Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🎯 Affected products6
- Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-operator-bundle@sha256:0afe9ca958403340a8ab4d89e07c4b685ea69cbfd5b94c3bc76b5db85afd152d_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:77f1e202337d716cd2fe7a6701efdeed9cae719f3dfdadf7a0fd4574a11b6ed8_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:b362fa9e2a18aa84f2393cce8555d34a9c8de822c65756897717ad54e2aa7c45_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:bb7ee5838e15f9a31c12af6f4629bb90ac0b41eeee98e0bac4642c6a764944cb_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:c7d68fdde482c4df1768b99ca6cb6fb358410a152020aca8cfac27bcf77d813b_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:22485
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33810
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22485.json