Red Hat Security Advisory: Multicluster Global Hub 1.8.1 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33376 — grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-55677 — github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-66801 — multicluster-global-hub: multicluster-global-hub: shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
🎯 Affected products22
- Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:20dd82ac568612c5a3ed26229079a0fe338a76052e2a96c13d4a9ce88be430c3_ppc64le as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:5292916fe3b9e955345d049a003fda95983ef54495f9af1b16d1ed7587266249_s390x as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:629c601f75821fc79cc905ddeef2301c20f89932a5bc4b2d71b86deb5da75b63_arm64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:8607fc079dce6f19c28d865f795d8ebad05cf4fec6f87e5e524d2a038430edc5_amd64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:09f57ff7ccf26c7034221ac57936aa8ae6e6ef1b6406d0050949917ca68ce146_s390x as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:0cd013a1552dae6134812eb39c9ddf46b5a5b16c8f433fdc95f16f8765a72a18_arm64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:42d8ea192a05154b22fb0109c163791088130a10471b3c9ab03b8d55b7ee8fcf_ppc64le as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:eac0133e4c8130d6ee373faa034e920070db1515212bfd0c9a6d559cd31a6647_amd64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:0d1f2503b10bda1c3d075a57c7ba23759dd42101edda14edf59a4c05da0b095f_ppc64le as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:69229a78e4a5f37c5b3ecce7b8056fd43ab7aa3ec581a0b180e38de6866253c2_arm64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:7c3acb82221c3da1df4cba5d655ae19120f05ee22d03dc149b7c6a9db7a0c076_amd64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:ca8bf1d0e387476163e21d18dd6ab195f0348ef498fe61b058fb284d62b131cb_s390x as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:9fa9b4a4984fa2c8057ec7375a613a302bf6a99ec5c6059dfb43e35fb3a29ae8_amd64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:0f4674f643df1e8cfe5b11d9c992e85b32dc915ab951c080b7456acd34069fdd_arm64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:19e202dabb23f7c070fcf589ce4fd6f36ae7ea9813d947ace90b60e43b9aeac9_s390x as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:660024abdf32887c978d5e19b7a968c0d04d94f50937aa948d0c8b2cfd74e548_ppc64le as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:737736d10e925c7f8de9560552735aa0bc4404470a3a4fa5e60b63d383b28037_amd64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:068e16c4575f853f8a292bc3f34d50ee0fdb76e410d5e6a273399d5e7533ec31_ppc64le as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:351c748dd43ee596b8565f4742569fec5dd6c41f6c0646f4b58ab1ee4bc8b603_amd64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b421850439207c883866768499822794db6c04a473f8fa80d553e3b35e595e33_arm64 as a component of Multicluster Global Hub 1.8.0
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:f1f58a76e9278fbe234cf6ca99383a96fabd716186d9f1908080b4532ce3c7fb_s390x as a component of Multicluster Global Hub 1.8.0
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/multicluster_global_hub/index Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, explicitly specify the intended IPv6 address mask—typically /128 for a single host—within the Grafana Auth Proxy allow-list configuration. This overrides the incorrect default /32 mask, ensuring that network access restrictions are applied strictly as intended. For RHEL: Update the whitelist directive under the [auth.proxy] section in /etc/grafana/grafana.ini. For example, if ::1 is the desired address, configure it explicitly as ::1/128. A restart of the Grafana service (systemctl restart grafana-server) is required for the changes to take effect. Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:52946
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33376
- externalhttps://access.redhat.com/security/cve/CVE-2026-33377
- externalhttps://access.redhat.com/security/cve/CVE-2026-53492
- externalhttps://access.redhat.com/security/cve/CVE-2026-55677
- externalhttps://access.redhat.com/security/cve/CVE-2026-55969
- externalhttps://access.redhat.com/security/cve/CVE-2026-66801
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_52946.json