Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.20.1
🔗 CVE IDs covered (53)
📋 Description
CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2026-1965 — curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication
CVE-2026-3783 — curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect
CVE-2026-5435 — glibc: glibc: Out-of-bounds write via TSIG record processing
CVE-2026-5928 — glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
CVE-2026-6238 — glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
CVE-2026-6653 — libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch
CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error
CVE-2026-8927 — curl: Information disclosure due to uncleared proxy authentication state
CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass
CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5
CVE-2026-11979 — libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow
CVE-2026-13757 — p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
CVE-2026-14164 — libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack()
CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
CVE-2026-14457 — openssl: RPK server signature algorithm selection can dereference a missing certificate
CVE-2026-15588 — GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering
CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet
CVE-2026-41989 — Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-48864 — libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions
CVE-2026-54370 — acl: TOCTOU Symlink Traversal via getfacl/setfacl
CVE-2026-54371 — attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr
CVE-2026-54874 — openssl: excessive memory use buffering DTLS records for a future epoch
CVE-2026-56392 — coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-58010 — glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58011 — glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
CVE-2026-58012 — glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
CVE-2026-58013 — glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58014 — glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58015 — glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
CVE-2026-58016 — glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58055 — nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests
CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping
CVE-2026-63073 — openssl: untrusted sender DN used as format string in CMP response validation
CVE-2026-63074 — openssl: CMP indefinite cache growth of ExtraCerts
CVE-2026-63075 — openssl: QUIC ACK-only packet retention can cause memory exhaustion
CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg
CVE-2026-63379 — libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning
CVE-2026-63381 — libevent: Libevent: Memory corruption due to use-after-free
CVE-2026-63382 — libevent: libevent: Multiple HTTP Parser Bugs Enable Request Smuggling
CVE-2026-63383 — libevent: Libevent: Denial of Service via malformed RPC data
CVE-2026-63384 — libevent: Libevent: Denial of Service via integer conversion error in evtag_unmarshal_header
CVE-2026-63385 — libevent: Libevent: HTTP header handling bugs create risk of access control bypass.
CVE-2026-63387 — libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption
CVE-2026-63388 — libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products9
- Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:a5f4c1a5cffdd4a0449fdf9b05815810e92d27601e9d683ed647ee1c2e5df4cf_ppc64le as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:a9ea762f1429d17b65ed677f7dc1162c3de7f6b792297872079263efc23c34df_arm64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:c34db4a5a22ec01496292c66eee29ff041722ea90da13a886acbcba5f96dfb8f_amd64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:d86af8bb35aca6af6b12478d265eb7ed049c6f8ec9d67c04bd5013fdcdc8b170_s390x as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:4c096dd98f4e139c2c5f08f26559e4f243edd2d745da197e232f02074092a300_amd64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:6064f0ab2db9a4f10c7453060d8281b98ce8daefed74a79079731c861715dae2_arm64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:61ff21a427d5b8a009d24eb9b6764369db24720a7cbb8b9022fb2b568ca3a80f_s390x as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:cd676b157e11d5f02be67339da1c40af6ee063da2f5dbdd3544619b2956a9a15_ppc64le as a component of Cert Manager support for Red Hat OpenShift release 1.20
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To prevent the leakage of OAuth2 bearer tokens, ensure that `.netrc` files are carefully managed. Avoid configuring `.netrc` entries for untrusted or unknown hostnames, particularly when `curl` is used with OAuth2 bearer tokens and is configured to follow redirects. Regularly review and restrict the scope of credentials stored in `.netrc` files to only explicitly trusted destinations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Updating to a fixed version of libxml2 (2.11.0 or later upstream, or a future RHEL errata) will fully resolve this issue. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications utilizing libcurl should avoid reusing handles when switching between different proxy configurations. This operational control prevents the unintended leakage of `Proxy-Authorization` headers to incorrect proxies. Workaround: This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user/<uid>/p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure `Restart=on-failure` is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw. Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available. Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory. Workaround: To mitigate this vulnerability, in applications processing user-supplied dates, implement input validation to ensure the supplied date is within the supported range before calling g_date_time_add_full() with untrusted data, specifically rejecting inputs that result in a negative or zero days field. Workaround: To mitigate this vulnerability, implement strict input validation to sanitize user-supplied replacement strings, specifically rejecting or escaping case-change modifiers (\u, \l, \U, \L) before calling g_regex_replace() or g_regex_replace_eval() when the G_REGEX_RAW compile flag is used. Removing the G_REGEX_RAW flag or hardcoding the replacement strings will completely neutralize this issue. Workaround: To mitigate this vulnerability, restrict any custom line terminator string passed to g_io_channel_set_line_term() to a maximum length of one byte before calling g_io_channel_read_line_backend(). Using the default line terminators will completely neutralize this issue. Workaround: To mitigate this vulnerability, implement input validation to sanitize untrusted key files (such as .desktop or .ini files), specifically rejecting or stripping empty values before calling g_key_file_get_locale_string_list(). Alternatively, restricting the application to only load key files from trusted sources will completely neutralize this issue. Workaround: To mitigate this vulnerability, ensure that applications only connect to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle (MitM) attacks. If feasible, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 will completely neutralize this issue. Workaround: To mitigate this vulnerability, implement input validation to sanitize untrusted D-Bus introspection XML, specifically rejecting malformed structures such as <node> elements improperly nested within <method>, <signal>, <property> or <arg> elements before calling g_dbus_node_info_new_for_xml(). Alternatively, restricting the application to only process XML input from trusted, authenticated sources will completely neutralize this issue. Workaround: Configure your WAF or load balancer to drop incoming HTTP/1.1 requests that contain both Upgrade and Content-Length headers. This blocks the malformed traffic at the edge before it can reach the vulnerable proxy without impacting legitimate users.
