RHSA-2026:5633HighCVSS 8.2

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.12.8 security update

Published
March 24, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2026-21721 — grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig

🎯 Affected products177

  • Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:20a379058f6e7b95ba010b0ceb936e124a67ad493975557c4bfe085948166b6e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:7fb6e4b9729a300d9e82207ede660b52c2566fcdfb1f7174e5dd4cd59514afdf_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:8a842f5c48c760be11d7df87fc2519bd9a68886bce7240aabea3e7a99c6bc172_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:fdcd8eff118d00b93f7a197c992bd5ddd1cce96b2b5cf3b542403dcbcc812691_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:59a7ad296b2023d6a633e2f7b99767e2c0c35ead31c8d92bdf233ff52522125d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:5a1fba286678b5d606a3ad553041cd68df207820c5f11685f7df0e94d04c27e4_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:60546ec2d4128da096811949b2609bdb9c7cb6205b36673ebe9d7b1ff868ea88_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:647b86bfc09d7eca6a7c3f7ee967ea60db1b90329600a0898f8f8b7bbdb204bf_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:495889c3607c289f7265ef7bf18187686fedcbf8c382e86e8e98cdc31e8479d5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:519bd85630bb8c1eac29ca79a21a09e949fbe507e4186fe5d990c357517731a7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:b97cb625d22889517ef86b148ca4bfcc20e39bb887e0715ac37bd915cf45a83b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:d92337026de448a873fe66754e1ea837f7a650b4c8b1a057cbef1cceb6ae114a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:1ba9482f4a157a04b4b5cc212b7cbb98a323250969501698b230432a6ea545a5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:371bbcd62cb8e6c28cd3c1921e17c9067bc160433c4a6b14a1a2685a5f7d0519_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:922167d560484b217f772384cac0e9da48c31633ebf8984abf3ef99f5c31919b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:fd95f9c98201fc9e2deb2ce1af7598056e7e2bd61e2db42d195fa8acd4958f79_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:280e1dc73ea367d9c818086754ece9ea2d5a2c96496dcfea09844a7a55feb51d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2d8b0b11cf907b25304501a2a62d5551c792c1fb3662ea4cd0e01db724a57b86_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9abfdfd7491e219d7249800e05298472c4d545687fa7b6c79da71f9414f29d12_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:c11c8ba588a27d39f1b46bc6b63eebd8e9f9a822917a7638216c7fb93350aaf3_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:16710678f62e24a8877350bfdada7b8a533d4abad81984145e31614dc0e64d26_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:88c844cba042e1cd006c3ad413808ad10c4bdb95e8c0fc7b79cec3c3c40882b1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:d32bc1e886821ba104e8b2a5e16dc7b0aa1a01ea927e426ebd264298ac1d66f8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:f09e16c30c4641612b2306cdbf56f85e31e03028d522597adf2e00f781148254_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:0dbdb9d02b41e437dd885741918114d8eea5bcdb1e97098b8e026adaf0cc70de_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:5a2014800be744b5034e754ad88cc82c29779c629cf2aa52068274aecd7b9d88_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:dc38a15065a73653097c85f6eb1b287a97498bc69dd86e7dbcd9efe6853255bb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:f544c239f288daac99ca0018719000678f2e9f27b8303a5182fa01777c4c12f0_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0184923381940f806687d21a3422e16bee10b39b409fcecb50c940ed9b7e4d58_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12
  • +147 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)