Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42211 — react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode CVE-2026-47262 — github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing
🎯 Affected products4
- Red Hat Hardened Images
- opentelemetry-collector-contrib-main@aarch64 as a component of Red Hat Hardened Images
- opentelemetry-collector-contrib-main@src as a component of Red Hat Hardened Images
- opentelemetry-collector-contrib-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: To mitigate this vulnerability, ensure that applications using React Router are not configured in Framework Mode. Instead, utilize Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`), as these modes are not susceptible to this flaw. Workaround: No mitigation is needed for Red Hat products. The vulnerable code path in containerd's CRI plugin group-parsing logic is not executed because Red Hat uses CRI-O as the container runtime. Products that bundle containerd as a library dependency for OCI image operations are not affected.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:29770
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-47262
- externalhttps://access.redhat.com/security/cve/CVE-2026-42211
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_29770.json