Red Hat Security Advisory: RHTAS 1.4.3 - Tech Preview Release Of the Model Validation Operator
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
🎯 Affected products4
- Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-validation-agent-rhel9@sha256:95b65949baf82e72266e1e08827318e714bf71e4a1c8716877851483134eb2db_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-validation-operator-bundle@sha256:5ee2989bd15baaaf11684cfcb3b79183d1958be048303235d04c4a14a261718b_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-validation-rhel9-operator@sha256:356e32a685260088ce56bbf6f6e8cd2552c60508f30a75c998dbac538fb54f99_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
✅ Remediation
The Model Validation Operator is a Go-based Kubernetes operator for OpenShift that validates AI/ML models and their signatures at pod runtime. It verifies signatures on model and container artifacts before workloads are allowed to run. Platform Engineers, ML practitioners, and Security teams use it to ensure only trusted, compliant models execute on OCP clusters, in both connected and disconnected environments. For details on using the RHTAS Model Validation Operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:50911
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50911.json