Red Hat Security Advisory: RHACS 4.9.11 security and bug fix update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
🎯 Affected products46
- Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:2cc2d55f647a0acd06723bf0c23b16d86f7a84ebdf3b4e05ae7ced26823bb228_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:4e6b9c3daa151288545958cfe856902f9b5e26d50e45366d8be46acc10be32a3_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:797ecb9fda4d0005218cab00b331fab88841f63376889ec9ea121ba67a7fd2b8_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:7df30179329e0320aa98fdf077a6b4bec9759f9c069a720f07b797b7b1593a44_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:7f29f017e737a868ec4b0d9a2afda102d0451b8601059bee4447667d51d6cf65_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:ac722a3422c6f4e3a3310ff40321e72b6b694e6b7b390cb24078962b2192e0bf_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:f1de7ff333ca631ef030257f9a15828e3ed45f512534361fc5e00e8a7ee7337f_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:f38aed9be9df9dec079c5092986de018ba29397087e1b3d0e1ceba2940fafecf_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:2bdeb008b2b3e965cbe66e8683eedd9d80b68fb06fdea198b552b40683b42528_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:50c041d09a8b6623e4868729a253229fa33244cc51520c4fd4ebddcbdd5b66b5_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:67fe3d7db9faec6e98d517dc5b48b05ab9b7f5dd4f37e407dbb7aca8cd3284b9_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:9bb12e25b5f9e2930c56bfd03702e2eff50c5a939b5ce956cadaa1c3a4405a50_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:67d5c0b4730b0dce61aea2edc4f4ca9bf82df5381a8b8b34ac1e683c3224ad04_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:6a8e091c8c3f3ddefb3763fc8bc64940ade011207482ae619700715e19e4ec45_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:bd67020ec13261b52e4c0729d15e5d0f2a3bcfa2d0091c19a7dd21c2d4f4c54b_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:c5a67900cf6ebbbbaf24f777678a3457588f3a839f5caa0652b3d3dc149aa2b8_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:caac0035f166cae79d5be4a7084e8f42cf23efb8dfd1df63e8e294f29ecdce7b_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:5b96e28eabb3b7d40db9cff48c0aa1c45783e7b337c58406cd5c9565f23006e2_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:bcd7c5f40c35376a3525d2ad17dd842e4ce2ac6a3fea017b1fa6ff79c0f21368_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:d55400d4e004a1310b774443cd25fb8b6bdf3e8f9e5af24e00ee26d0012b34a9_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:fe77f65d77790e3e71f7117e62666aa65bdb2572e4afdbd88f272e5038e03622_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:16a49f0abbf2b4193a4ab018f3be334400454ebc4afaffd2c4c505907c7ac4ec_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:1a45d114f30403942d6e5e3b2460b7e2dd03df50abfa8e52fa9986fc1908fc3b_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:3b1b6ac2ea4043c2458e9cf347949e0eceac54f823070aac29191a6b2a5b23e7_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:a939bae7740b3b4ee0ec82b2b2ea4f6bb2ec42061f02a9809639b81b008cf2fb_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:30a55b92e855022fe0f9946d1e01b15d0f521f0d48aea5437da3ca1900a04173_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:4705abeb250d879fc0bdc8c753b9bd84fa9b0b8a67fc0d34ac680d20df3b259e_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:56ea592bab960f3704dd3bff8ee31b1846d8310903ab5ea41e7a6b2d6e15d0df_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:f2924a1724c6e0b79dede1e9c88de322739773ab28c5479c3cd19136717c3f1a_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.9
- +16 more not shown
✅ Remediation
If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:59202
- externalhttps://access.redhat.com/security/cve/CVE-2026-39822
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.9/html-single/release_notes/index#about-this-release-4911_release-notes-49
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59202.json