Red Hat Security Advisory: RHTAS 1.4.3 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
🎯 Affected products21
- Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:05184a85ae6e96793f187f93627e8d2ce2c33965df2af53acda0c74955a685a3_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:73501c06ced3fe1a280238b611871b4cd99b646ea2cad5768605f9c1266fc56c_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:c41399a432868f51897c762b2ece554848b06ba40c1f3248dcf100dc2e3d503d_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:ca97d62040ea5c0d0c79a6f049005aa6045d0ab12cf26ed3895b53326e9c36b9_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:54cbc07d0994830217da416e6292ba71d1390bc234380a85eb06b9f7e94e4653_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:b3f6e07279a1fccf9c711d6b1ecb32aaf8090bb0bb452e2c16e8ad907051e9c3_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:bbbd8f5159ed8beaa3ca98114efd6b6381c359ed9341a188470f47942b98606f_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:c261d440478b843d22f4fdc96b1d757eb386c82a0a9e9e06259e0306caf83c10_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:010e5b279bfd40a84ab0bc84b56a6b1df49552c99cf8199d154310d3b014c2cf_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:05eb44a8ecdba9c0366cdf26c43721f32801550bfb340dd38899c734e50b4dca_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:599cda5dbab56f4c93a3e2cd35e74177735dc96680c9809c5dc1765c3bc18143_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:e1c9bfa9841fc20055cba3ab6ba99892ae7bc1931db4f23e0d56511a06afadba_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:2223653550b5b997b079ba5c454cc0ad1d979194f92555b9d2132dcd0e281608_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:2d6400f3d9ee4db96e5f9d3bc2499500e35e0dc0399df5090a41ff9fde4ac729_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:adf057ecf3b9220adfd0ac4aeca581652539f49604bb572581cfc2089fc75e0a_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:de3e98edbc00e2d565949afd3273e4e427a67ac43fb3a3960a05cdea88873216_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:689b66e54119ee8204e5bf7ac63d10635272c911d4b43279004a1df98f0d0ec0_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:9bd519e8a801da58e6f8fcac9aa786d040ca7b626bdb75642e783138082f004f_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:adc83c6f6b1dd619eb8cfbe3e08d07466b762b7b745d0e01df1f96fc64db705b_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:d3d715bbe7fb48fe369b81a8c29f9a9288ce30b5a8964206f6cfe36669e95356_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
✅ Remediation
Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:50869
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50869.json