Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.5 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-89060 — stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:3a8233dd6636564dfe7206adfcbfe864ee03d8b6534ac5fe0a05bf190e1285af_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:4d087e12b47de749741d32e6352a73f8a6af2bd5e488001eda4299889393874d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:549567f3d2667b89a55bdeae3d716b3396d161137032bc110fc90045969f0cde_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:7a1a867965465605ce847b8da5f05dfe7678d0b6d4f34dc6732f741b9dc60c51_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:279a0bf471a42a0d0ac6fe6830ae1552441af0b792cc23fb9dc554d627d01ffc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:745492e13ca66b0616316d5204ac1f192e8f35d9df48015d20c74b4936b35278_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:b4ead256be98bb90fedfa03edfa2022f97620c205a26f6ec011eb1fd7475677b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:d5518e19af5e5022cb326e7f99264c2d17078b583e923eb3016263fe9d3eda57_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:51443295ffdf2c89ac7ea801982918f92a838cf5d6c68b3d3b08050c49ff1b3e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:9189d6d7e27b49c53e8998bad3ae1d784438d418afed31c7ff5cf9cea2e0e5a4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:e8069763f3ff74d01df98a34ba2f841a4a46d428bfa9654cea02ab58715e0f5f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:f4cbb25cac2f4c697bd11dcbb1d90f65f704172f8aedd493dbccaa42c771a2c3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:174c66907fec51a4538fda3e69e5035f98f0f3cf6665d4afd6e11ec20fe2c119_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:98dd82850ab904d70e5664f289500a74c9771549af9256795c8a9df6280363cf_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:e63de039ed8c50e798a34206a571b07a77b73bacdc120a6440808e63dfc829f4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:fbb4db3b0865092d036d85b86c92dbb452a549bb5ceed6f2f299b8d3dbaf378b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:215e8ad2e509617d748466654632d22a1b194f1b655d1cdce86f03b4629f3d83_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:a3160e1125608b4dcaa536e04097ee6a4ab0942711598e0d9958cd1601422cc5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:c6dfefef016fbc204d8f3174f86734686398a37ff04787de2dbe00b8a22e1802_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:f59d17a8e87273f1eea52717f8fe138c79be43f073d8c3c1f0e67960cc0f8647_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:1a96924a2d8c736608a0c7a1a2ff5e2b68ed07977c4f7859a601bfadad9202a9_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:255a5b6fd39fc3fb50d3310490223fd38f299ba2f29f0d72cca09f1fc5ff90f5_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:32e15964114ea68f9396b92997faca67c53352323e0fc9ebe9934285ab069ff1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:513e03cc2c715a50329c7b3a999082360b29b154bf5f6051cd653fa0322f5fff_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:19344ca9c8d88ef883bcf8127f411f0a4c48c031855fdc7bd5056d64cd77acbc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:2a09e71c4d52a4605a173ea81c3894ae54371c32a9b38f280f07e10d2ffde259_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:4f26535d4b3a8ec733c3f0161ee904f48966601d13ae150302d63a387f483501_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ef0202eae932b7389275befe83e235e97487f8ae0429a341a902aa40d19104c1_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:3b727306a3bc420b94a5c2b72434a3f073c18ba078e4fd4a687f7feda8b8b96e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:67539
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2026-33377
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-55969
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- externalhttps://access.redhat.com/security/cve/CVE-2026-89060
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67539.json