RHSA-2026:71116HighCVSS 7.5

Red Hat Security Advisory: VolSync v0.15 security fixes and container updates

Published
September 23, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-46603 — golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests

🎯 Affected products6

  • Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7284b648c9477346ebc5c3eb1a2693c5207bd82be8800e825f8757e49bcf064d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:28f50adaa537066260645d3ebf9fdec957046881d946d5d684940cb85b06a2e8_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:87b9cd7728b598b1377c44fd0ab9300573df87031f5043aaa95118219ce15faf_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:b34206ec874e82b2d99f5d0d7ccf21bff049dd2959c93b9fb89c9b2aedce2001_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/volsync-rhel9@sha256:e488e422ac00ac84b0bc11c06d8c54e4de6be516c832f83636d980692f5c4fdb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/business_continuity/business-cont-overview#volsync Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (5)