Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.5 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2024-45336 — golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66808 — hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)
🎯 Affected products125
- multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:120becd4f1b2a36f48a43d2933b7a1be1595cc2cb626d44a053033d010e6aac7_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:610df72fa91b7ff983c5698c08462a2c77ec60d2940e8c0048054d14fd0a3e31_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:675af2b54df773d590a2543225c7c5cce1e9a6b0f3651a8e454c02dde506a580_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b69db5c2aac4decf99a4c97c09e9c7055b642c4849f7e78d74f78877702428e8_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:07d634b81a8d2b36bfa1608edf2cd79c144da7a0f102bff4b215260cd79b4825_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:317647b20d3187f70e42a9c949babc179c16f2455aeafd11cba236f28fa0cf09_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:979bd4d1bd8edd0e89079f82c20d569665f4995e65ac5d8455fd89e1b7eeea52_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:b1e309ba995955d80bd8d3fd3577a42b03412a47d6e98cbdd8e491ed15edb919_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:0ac4fa3c84c455fe75f83cf706fe70ec4c20c4099013512a0aa7f9894b6a7c6b_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:60a9d2ecda391d879b53330702b3b3e28af5fbb32b419c0061ee710302bd02e5_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:6fdfb1894d8b5579119a50b2f1158055a5a60ada8a3e30528d0ef47616853da3_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:965a2b59ba300852421a71c0b10fdd91b8347fa8d4b70ccff76df4df3d2271ff_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:3970ffab169370577f2a69e2f79d68c7ed1a007a18bf2797e477c1039e53d718_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:c30bef6a17387423d54aaff9ad2ad3905366d8401b0b866234f09a0e6de2a018_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:d233ecc2ff49b650f617f56cfa187910ef6a1a0c20de24a154c7292eae1888fe_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:ff8266a88d6321a29469ea13404e714f10aae949e9394e24633b43304f54b121_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:22d2a996d18d00f5985f381e395b33186c2af759fba010bec0cc9f3120be3d3a_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:51b926dc40fa8abe32f1a31f419d6e38d2ac322dc5973650bf0326afd841edd7_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c86653f45ed8c480589f2d3cde84e1de45e23dbdeb7dcc398d5f0121ebc9215f_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:dbe55cb7c87224ae10d5b157ef5e66a4ffe4788bfb134a3db47d2c1bceab4eec_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:0815b6568f3c2df6d86aa70458a3037d0251f58a673244f13defcfa9053d4019_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:2fc1ac0ac7950482cc4ee05aea133af511ebfcfbe45e0fa3d13f33c983a1a75a_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:48d38b946e601b8bfebe7fac00d538f01b6e565f01f76681059af7001d1a42a6_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:81b31ada806558c18afb7bfcdaf1bc74ae92245e2f42aade9d80c59be2fa9a4c_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:3b69bad711b3358fa22546c193d0b7d15c96c1b0c445b36da1d426695516634d_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:72514aafb15a0988ec5d65cd01a90bd0c58010cce32af69c3d42b4d3a051a892_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:aa964bc0245cd01f2077b2f28567048ccb638cb899eefa66383dbcc2d53bcf3d_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:affbb00a938b6306fc357de5f5b5b48c1bc493a280b9db94cc0a5d545337934f_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:1b5f4016b9554486a3af91dc348c7d34ed1e55fe7649453a9ea1fe6ea07645c1_ppc64le as a component of multicluster engine for Kubernetes 2.10
- +95 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#mce-install-intro Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:54432
- externalhttps://access.redhat.com/security/cve/CVE-2024-45336
- externalhttps://access.redhat.com/security/cve/CVE-2025-22866
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66808
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54432.json