Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.10 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:31bd91156f49687d2efffd3be971d9ee0e16abb420b8e8b958caa88b97770020_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:a6315866c67ba350665f5a92f960a5a44e427ca37ae7505e2072af4e02c42f76_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:b3ad6fa1de658f3a40c8b183ab501ebc66b359d8cc01439d4215aa52769df213_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:bfde9ebea1fcd27b6d104d5f67db62e870878f9517ccbec2f649dd2c1af4a073_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:08fed161d59299881ff7a54db859feaf8ed7bdb8238d6cf12628ccb73575665e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:09436fe2649ca384b1bc1fd8f736fb1d71392733310e66758ed9f289e00471f9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:3b83670e1c0e9d1f5b76bd7b75d77072bc6208646bc2201bd0bd200dbc59e34a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:927146f966e4c5c2908d29d8ab45a8f3071dbd5ebd9cf0424460a23f814a72a7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:38a3bc59511133cae56827eba879e7c82c5a974bf1f16b6e8d95e1f79821e669_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:3fa04db82e3ce6169270db0ce29107b69d8e044e0a1ab13a2bf1050b8c26d087_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:6041a918713d4464c73560b68c294a12d33f297a980d2f9d0e0cc8c300a96f24_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:98bd72ba69bdfb3070d87b3edcbd7050579a514b72cfd67c2926541ba52dbaf7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:938abc970731c2eeda8e2b7b73e96d4dfcbf7587330c7b7e52117a577700e426_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:a0876a25ce85d7d4616212813f012422826f152b8d71065e75cd9c3e23034d8a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:c77077a0cca835a503a6529c89ab19c4027f949d361afdf8a5a259e1e87b0d55_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d5bbf3fe886f27cdc27363dcb175e004487d9c8f36de4f1f8516fbeda3a95224_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:0f5d8cae3ba4ea4fcdc5fb9d08f797d576bc225b92af66f193bd4b1324cda4b9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2d3588825f8a714fa59b1648d0934d064165e333f322f7f31f01f07b940d42d9_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:68aa571827f5331f1d5a3bd0c60ad441a18877ba11921aff2633940236bafcd4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9b80c9c61d4befefa7f6a65ae8c001ce7e343a1e4f251e5ebe025625d9511730_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:9b2c24401a91903f023096d2b641aa977acff423eb6770a8e4c4a81aecfd4e62_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:9d74585acc098c13f3e9dac5ae7f5ef337fa82bd7119d7f1849c5f8a50e84907_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:a6ee95d0ed82bddef084684d11fa770bd646d9be9bc65b3bc386d7c58b33975c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:f7b8654eb8bf675c8c26f0ad395d790f990308d3ad6683bb61b484c92073bbac_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:2a598e7fd07db27100d9a53a328ac9a0535865883bddd1373f4f1f2705068d2f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:4f8f0b02d0969753e156226a998d442746c238a2a50ea606a49ca0cf695b8925_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:63c02348faa7d4e26e35c69aef5453613dd607a26116823b931b89fe5311e181_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ae224866f0085d2c00ab18a28d2aed076e455731903989a49a544abf49950d1f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0a90a13f006ef0b271079b728ef6d54081f36ae19b6d0e9ab4dc24ea52a30fad_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:47737
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45447
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-50151
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47737.json