Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.5.3
🔗 CVE IDs covered (24)
📋 Description
CVE-2026-18140 — aws-smithy-json: aws-smithy-json: Denial of Service via uncontrolled recursion with deeply nested JSON CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-29181 — github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products35
- Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:a5e092c0dbc40b85fd7a93328c798e4721e7c059fb30b470501371149294f9b8_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:822e29c6b0b68079a347949167ea267b0a8627d46c901bc3c4db535abe510e72_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:99d11f42d86d470e4c7d7e058414391e97dbd486b65f3be5632bb1b88792c71b_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:be174af030d4d5d34cf01da528d548caea0ff0ea4e14d1d92ad93b6714c3b96d_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:f3eabde3d2da8cbc70ef0400d57d960d5dede80aab1d33ccf011eb5af08b9755_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:4e36e066b35f44a54674984e22b185349bf3785e6f9bc86b569ebaa59dcbd2a2_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:52ed6ebbde66a133f3e493de4e70f8dfd34a530821180433ccb53e3357bac655_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:e317827dc1605cd47d546d144202dcd438d6d896dc555968aa898039a79ca7cd_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:e72f4d0887e40b93bc90f7b4dfd11268ec89545c3ca88fb9f17e2b791d8e5655_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:0b689d6bfec28d22e9bf20bead50162d42f86869535eda8f706ab7995b56506f_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:cfdd5a3a9f0155fc6e95e286aab35c3f5426831cc1e721c1db3dd52ba2a98472_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:ea92dda5184757afd722a8bbec34228dd691657802c883c741c83b12a9669fda_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:eb39de1415d25f2d15c14d0535968ffbd2de47dcc76cbf59a223662933c72374_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:1aff1edffe97335213aeb0f87488fe4b8f705963c606dab61706cda628ba7d7e_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:2a2a0ebc791a8c6df0587901845d99af607fff15a16f34d44d60246a1edc46ab_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:3f527e14b66008eadeb6af9f8a879e7b9e27dc57a5df00dd14d4f010f411cfc2_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:7edd996585ced7980c0361d170e4609847beee3576876d587a27af3477ebe25d_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:0351f0ff2bb2b848082254b9dfab95104c36cbfa918ef5b8326da68c15a53d21_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:00feaaf029da12a09e28f196953423442e608cdcb5c75a507fe8c97dc662e183_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:716dc01dab13e4bedf7dd639d985d8514b1db4bc79467566da026b4279136c4a_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:854701ce7fb777b8e7d0dead014dc85e8c162c4f0e573264b6dad3ebec46d763_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:c2028d322147474bf38f74d341c0c5469e10b54c0dda1ea894b88bf59d9b478f_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:00105990cbeb225eaf1da878fc8dcb47325703191d1389096637ce9e32da13c1_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:2db7aa5ecc046e77ea58de7968645f27727ebd04efe106064991b3ec78592b2d_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:742550c2488970f3c86c0774d040d96c83e64bc3b78ba9be22355b3be7d5f692_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:a2637f8ba12b50ec71c24bb32a18dbaf9d2fb4c34c60ee131707a5fb2b204050_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:302a19cec76473554ec2157fc8cc6995eb53553954edab2c9d5dde7da36afb14_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:4c370fd40f050135ce34fd3b4975986c6010868027377a41c62760efddba0c40_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:545ba3142e245dcc9686d07ad3d5764922f408656ddb7ab7972decd85b3a9dc3_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- +5 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes For Red Hat OpenShift Logging 6.5, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.5 Workaround: Restrict network access to services that process JSON input using the `aws-smithy-json` runtime. Configure firewalls to limit incoming connections to trusted sources, thereby reducing the exposure to remote unauthenticated denial of service attacks. If the service is reloaded or restarted, ensure firewall rules persist. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service.
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHSA-2026:70870
- externalhttps://access.redhat.com/security/cve/CVE-2026-18140
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-29181
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70870.json