RHSA-2026:71117HighCVSS 7.5
Red Hat Security Advisory: VolSync v0.16 security fixes and container updates
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-46603 — golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products6
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:fe4c6c976e41314d09f7c0737afbcd87f1fa681bf2ca9a21b5528f7ceeabfab9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/volsync-rhel9@sha256:1e3e0e3f7293f8e22af69b3b3422bb8778a330dda959ac974ea3fbf61e26985a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/volsync-rhel9@sha256:2aaf342144eef8f2776d14a5747313a2fab7c9c2bb4826b89e23c399a3273b96_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/volsync-rhel9@sha256:9ba65dea8faa1ef11a7f7308adf0732012d54cb734d373efe704e176a0218f94_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/volsync-rhel9@sha256:a0ccdb6af3920ac42c6cdf7092df6fc323886e926e3f47a0c7f6b62ee25c0c8e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/business_continuity/business-cont-overview#volsync Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:71117
- externalhttps://access.redhat.com/security/cve/CVE-2026-46603
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71117.json