Red Hat Security Advisory: Assisted Installer RHEL 9 components for Multicluster Engine for Kubernetes 2.11.2
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products21
- multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:571bbf5386c664f54fad514b1d04f4b3b01162e32b464d7707171807cfa2cf44_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:8a4df62ddba452378bc553cc94ca0d672d10a86f45e609dd0117e56caf72763a_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:bdf657fe8b0c9ab539ec474052f403a2fc79833fc2479079ba9e7eaf7880dd93_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:ce084ef4b38c390778b20c96b48d78837bd3609281db82a15a28eed65ac9df41_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:27709bd7f3b1bf435b7f016d19ac36f7fc9ebc9ac5d1af13ee00a19a362366a2_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:938acf1d06fc33bbf5c9432d5953a10d02fed45824b776248e041b05af129c08_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:93e7b5d6eb7fcb89150d6e90c9a9c16a793ee96244eaca65aab0a326a12be2db_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:b63da7b89b6a8335394e05e4a83a18d7019e7f0ad6c32166de0f65bf44d5e82c_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:58bd75f698338aab4cc8c04e28530368dece860c4741f8a2926f72726671e8e1_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:8e30a737c67effb5163936e217da3cf4528abc501b42f109371f2e14cd2fb43b_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:bed53a9e264eb42cff85a3db9e08f869713fa1c64c94b2bd3fa5223720a8bb19_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:d914e7f8a2993fc12783e985475c9d759335f360b111c380d9e90bad1bf8236e_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:6184e752f0e4d70c71448cd9c237171ad5efb18f8fa748e3e483b12c610a6a71_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:64bb85c01610436d1ca8d924e6a806d9505d4fcb7240bd53df7df6d22f0eb2ed_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:6f21637ae5536f0a9064ff0e8ad658d8bfdf0939c771f90809698199ee670837_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:6f33768139cfb4068f1f2d9887a5705947941f20aece137ae479567f9551786a_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:a85b56510f1414be81c5ba10601b92bc7acdd91d92c80422278aae7733b02f87_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:b90069a7f8a34aec8298179773ffe9c500534ce423d4eb25104ec7d66f279b06_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:f0d9c2b1fa4a0a29f607d4ee0bba2405c15018bbc3d437bbe4f1385017f780c2_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:fb238966a44e31d1b2b23e6d2b236296dd9e4808c330fef0eef8ce50f698dc3c_ppc64le as a component of multicluster engine for Kubernetes 2.11
✅ Remediation
For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.16. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:19108
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19108.json