RHSA-2026:22299MediumCVSS 7.8

Red Hat Security Advisory: Red Hat OpenShift Developer Tools - Source-to-Image 1.6.2

Published
June 1, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root

🎯 Affected products9

  • OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel8@sha256:365451b37b74743f123684976d01bee50f3342feed9a538eb1f64d630e99325f_amd64 as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel8@sha256:5b1a38089985b74754dfeb0888e32af42f6808d647c28f37ddf8db72aa77a871_arm64 as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel8@sha256:627567b8f0dff2b752da7618db040d5dc16e836bfc84aa8618e24930f9754d21_ppc64le as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel8@sha256:6bc0e8e3035dea680fd63b81c6b2a83f7b046ece14d32e0c886d3699e9a78f3e_s390x as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel9@sha256:aea2f22b7f61cb32fb82ccde987e8bc36d49c88ae91181fcc6787a6e352c7ee7_amd64 as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel9@sha256:b1a02de0dc3ee11c2919f056e6db377fe2df608c82a6dced1af1ea1a230276bb_ppc64le as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel9@sha256:c5a7a5418f3e94573f8357e9f324d5ca5030f22b8d9450995ade1f1a5d722019_s390x as a component of OpenShift Developer Tools and Services 1.6.0
  • registry.redhat.io/source-to-image/source-to-image-rhel9@sha256:f201d7a4151149fe66c6a8acfd12ef0a41bd856a3733520439bea3e044dc12ee_arm64 as a component of OpenShift Developer Tools and Services 1.6.0

✅ Remediation

It is recommended that existing users of Source-to-Image (S2I) upgrade to 1.6.2. There are no changes to any data structures or API’s included within this release. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)