RHSA-2026:36873HighCVSS 8.8

Red Hat Security Advisory: Submariner v0.20 security fixes and container updates

Published
July 8, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2025-47950 — coredns: CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification CVE-2025-59530 — github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2025-68151 — github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages CVE-2026-26017 — github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw CVE-2026-26018 — github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.

🎯 Affected products34

  • Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:08c46fced26b98ad3e1a07a3f3c7239521d916bfe116d2e7a44068011319ccd3_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:b6aac33c3af11a883a7c45d6dc8392d9ffc8fff09b21f31404b97e48beebbe7b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:c045357b268bc940f2ccd50d17eaeba2a80f332a4b76baff1fcfdec8992eb785_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:f856073e50bb0cc5519d7ec413e4ff92da750fbce141cefbeaf3dd945149ea06_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:2d9c2c52df2251db58f47eb0b982ecf62175d9aa29ba7a6a3d72001034441390_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:4fb8d0f81059a89c233aa55d72b5007c42811557a815ce0ec7f3ee042cb6a560_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:548a13d40574a1efd59f327a0d9193ff8e0109b571645ea16721347a89774e0d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:f10f17672a539dd7a7f5f40b52d9bed10ea03438141259e7fbe75373c73985f5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/nettest-rhel9@sha256:0bafca38a2e80233c1b859d4bc2d9bde815678460cf71d5aac5804a1524344dc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/nettest-rhel9@sha256:74f9c159bf2af9e6fc2188234ba7146f00519f130e9d7c2d14902e73a0c115bd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/nettest-rhel9@sha256:cbbb16e36221a15955a62d54ff631029080ab27f92d8c6b9e4507bf4d32b686f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/nettest-rhel9@sha256:e17325bedd6b7212772ea2888a703b159115cd573320c5313bd649c962674e60_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/subctl-rhel9@sha256:438c6d99281497b67dfdf4d2bb5f5c13abf1fce3ea6f50d96ed5f5c88fe5086e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/subctl-rhel9@sha256:a8b2139b2664316d43fc31479c468b4af7afb0d370a81a794bd71dbb4d97de0f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/subctl-rhel9@sha256:d6e2d8f486276918329ca386bd54385d944009a412830d8d3c175ab38f23dcf4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/subctl-rhel9@sha256:e0e37798c3c66494c68259d79ead0e18fe7327f27c7babf72386b210595f1877_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:3ddcf732be3481259c42b647cb273b5968ddf2d5ff5c31de4ee8cfbe3182c238_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:9abe7999226734514841159e0555e5a13be581b84c7bd9899f7f956dae5fea07_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:cdd5f5b983486e39cdaa76f3fb97266994863b68be8dd1fabdba8592f0f4b581_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:e2da53cce8f1e6fa1a6d235047b709835f08d1186833baae48ce106dd9029e25_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:1605dc6f3baba80be77d26e09d32a3adfc4711fdbf90dca8f821dcae6131cb95_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:21f72fb118a708fcf5e0bb6dc5091954275f0496c0f4fbd67937c2ef6e94a12b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:4e0213961fd6865df9076e5c613370a45f68ba6fef646e0e23492358d00d167c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:cdb56f8231fef80d46bf68132c1e7a40fd2592e3024590cea801ece6d3de6b14_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-operator-bundle@sha256:dddc574f9c2ed8e7266522761842ea2c88e9cad3e284cf9c3522fd5e834d82ef_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:62857f91e51e167d39fcf932c444d04b6105720299372789fe97941aafa5ff52_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:85cf9cf1f440604ad7346608d6920720acc9e75b2a0c3579439e73d0a7278554_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:bda6bd1cadc353bf93dbb387b0e473840efa4488a11488b9e0f91e22a86cb834_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:cda143023feee01e4cd88a075c93a587ed14f6071611ef2516d89ad33f51ee0d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • +4 more not shown

✅ Remediation

For release note details, see the upstream Submariner release notes: https://submariner.io/community/releases/ Downstream-specific issues resolved: * ACM-17819 * ACM-21727 * ACM-21731 * ACM-24786 * ACM-25148 * ACM-25152 * ACM-25169 * ACM-29510 * ACM-29564 * ACM-29565 * ACM-29574 * ACM-29584 * ACM-29585 * ACM-29586 * ACM-29587 * ACM-29774 * ACM-29775 * ACM-29800 * ACM-30133 * ACM-30722 * ACM-30723 * ACM-30724 * ACM-30725 * ACM-30970 * ACM-36662 * ACM-37000 * ACM-37038 * ACM-7515 * ACM-8292 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/ Workaround: Users unable to upgrade should manually disable the QUIC protocol support. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (14)