Red Hat Security Advisory: Assisted Installer RHEL 9 components for Multicluster Engine for Kubernetes 2.6.12
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
🎯 Affected products5
- multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:0dea3f88818977c2392172f46f00c2298360811d7f1d8a8878a947ee986f68e9_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:88a25f8f2cc5c935b8b6f7ffda5beac8d58e3370051cb704dcba9f7fc2c446c4_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:d9d180f6958fbaf250b99cb10d3c955dde07037c01fc39936b74e9cd2484d486_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:ea5ac20c57933b17e55ae6e629ec272f385c3c61d12d0cf91678b6bda12396c8_s390x as a component of multicluster engine for Kubernetes 2.6
✅ Remediation
For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.11. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:36167
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36167.json