RHSA-2026:72399HighCVSS 8.6

Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.20.1

Published
September 28, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (53)

📋 Description

CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling CVE-2026-1965 — curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication CVE-2026-3783 — curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect CVE-2026-5435 — glibc: glibc: Out-of-bounds write via TSIG record processing CVE-2026-5928 — glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings CVE-2026-6238 — glibc: glibc: Application crash or uninitialized memory read via crafted DNS response CVE-2026-6653 — libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error CVE-2026-8927 — curl: Information disclosure due to uncleared proxy authentication state CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 CVE-2026-11979 — libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow CVE-2026-13757 — p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing CVE-2026-14164 — libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server CVE-2026-14457 — openssl: RPK server signature algorithm selection can dereference a missing certificate CVE-2026-15588 — GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-41989 — Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-48864 — libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions CVE-2026-54370 — acl: TOCTOU Symlink Traversal via getfacl/setfacl CVE-2026-54371 — attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr CVE-2026-54874 — openssl: excessive memory use buffering DTLS records for a future epoch CVE-2026-56392 — coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-58010 — glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() CVE-2026-58011 — glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime CVE-2026-58012 — glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() CVE-2026-58013 — glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" CVE-2026-58014 — glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" CVE-2026-58015 — glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive CVE-2026-58016 — glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" CVE-2026-58055 — nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63073 — openssl: untrusted sender DN used as format string in CMP response validation CVE-2026-63074 — openssl: CMP indefinite cache growth of ExtraCerts CVE-2026-63075 — openssl: QUIC ACK-only packet retention can cause memory exhaustion CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg CVE-2026-63379 — libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning CVE-2026-63381 — libevent: Libevent: Memory corruption due to use-after-free CVE-2026-63382 — libevent: libevent: Multiple HTTP Parser Bugs Enable Request Smuggling CVE-2026-63383 — libevent: Libevent: Denial of Service via malformed RPC data CVE-2026-63384 — libevent: Libevent: Denial of Service via integer conversion error in evtag_unmarshal_header CVE-2026-63385 — libevent: Libevent: HTTP header handling bugs create risk of access control bypass. CVE-2026-63387 — libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption CVE-2026-63388 — libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests

🎯 Affected products5

  • Cert Manager support for Red Hat OpenShift release 1.20
  • registry.redhat.io/cert-manager/cert-manager-operator-rhel9@sha256:0bfd185a474fc2a5adf322c153f804799f38e0cb190528ff0b9be9c101c3eaca_s390x as a component of Cert Manager support for Red Hat OpenShift release 1.20
  • registry.redhat.io/cert-manager/cert-manager-operator-rhel9@sha256:4448c2c0b13f63a95312a0c023208133f4987e3815aaf8f02361d3f1b099553f_amd64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
  • registry.redhat.io/cert-manager/cert-manager-operator-rhel9@sha256:45529b1a8cd9562986a7a6d4dc459a2638ad417e9bf172d7ef9c62ad21443aa2_ppc64le as a component of Cert Manager support for Red Hat OpenShift release 1.20
  • registry.redhat.io/cert-manager/cert-manager-operator-rhel9@sha256:da5ea3c112696151994abab6160aaa0c51a9644f1a24d190ef54c7fcb3fd7755_arm64 as a component of Cert Manager support for Red Hat OpenShift release 1.20

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To prevent the leakage of OAuth2 bearer tokens, ensure that `.netrc` files are carefully managed. Avoid configuring `.netrc` entries for untrusted or unknown hostnames, particularly when `curl` is used with OAuth2 bearer tokens and is configured to follow redirects. Regularly review and restrict the scope of credentials stored in `.netrc` files to only explicitly trusted destinations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Updating to a fixed version of libxml2 (2.11.0 or later upstream, or a future RHEL errata) will fully resolve this issue. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications utilizing libcurl should avoid reusing handles when switching between different proxy configurations. This operational control prevents the unintended leakage of `Proxy-Authorization` headers to incorrect proxies. Workaround: This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user/<uid>/p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure `Restart=on-failure` is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw. Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available. Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory. Workaround: To mitigate this vulnerability, in applications processing user-supplied dates, implement input validation to ensure the supplied date is within the supported range before calling g_date_time_add_full() with untrusted data, specifically rejecting inputs that result in a negative or zero days field. Workaround: To mitigate this vulnerability, implement strict input validation to sanitize user-supplied replacement strings, specifically rejecting or escaping case-change modifiers (\u, \l, \U, \L) before calling g_regex_replace() or g_regex_replace_eval() when the G_REGEX_RAW compile flag is used. Removing the G_REGEX_RAW flag or hardcoding the replacement strings will completely neutralize this issue. Workaround: To mitigate this vulnerability, restrict any custom line terminator string passed to g_io_channel_set_line_term() to a maximum length of one byte before calling g_io_channel_read_line_backend(). Using the default line terminators will completely neutralize this issue. Workaround: To mitigate this vulnerability, implement input validation to sanitize untrusted key files (such as .desktop or .ini files), specifically rejecting or stripping empty values before calling g_key_file_get_locale_string_list(). Alternatively, restricting the application to only load key files from trusted sources will completely neutralize this issue. Workaround: To mitigate this vulnerability, ensure that applications only connect to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle (MitM) attacks. If feasible, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 will completely neutralize this issue. Workaround: To mitigate this vulnerability, implement input validation to sanitize untrusted D-Bus introspection XML, specifically rejecting malformed structures such as <node> elements improperly nested within <method>, <signal>, <property> or <arg> elements before calling g_dbus_node_info_new_for_xml(). Alternatively, restricting the application to only process XML input from trusted, authenticated sources will completely neutralize this issue. Workaround: Configure your WAF or load balancer to drop incoming HTTP/1.1 requests that contain both Upgrade and Content-Length headers. This blocks the malformed traffic at the edge before it can reach the vulnerable proxy without impacting legitimate users.

🔗 References (57)