Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.10.2 release
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-5435 — glibc: glibc: Out-of-bounds write via TSIG record processing CVE-2026-5928 — glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings CVE-2026-6238 — glibc: glibc: Application crash or uninitialized memory read via crafted DNS response CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal
🎯 Affected products26
- Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5d37a9295fcff51eae08cfda93f8fd9150ed8481bf65a71744ad5535b861225d_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:ddb66284889add51287b8d61052bd00d8a0ef516fbc0829a2a4b4b99bdeba5fc_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:ebb47074d9e7e06f56284253edaefb60ed4bf5efc1c3cecf9f4c49edeaf3a209_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:faf4ba531c623ea0d19755b77f2138dbaa43a51a0775b4ee02d1225316dc654c_s390x as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:0df194c5cb39115f89e8df733e39d94ea12c834fa9e8a29198a8a5cdb84553e0_s390x as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:28219c674953a66c96fe7db3c684c26829a295f3ba1ded42f739124c2da040ba_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:52c3188a11918718364db6dd46fb1b9cfcdd06bb83e6262b874368a5d9c3242d_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:90d32605a91f99e3bf54577014cb33bc19afb96f6f3e47b8b00cd5e2628512f3_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:10a722d4a344473cbcf8c808800328d4f7ebed295defeb5c415e17e0398b0b5b_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:390785f43baa818e969bc4deff6734ef30cbabb442acf0c40af205caece7b3cd_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6818877323264424695b25c3353b506b659424d07f55f128a3add92c32ca9747_s390x as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:b911ca02d5b6503b37854c840be1cd1abb08a66160ab5a5a7a9d0d77881739ca_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:40c77256530f670a5951bb76fd98780b04756f5bc533c885dcd227a0155ad303_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:2ba02d10898f9d23098f89fdcc873ca2902159d598077a8a793cde6924ea0ea2_s390x as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:4043b1f73650dae9fbaa0f68eb50930011763abeab0f123f04a2c849fd413023_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:50d6dd1edf4bf2cbf4cc03946d0ea3db17b5a7b72b8ff827a0be7a0981403c4d_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:8e2efa2a279952d22dba9703d08ea887121a969b045923764063a10f167a3412_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:0ff040679a174fa9d9d23042349d5071dae8c7e7091dccce4c6ee2123a69ae35_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:948718d12957aca408a173259fda1151e30644d6423eeed740ea21d7f7bb2262_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:d1ecde6e98b112a31d78156b1df2490eb4529e46f52b3a5253680c8ad0ce0e6a_s390x as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:fefa59c75182e18ec20e3efe5acd1456e113c36e3347fae4fe457d5bde7761f1_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9@sha256:1fd5fdd5a09d85f2cce8ab19726e68606af7a45012bfc0a7a9f8aa9af2cee255_s390x as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9@sha256:bc2a9f9b0174d8bb70d6ce582c197bf2c397f0b9be70df5d32cdecbc352665a4_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9@sha256:cdf828754abcd22e000f52ecabc500ac632cc2a46280332f49ebf8fd4e479387_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.2
- registry.redhat.io/rhosdt/tempo-rhel9@sha256:d95e74f5a3c907455a884c5a0c23bdf668e4a8dcea44c124bf8c862daf6237f9_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.2
✅ Remediation
For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:44624
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39822
- externalhttps://access.redhat.com/security/cve/CVE-2026-5435
- externalhttps://access.redhat.com/security/cve/CVE-2026-5928
- externalhttps://access.redhat.com/security/cve/CVE-2026-6238
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/distributed_tracing/distributed-tracing-platform-tempo
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44624.json