Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.6.1
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-18140 — aws-smithy-json: aws-smithy-json: Denial of Service via uncontrolled recursion with deeply nested JSON CVE-2026-29181 — github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-75593 — github.com/moby/buildkit: BuildKit: File escape vulnerability allows unauthorized file modification
🎯 Affected products35
- Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:b70b971f9692763a3941e2bd6b14f0c42da9ea1463611c580ab97dd35a2d05d6_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:7a67cfa1080e9907b11e848e57248585fe9abc116c52c27219da2a0bcb14dd48_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:7da78fcfc9a68e0cd20c3669dbe36463157f9300cdcffadbe307e05362e5cc10_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:b7ce1ff86db289869a70e85f04afdea0ebc5a6d0355a4a1852574cb2d168e761_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:eb894abcb44c991cae390e8e98204d288dce15ac02f291fa1c4d653dd3b6a9fd_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:2afdc9734eae1ef40de4550f3fbaf76b504333804f5eb75be037849a9dafca84_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:8f0a7bc5882e476b97310a278e237d5a656bb58b91fca77b70610931d9020550_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:c3aa1419e70e5331eea0b3cc761869d2b9ca2bc43be1a3a948b2f9dc086189ba_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:fc97d3d4bee4ed82a6824ae07e2488f2f58e441cd0ad400a2ba3feb781838f6c_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:1be7f16e2465e30bb5c1685acec962f2999a162c87e9dc0c17ec3389c3d3bb3f_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:540f6b00efbcc520196e807fbbc5c1b982fd080873e911147a60b0c9e3c0e4d1_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:d39f996011dfd2daaa5cfe9d263f46a4024074d88c884d78393a40fdb9c56624_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:d49eb46ee45c07d34dbf5ee769ae95cb50f3595ef5ef82f034500d1ffd0c629e_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:4df1e7b6b03bafee47e9474b3332fb50613e0a843da82a6b2c5810b127ea0ca4_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:661253d8317a91ad3077ab8572943dc8b37dd1e62ca7795ba0b1869a2eebf5a0_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:718f7a43dfd4ba546ca0a09c61bd7cf90acf200a1c889c75285f1b148974cb52_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:72ae49d6a4343093cc2ef0fc98ee2a9e27cb747c17e33ff9e2a69b17d4449378_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:04bcd8f7bc94a504e7b0f60d4f68a047c1ede64c5cb45a78971bdb0b33ceb53d_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:27c478f87c6095287e3cf1ce769ded5b16792f911ffa24726bd5968f8cae68e5_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:2ad6308eecf1c4e6cbe911098ff6fbc11bc5836d5369d9d314058198c88744a2_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:8cdb179af25749ac44844e045d2b64826398fa6b4ca2dab94c6aad30d630cc98_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:8db46da735f9196011098f825ccfe1347d76a3a85e22b0e9c46c54b33452ccc0_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:6ec0bb95f6f87615ba3dab2e6232c44f3dae7ecdc291e50bb605580a221d95ac_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:9274be691efca76b4362b6e482c1abfa08292d2718b6bfca788dba47412a45f2_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:ddbf530f7ec5f0676cd92c023e1f5105dca537d67b49a401267a6a7b50ff3bcb_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:f8926ba9afde4be23599a36a60c05e56c1c6395d522f0ac355829bb93f77032c_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:01202b83e79f9cc08b3befa27f932a08f2021d634bcc60afb8275a3cf049d153_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:30e751b1b2b86757102d9378f201a5f5b0acfd7d2d599e2d67ebf4bd9aa13142_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.6
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:dce6f5acebed618c32876118ad7636a7ea24e6abf8b3406fa886620a97b7d677_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.6
- +5 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ocp-4-22-release-notes For Red Hat OpenShift Logging 6.6, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.6 Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Restrict network access to services that process JSON input using the `aws-smithy-json` runtime. Configure firewalls to limit incoming connections to trusted sources, thereby reducing the exposure to remote unauthenticated denial of service attacks. If the service is reloaded or restarted, ensure firewall rules persist. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:66521
- externalhttps://access.redhat.com/security/cve/CVE-2026-15792
- externalhttps://access.redhat.com/security/cve/CVE-2026-17106
- externalhttps://access.redhat.com/security/cve/CVE-2026-18140
- externalhttps://access.redhat.com/security/cve/CVE-2026-29181
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-75593
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66521.json