RHSA-2026:65542HighCVSS 7.5

Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.11.0 release

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound

🎯 Affected products14

  • Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:be10082c2fa3d382f9f3f6e9965a5671eb857219506cbe28a84e250abd513289_ppc64le as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:c16f2b226c6fa1df2b0c45271f7429afe5bfb9abeba4c9986a5f10c0ececc0a2_s390x as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:c978aa771ee250022ba72dd67db6ed63613f17f717bc1c07d107a5982d9e3160_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:f44b6f7bd152dbfcfb4f1c067472464d013be031985b8e30370c925abde0c8ec_arm64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:b760df73ba4b903adfc466b427453907850b88a43c7d77c2aadec9d880577243_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:12f2ad8c82a43430eba0caa78fa3c95d7e31d2355d33869e3a470c1fd03901ae_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:3b4357f29551c2e1defbc9fe6d419323339effe87e4e7363e6c7ce7ddb373d3f_ppc64le as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:8a8032c902dc640147300c7ba90c5c34d48c5dba640f501248f87fee8b1928b5_s390x as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:90c3079709e4ca7b69b9f4014cb76c18d0302c5957bb162d34d6dbd35a121cac_arm64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:44df27737d7965f37444baa1dd4bb5f971c0ee4f18709b266184b39081b648c8_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:a7a816f6276bcbaa5b01a8c634feaf37adffb941d48be747fbb7aca3c080b863_arm64 as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:ad9ca1e9011c15176fc2455ddfa0d3fc8f7cdd35161a0ad784371d4cf26d59c2_s390x as a component of Red Hat OpenShift distributed tracing 3.11.0
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:bcbb3cc8a5b081b9afecebdc973cfd8fb78aa7300e20149b59ce28088f1f5a19_ppc64le as a component of Red Hat OpenShift distributed tracing 3.11.0

✅ Remediation

For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (6)