Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.17.2 security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-45570 — github.com/go-git/go-git: go-git: Shell command injection in SSH transport CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-89060 — stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references
🎯 Affected products185
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:4dc81f611bb6640ec0ade7ee836201a08b00eb08088ca2bce2fa984fce946c0a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:91c0e1c365a59c3460382308c0b9fa213de8f11ca116899407b67e896a5e3518_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:988cf6240705c753fd569fc33a773b30d960bac40bced249f025642462a2f47a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:c854a3a967c844cba7f5c3669c575a42bbf05b30815e75eee44a367a65cd639d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:195fdd92bcbebce03d606124c76a39ddcd6df6f10b833cbaea3548c9a06bbfe2_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:29861eacf73a6ad3e5f78b93b7417810fcffd854d0e7018ac5ed3c75435c92b0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:dd252f08ef09a27d26dfdd1de692b0a776ed22259bbaef7782679009f994e572_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:ea5ff77931de87de599cc894a31a5a2cb0605fb68cdc559ff6427a649a3363cb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:3737bd00dc2c12fbd80232e8c2d8ee767caab3b5df052a304df0557b1b7d756c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:77f9f558c506324caf90eb031e35ec8a5abbc851b82ef10741b4287a3c7bae86_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:91823d35db14dcc632e2421cbaebdfad3f0c5a61766adb11921d88fb0978d0a5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:c300d829e887522e545623323204a63c6720fcfa37e82164843a7ba3dbfcf9fe_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:13de391240cb4d26db46846eed986d900493a7b7479c784b9dbeac3eab23b169_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:36cbec8e8fb6c32e56de8e272f5f7f61bcc3a6aed983b41052e8d9b27257830c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:afe76460d60ee1bac840e5d102b8f1f92da1d3e86350c95c723085d8833a82fb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:aff8d5ff00a0829b3848f403820066357b3a9ad0fa0c7c502daeb8bda3ddd6de_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:6f39750ab9ad9dea52936d5266e8636da656f67ca3e10c7c272c16604b5f9f43_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b6563591bae5c2b8a8b0f3db6e4f5b6da0f6f34da82450567a61e24bb0acebe5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:d5333fdff82219dc7c2f3cab0e603b65412fc1a8d1039f0a5c1688dc00edb639_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:e84c6591aa09b32217374ebcb983ed2247a6f45d4307381d65f95bf5d76aed72_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:0f42b4d8fd7963be031b97db51eeac4e091f1cb7efa33d8c5e3c5803ea0b02c3_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:20df4ff9a6d236fdd6d783c93d4d4a4409fd20a888a000f1b56071bece89fd74_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:de93be469ed92a5e2e77c287d834c3470b9fa99b445001d425df3a187d763b79_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ff72c2007cd1beaf51c971033dea54550b767b3a3fd4813b434d9138764ce637_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:548a6ef9116c540b3e79e80043e7d36b3bafdb7400306cecd075dd76cba2a08e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:67fffca15f9e9c0063e4e2f622ac159a713c77d9eb110bac3f55f7803ac63ce1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:c1e96a155ce3830f6259d547aaf59cef4817ad64d3d9a23ba4d17b92e18a658a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:fd57d49e6a30de495474163f8cffb82615b1d469866fdc27f3aeca022aa7a9b6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:5f5f79f8c8d28c4b7dbb1a1da41e3c2e57cb09cf231c4e7569fe6c2a71980801_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- +155 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:67543
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-45570
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-89060
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67543.json