🔗 References (57)
- selfhttps://access.redhat.com/errata/RHSA-2026:72394
- externalhttps://access.redhat.com/security/cve/CVE-2025-6170
- externalhttps://access.redhat.com/security/cve/CVE-2026-11822
- externalhttps://access.redhat.com/security/cve/CVE-2026-11824
- externalhttps://access.redhat.com/security/cve/CVE-2026-11979
- externalhttps://access.redhat.com/security/cve/CVE-2026-13757
- externalhttps://access.redhat.com/security/cve/CVE-2026-14164
- externalhttps://access.redhat.com/security/cve/CVE-2026-14456
- externalhttps://access.redhat.com/security/cve/CVE-2026-14457
- externalhttps://access.redhat.com/security/cve/CVE-2026-15588
- externalhttps://access.redhat.com/security/cve/CVE-2026-16118
- externalhttps://access.redhat.com/security/cve/CVE-2026-18798
- externalhttps://access.redhat.com/security/cve/CVE-2026-1965
- externalhttps://access.redhat.com/security/cve/CVE-2026-3783
- externalhttps://access.redhat.com/security/cve/CVE-2026-41989
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-48864
- externalhttps://access.redhat.com/security/cve/CVE-2026-5435
- externalhttps://access.redhat.com/security/cve/CVE-2026-54369
- externalhttps://access.redhat.com/security/cve/CVE-2026-54370
- externalhttps://access.redhat.com/security/cve/CVE-2026-54371
- externalhttps://access.redhat.com/security/cve/CVE-2026-54874
- externalhttps://access.redhat.com/security/cve/CVE-2026-56392
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56854
- externalhttps://access.redhat.com/security/cve/CVE-2026-58010
- externalhttps://access.redhat.com/security/cve/CVE-2026-58011
- externalhttps://access.redhat.com/security/cve/CVE-2026-58012
- externalhttps://access.redhat.com/security/cve/CVE-2026-58013
- externalhttps://access.redhat.com/security/cve/CVE-2026-58014
- externalhttps://access.redhat.com/security/cve/CVE-2026-58015
- externalhttps://access.redhat.com/security/cve/CVE-2026-58016
- externalhttps://access.redhat.com/security/cve/CVE-2026-58055
- externalhttps://access.redhat.com/security/cve/CVE-2026-5928
- externalhttps://access.redhat.com/security/cve/CVE-2026-6238
- externalhttps://access.redhat.com/security/cve/CVE-2026-63072
- externalhttps://access.redhat.com/security/cve/CVE-2026-63073
- externalhttps://access.redhat.com/security/cve/CVE-2026-63074
- externalhttps://access.redhat.com/security/cve/CVE-2026-63075
- externalhttps://access.redhat.com/security/cve/CVE-2026-63076
- externalhttps://access.redhat.com/security/cve/CVE-2026-63379
- externalhttps://access.redhat.com/security/cve/CVE-2026-63381
- externalhttps://access.redhat.com/security/cve/CVE-2026-63382
- externalhttps://access.redhat.com/security/cve/CVE-2026-63383
- externalhttps://access.redhat.com/security/cve/CVE-2026-63384
- externalhttps://access.redhat.com/security/cve/CVE-2026-63385
- externalhttps://access.redhat.com/security/cve/CVE-2026-63387
- externalhttps://access.redhat.com/security/cve/CVE-2026-63388
- externalhttps://access.redhat.com/security/cve/CVE-2026-6653
- externalhttps://access.redhat.com/security/cve/CVE-2026-8286
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/cve/CVE-2026-8458
- externalhttps://access.redhat.com/security/cve/CVE-2026-8927
- externalhttps://access.redhat.com/security/cve/CVE-2026-9547
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72394.json