Red Hat Security Advisory: Red Hat OpenShift Builds 1.7.4
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-10840 — openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to Kueue and cert-manager resources CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39833 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
🎯 Affected products38
- Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:09fdae42b81088e67a3f29e32ac980d57652d8ddbe9665b86aab69b37a4327bd_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:0ef830a815d07df60291e9c7b89a03dd40c0ceabfc3071f1fe188575f65a0542_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:59bc241a2a06804393a63785eeb8f0a8165a99263f08e0ffc3e727671c214114_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:af26444b2b45eb9c726b8d0cc92f023c4f4e52c9fb839198ad862d6513e2683f_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:0a189209a84ceddfbbfdba58e43fe94b5ddd211982a58a0929eb9997d3bf585a_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:2d8b7f64fa620bfce0130c52b977942ec9118fafddc9c090994609ab274df00c_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:a18b4c58e2b285058541b77a47d6482a9db6be58756651df3b3c648548a44f8e_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:cebcaaef5272faa6e6f147eeb966803b7cb3d3fbc86514132f6ad2e8b51e4557_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:64c957565dd799994cab0828a9c1169c128ca20e8b103af6b6ac2f422077e322_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:8c8aa38871ee6d945a186d0e3a7b129bafd08d53e52278e1eb6d8011491240dd_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:a473e11982fd3d970a3e28d7e103ee40fd50217cb0de7028edfae345c34bcbc0_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:ccf2448519c0998d9843fa570f128f420326e849c8c69dd3c5b526c3444d9f50_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:7bda73fcb94b412a8799bd11915066b07ed341fed2cd0ab81776f4c601926b54_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:992588aab0cfe3ec909418e827ca46828d0a07d9e3e1479fed437c9c445d7ff0_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:a80038bcbb994457fda1443b37dee5fbe66bbb02972b38139a9877e978c73835_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:cf2318bcce1f1a565bcfdb722d89e0ddb2e88a523db237e926def3934add78e5_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:24c95ad401a653c88d072a7753052850cfa6738686ce9aec7ba5f6fcbc92e7fc_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:189d8de6e11f86cd47891d2268c2a91134a6fe617ecbbc433dda7a7f68519421_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:61007260c34ec5113e4286f679a5377c64fb6ad934aee5de6928f4c06c54e969_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:779614a189b230b5c78cd28e360d9e7fabb519aef73a5acacb26b3c26716c68d_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:898bf1c9ee31508ffb2d72deaa97f0b02639e22063788448bbe55f5b98d8db7b_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:0a2acfdea8fb6b49a6117d8914e9ae56bc4668ce882131a47923fc0c7ab7c6b6_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:37415ef53ed46fcc1fd8010da38f13ffc9015f8435306b7dcf16bb3ed117083b_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:626527f0b4701d00b845c8bca201f81756a0577a555447ea90b8903b0f968e12_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:98ad870b2929bc5db27a7cf0f9f0791f82d6889673ce7d102838616c466af612_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:2d1e27a8dc06bc78b251796816e89ff0ad7ee91ccd9077db47d245fb5ae5d291_arm64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:c472058fc730b6ea6d064cd77dfa583340976209afe109fee9296012f02df66f_amd64 as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:d3ca3c7f85c104a6ae087dccd37e328e1cdeb5b93a880b48e1f2c99c015fd101_s390x as a component of Red Hat OpenShift Builds 1.7.3
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:fa3f9534ea19d8828c2342b3557f652196aec37552fa49e83af6dd1b0c356d69_ppc64le as a component of Red Hat OpenShift Builds 1.7.3
- +8 more not shown
✅ Remediation
It is recommended that existing users of Red Hat OpenShift Builds 1.7.3 upgrade to 1.7.4 Workaround: If the Tekton Scheduler feature is not in use, administrators can mitigate this by patching the ClusterRoleBinding to reference a specific ServiceAccount instead of system:authenticated: oc patch clusterrolebinding tekton-scheduler-rolebinding --type=merge -p '{"subjects": [{"kind": "ServiceAccount", "name": "openshift-pipelines-operator", "namespace": "openshift-operators"}]}' IMPORTANT: The OpenShift Pipelines operator's reconciliation loop may revert this manual patch. Verify that the operator does not reconcile this binding back to system:authenticated after applying the mitigation. If it does, scale down the operator deployment or configure the operator to skip reconciliation of this object. Alternatively, the ClusterRoleBinding can be deleted if the Tekton Scheduler is not enabled. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Update affected Go applications to use golang.org/x/crypto version 0.52.0 or later, which rejects unsupported ConfirmBeforeUse keys instead of silently ignoring the constraint. As a workaround, do not add keys with ConfirmBeforeUse to the in-memory keyring from golang.org/x/crypto/ssh/agent, or use an SSH agent implementation that correctly enforces confirm-before-use.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:36648
- externalhttps://access.redhat.com/security/cve/CVE-2026-10840
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39833
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/builds_for_red_hat_openshift/1.7
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36648.json