Red Hat Security Advisory: Submariner v0.24 security fixes and container updates
🔗 CVE IDs covered (13)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-62309 — github.com/coredns/coredns: CoreDNS: Denial of Service via crafted UDP datagram with proxyproto plugin CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-66781 — submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication CVE-2026-66782 — submariner-operator: Operator ClusterRole grants cluster-wide create/update on all ConfigMaps CVE-2026-66783 — submariner-operator: Release workflow consumes same-org composite action via mutable @devel branch ref CVE-2026-66785 — submariner: IPsec PSK secrets file created with default world-readable permissions CVE-2026-66786 — submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets CVE-2026-66787 — lighthouse: Go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082 CVE-2026-66788 — lighthouse: Dockerfile build stages use end-of-life Fedora 40 referenced by mutable tag
🎯 Affected products34
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:329806e6d9cee8c20823f45a67c1b0cdb4a8af957c520ef8303557576e8a32f0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:5ae6ea9d9cdeab414a4010e580455a2eb7d1dc23e62d27d1629f531d10930e8d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:6ad357fc6bd252aad971852abf04c809245e8774b0af10b32f9f01393d7abebf_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:ecce053c0601c91638c2f9aea23289e685194839886b5d1701ccbf602d20ce75_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:321dc468744626a9542c344381f9db454d7cbc7a69e3a925365ce1d8ae8ca474_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:4b0e567a6b91e16899ad070e6ebe366885e5c2f333ed5f55cfa7e2bd8fc98565_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:7977035d3755e95121062d90a386a6b23af5d394dacb7c5e622098d70285e1d3_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:d58913107527d89b998ea945f7aa164ee8ca67de994965e7aa08dc659f4dd818_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/nettest-rhel9@sha256:1ff333877495876e1724cb0cbed2b896c7792ff0ce4a15365b2e627d932f77f9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/nettest-rhel9@sha256:341200ef2b4f45418f388138aa76fad3608b138e24ade1277b14805bf1a718bd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/nettest-rhel9@sha256:cdcf36cf6655129561a938b9ebd5104e86bb1ab1cb5afc27acf021b431597d9e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/nettest-rhel9@sha256:d4e3a9606ae6f2cdf2deff18ae688a485560e782b664286d95795ccfb2b73204_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/subctl-rhel9@sha256:1b38ba10de27535bc6e76dac4db2e66b95e7c666f20136c15d7ac11531c541df_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/subctl-rhel9@sha256:a8f500a30142993b8d07f4ed5b29007d89c6edc09ece1bbd72b4467e1a504c6b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/subctl-rhel9@sha256:d5ff003a3893554a20712a9aebda49be7a6e83594ecc5fd8bb898567734c86b8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/subctl-rhel9@sha256:fb5fdb72a0f7d4b8555359d506eebd63d10713a2fd24b5a3669554155f620c62_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:7045277055dbf89b028bab81aaddf2b9793e3f55aa6f611d92c6619c97d0b91f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:73e5857eceadffb8ac80ef9e67720dd13f56ddbc08d6438b936eb3b1f3cfc08b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:7960fe35f5506118d31813c2d263aa8212f32b719b6053fa52c5fe6447b6464c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:bdd03a5cb677b0fa583f223dd9602b53a3d186720ad641e46bde67b2abd69cdc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:38f793d2ffc56c1728eecff1b427435c4580c1edfee32fe747a35cd5951e385c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:933c7641c879446b0c0f145d1a1ac6bda43d397cd3aac9e72195228d6ba6198e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:9cd8f3b7ae72986e653970d8f8a40626fa847e719e36e99fb5c25e1571255b68_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:f2478a2954975e8972458ccd2ae48d81fd1ab4cf393ab427eca0c91c3d0833f1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-operator-bundle@sha256:a8bb318b8afa37daf2ce9394d80c46224e872b593934fbb68fd89e20e6665f84_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:0714135f3594b0e42c4d185779b3a716fc98c6bc35135aa6dec2c9730c93ae52_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:1c0fe9629265844d3cd36fa6fd358026087240dee118e1d438f3ac273f427054_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:5d1225146756be65df394eeb2ec2afa87b025b6e5bfbc9ddd89eaff47d5a40d8_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:93850d48fc8efac7bc3630e4102f5471bcf84921a31c17bc1512e77a4602fc36_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- +4 more not shown
