Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
🔗 CVE IDs covered (32)
📋 Description
CVE-2024-25621 — github.com/containerd/containerd: containerd local privilege escalation CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33747 — BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend CVE-2026-33748 — github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42306 — github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
🎯 Affected products46
- OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:31a22af5fb2d2767267b80b3c15dab1ed0c2620eb1d33ffa4c4c24ca57071cf9_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:48a9021e3e559028b47eb049452df977177c93093d59131098ac0b6b10026213_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:56a93ad53df1c0445b3fee293ab42caa375f88b72872d8fb844efeb114869eaa_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:93fa051884d7ca638e8aee7244dc1635e1b1d07d05d7e7098fee24aae642afb4_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:4d763201b2daa4fe2e7f74fb42671e9752b9c301272b357d9e810420a617aff2_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:4f2300a741dd4e84bf99b1ff738a00fddd52b75db4b69ad42f3faf47e8ae3e75_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:956de2cb9012bb5d0cc0eee438e58dab3090f445617aa4f3361dbe7f9f151eb0_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:cf80473217c222c4e5cc7451f5a256422b553e01df03113b758e4172c3a3b5f3_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:93d8ce09a06af1c287ebe7616ebc38f6cf0acb52e11f96dbfbcca583c5e0540f_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:9ef46cc9fe1bb0608aba0b4d72bb1a1479e93e96f8cae8eea01643689fa568c5_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:cc86577f50b381f29b2a065527f227f5968be315908fc1683c89d52bafdf8f60_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:eea354fd6baee1b98e209e06863a04975885a3c12be678f3e33bcdd077549030_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-operator-bundle@sha256:bf818a9af2dc1e22b2c24d07d8e52f65453b529076277fb3eb26069aa4ad3484_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:54db3ee0284dbebea5017981abb6f7c710d7f1c505389931290d39a926cc805e_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:5c0f39a8d788109cf25cee0fa5d0f62024303a7f396b011ea257a4d89ba062cb_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:b38f0ae8f13ad9f9c8088d46b1e38b1348976dbfae03338cacf84c9f3ff7d6a3_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:c2ad30f62435ccf5250dab6e6e8286ca733cd513c8ab98b9d59ae3f20f606d10_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:1f2aa602270f1997e13f242fc75c52356de0c24ba68640b042e5d16280901e44_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:2e742bb7f42f63c253d8c027783f4722e5c140ca9f2fe9872cb874c2886535b2_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:4c20843755e2706f863274be9159a5e8e07895af8f70518b95bff5daf441e78e_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:b26b7bc0844ba584035ede98486feead55b5066667e068d05fcbeb6cc971b0e6_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:345f3aa4c15440f3a49513a2f49631799a0d9dda8ff1f3cd114adbc1e9d996c5_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:46227e86cc58f7b19655017b313bc8bcdd38f1f78d4f52f4a68428dfc54e3dfc_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:9e2cde3376ceec8f2794102f2b9834298eda10c9f7fe947c56f684fd493d8a75_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:e23a3ed44476b29116abc947f84e0134800ac5a3a97a4d7b6338d02a77940552_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:19b74fe19c3e183f37af9f8db97eb7ab858c46c6c5bf6c10154f622948dd327b_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:43f70e447a16f13fb6f54c3b5b924ca475be3aa6e5af8cc5445728488e2d6025_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:fa94619dec5548247a1b304e060094e07878276a6ee1351010d0a4cae5023af1_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:fd943aa4cdb7f56dd2b3a5ed30d4ba635e2c238e4cb5e8577671d301ef3129ab_amd64 as a component of OpenShift API for Data Protection 1.3
- +16 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: The system administrator on the host can manually chmod the directories to not have group or world accessible permissions: ``` chmod 700 /var/lib/containerd chmod 700 /run/containerd/io.containerd.grpc.v1.cri chmod 700 /run/containerd/io.containerd.sandbox.controller.v1.shim ``` An alternative mitigation would be to run containerd in rootless mode. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.
🔗 References (36)
- selfhttps://access.redhat.com/errata/RHSA-2026:51033
- externalhttps://access.redhat.com/security/cve/CVE-2024-25621
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-66506
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33747
- externalhttps://access.redhat.com/security/cve/CVE-2026-33748
- externalhttps://access.redhat.com/security/cve/CVE-2026-33810
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42306
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-53492
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restore
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_51033.json