaf740202edd3d8e81a5ada121_arm64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:eba79d28a525f781c99f256a5aea19f2c32c1642b47a75cadeccc1becbf4c03e_s390x as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:616471362a3255231b1b2f5434aa1fdde078570543b1ccee23a74272cff3f2b5_s390x as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:b28e5ae6585ee33cbe4b18240dc05654c97960174beafca7575e9e0e452f7fb0_amd64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:c630e73e617cf3ae94ded4961051c230ac51cab6c65f2067811e193aab489e8a_arm64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:d4ac4dab190256aefd49d3bcf91747a6647dc1981b105499d3a933554643c350_ppc64le as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:050b381149997b5fbad2e60ff312e1559ee7c2efc67c822cc3e26a9c77c58749_ppc64le as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:05c4770c79444de006d6ee9fa05c678e2bc26bda6aa3306c5149e80e741c07b3_arm64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:381e2f4b0aa56ebe408bb4a7b75edbc2b67ad972df8435ad4207b631c58b6047_s390x as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:c49db2fec7a746afd40fe5883737a9e042fe1280f5eb7d1a4133b96e5f3febfa_amd64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-operator-bundle@sha256:ddc2f107588e25d38af6eb58c7b106124f447deae8090ce4d78eead12487d1bf_amd64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:1ff94f69f055ccd48fe6c1c90c70302567a30dc9fdb548c8021bc041188673fd_s390x as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:281db2a4e1230228f5442ec70f09e78464171fe346722dbfdc2dbc277986767b_ppc64le as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:68ba04c2a97a1dbe3780ed8c6b86af3079584211e3d466f00dcd7a509281f371_arm64 as a component of OpenShift Compliance Operator 1
  • registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:b91a28de45761e8aa69752b0120cfa9cbfa1eb9bdd291ab77241e2b23d15c5e2_amd64 as a component of OpenShift Compliance Operator 1

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.openshift.com/container-platform/latest/updating/updating_a_cluster/updating-cluster-cli.html Workaround: To mitigate this issue, users should avoid processing untrusted or unverified input with GnuPG. Exercise caution when handling GnuPG-encrypted or signed data from unknown or suspicious sources, as specially crafted input could trigger the vulnerability. This operational control reduces the attack surface by limiting exposure to malicious data.

🔗 References (4)