✅ Remediation
For release note details, see the upstream Submariner release notes: https://submariner.io/community/releases/ Downstream-specific issues resolved: * ACM-30182 * ACM-32385 * ACM-34578 * ACM-34651 * ACM-34693 * ACM-36281 * ACM-36898 * ACM-36899 * ACM-36907 * ACM-36909 * ACM-36910 * ACM-36911 * ACM-36912 * ACM-36927 * ACM-38289 * ACM-38295 * ACM-38315 * ACM-38320 * ACM-38322 * ACM-38330 * ACM-38357 * ACM-38360 * ACM-38447 * ACM-38448 * ACM-38449 * ACM-38450 * ACM-38451 * ACM-38452 * ACM-38453 * ACM-38466 * ACM-38494 * ACM-38495 * ACM-38496 * ACM-38497 * ACM-38499 * ACM-38500 * ACM-38513 * ACM-38515 * ACM-38519 * ACM-38520 * ACM-38533 * ACM-38538 * ACM-38542 * ACM-38546 * ACM-39374 * ACM-39382 * ACM-39384 * ACM-39385 * ACM-39510 * ACM-39511 * ACM-39568 * ACM-40464 * ACM-41039 * ACM-42640 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate this vulnerability, disable the `proxyproto` plugin in your CoreDNS configuration if it is not strictly required. If the `proxyproto` plugin is essential for your deployment, restrict network access to the CoreDNS service to only trusted sources. This can be achieved by configuring firewall rules to limit UDP traffic on the CoreDNS port. Any changes to the CoreDNS configuration will require a restart or reload of the CoreDNS service to take effect, which may temporarily disrupt DNS resolution. Workaround: To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK. Workaround: To mitigate this issue, ensure that access to Submariner Custom Resources (CRs) is strictly controlled. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit read access to Submariner CRs only to authorized administrators and components that explicitly require it. This reduces the risk of unauthorized disclosure of the broker Service Account bearer token, which may be stored in cleartext within the CR's specification field. Review existing RBAC configurations to ensure least privilege is applied to resources containing sensitive information. Workaround: To mitigate this issue, restrict access to cluster-admin roles and carefully control permissions for users or service accounts that can modify Submariner Custom Resources. Ensure that only trusted and authorized personnel have the ability to patch Submariner CRs, thereby preventing the injection of malicious images. Workaround: If Submariner certificate-based IPsec authentication mode is enabled (`IPSecCertAuthMode: true` in the SubmarinerConfig), administrators can mitigate this flaw by switching to the default pre-shared key (PSK) authentication mode. Set `IPSecCertAuthMode: false` (or remove the field to use its default value) in the SubmarinerConfig CR and redeploy the Submariner gateway pods. PSK mode provides equivalent inter-cluster IPsec tunnel encryption and is not affected by this vulnerability. Note that disabling cert-auth mode means Submariner will no longer integrate with OVN IPsec's certificate infrastructure and will manage its own PSK-based authentication independently.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:63016
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-62309
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-66781
- externalhttps://access.redhat.com/security/cve/CVE-2026-66782
- externalhttps://access.redhat.com/security/cve/CVE-2026-66783
- externalhttps://access.redhat.com/security/cve/CVE-2026-66785
- externalhttps://access.redhat.com/security/cve/CVE-2026-66786
- externalhttps://access.redhat.com/security/cve/CVE-2026-66787
- externalhttps://access.redhat.com/security/cve/CVE-2026-66788
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63016.json