Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.20.1
🔗 CVE IDs covered (75)
📋 Description
CVE-2024-34459 — libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c
CVE-2025-5278 — coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification
CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2025-13151 — libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
CVE-2025-14087 — glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
CVE-2025-14512 — glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
CVE-2026-1965 — curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication
CVE-2026-2100 — p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
CVE-2026-3783 — curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect
CVE-2026-3832 — gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response
CVE-2026-3833 — gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-4046 — glibc: glibc: Denial of Service via iconv() function with specific character sets
CVE-2026-4424 — libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
CVE-2026-4437 — glibc: glibc: Incorrect DNS response parsing via crafted DNS server response
CVE-2026-4438 — glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
CVE-2026-5121 — libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
CVE-2026-5260 — gnutls: gnutls: Information disclosure via heap overread in RSA key exchange
CVE-2026-5419 — gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal
CVE-2026-5435 — glibc: glibc: Out-of-bounds write via TSIG record processing
CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width
CVE-2026-5928 — glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
CVE-2026-6238 — glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
CVE-2026-6653 — libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
CVE-2026-7383 — openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing
CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch
CVE-2026-9076 — openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption
CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass
CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5
CVE-2026-11979 — libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow
CVE-2026-13757 — p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
CVE-2026-14164 — libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack()
CVE-2026-15588 — GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering
CVE-2026-16118 — xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
CVE-2026-28390 — openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
CVE-2026-29111 — systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
CVE-2026-33845 — gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
CVE-2026-33846 — gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly
CVE-2026-34180 — openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.
CVE-2026-34181 — openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-40355 — krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism
CVE-2026-40356 — krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
CVE-2026-41989 — Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
CVE-2026-42009 — gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-42010 — gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-42011 — gnutls: gnutls: Security bypass due to incorrect name constraint handling
CVE-2026-42012 — gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs
CVE-2026-42013 — gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name
CVE-2026-42014 — gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin
CVE-2026-42015 — gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
CVE-2026-42764 — openssl: NULL pointer dereference in QUIC server initial packet handling
CVE-2026-42766 — openssl: Possible NULL Dereference in Password-Based CMS Decryption
CVE-2026-42767 — openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption
CVE-2026-42768 — openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-42769 — openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-42770 — openssl: FFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-45446 — openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
CVE-2026-48864 — libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-54369 — acl: Symlink traversal privilege escalation via libacl functions
CVE-2026-54370 — acl: TOCTOU Symlink Traversal via getfacl/setfacl
CVE-2026-54371 — attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr
CVE-2026-58010 — glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58011 — glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
CVE-2026-58012 — glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
CVE-2026-58013 — glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58014 — glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58015 — glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
CVE-2026-58016 — glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58055 — nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests
🎯 Affected products5
- Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/cert-manager-trust-manager-rhel9@sha256:41b67648465fa70bec1fb0a771a15c04c1daf0b1d053b0872ca8016f2b2f7f80_amd64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/cert-manager-trust-manager-rhel9@sha256:54c108742618f55c9c52ee7db0bce351e5cb84693adfdb9c12b588636418b387_ppc64le as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/cert-manager-trust-manager-rhel9@sha256:f8086b33e4cdeb0df936f6972ed7046f9b3a10b8f175d3f02a98d2ef228c904c_s390x as a component of Cert Manager support for Red Hat OpenShift release 1.20
- registry.redhat.io/cert-manager/cert-manager-trust-manager-rhel9@sha256:fe8ab3b44c313f20004b145ea7d5584996eb852338bac14a3e5b9cc64480851e_arm64 as a component of Cert Manager support for Red Hat OpenShift release 1.20
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information. Workaround: Do not process untrusted files with the xmllint program. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To prevent the leakage of OAuth2 bearer tokens, ensure that `.netrc` files are carefully managed. Avoid configuring `.netrc` entries for untrusted or unknown hostnames, particularly when `curl` is used with OAuth2 bearer tokens and is configured to follow redirects. Regularly review and restrict the scope of credentials stored in `.netrc` files to only explicitly trusted destinations. Workaround: To mitigate this issue, avoid processing untrusted ISO9660 images with applications that utilize `libarchive`. Users should only extract or read content from ISO images obtained from trusted sources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Updating to a fixed version of libxml2 (2.11.0 or later upstream, or a future RHEL errata) will fully resolve this issue. Workaround: This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user/<uid>/p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure `Restart=on-failure` is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw. Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available. Workaround: Do not install a MIME magic file or content from untrusted sources. Workaround: Applications that process Cryptographic Message Syntax (CMS) EnvelopedData messages should be configured to only accept input from trusted sources. Restricting network access to services that process untrusted CMS data can also reduce exposure to this Denial of Service vulnerability. Workaround: To mitigate this issue, enforce strict validation on all uploaded PKCS#12 files to reject those containing abnormally short security keys. Additionally, enabling FIPS mode on your system can help protect your environment, as the vulnerable OpenSSL code operates entirely outside the approved FIPS cryptographic boundary. Workaround: Systems configured to operate in FIPS mode are not affected by this vulnerability. To mitigate this issue, ensure that OpenSSL is operating in FIPS mode by enabling the system-wide FIPS policy. This may have broader implications for cryptographic operations on the system and should be evaluated for compatibility with existing applications. A system reboot may be required for the changes to take effect. Workaround: To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack. Workaround: To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in `/etc/gss/mech`. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality. Workaround: To mitigate this issue, ensure that the NegoEx mechanism is not registered in the `/etc/gss/mech` configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect. Workaround: To mitigate this issue, ensure that the OpenSSL QUIC server has client address validation enabled. This is the default configuration. If the `SSL_LISTENER_FLAG_NO_VALIDATE` flag is being used with the `SSL_new_listener()` call, it should be removed to prevent the vulnerability from being exploitable. Workaround: To mitigate this issue, ensure that OpenSSL CMP client applications only communicate with trusted Certificate Management Protocol (CMP) servers. If CMP client functionality is not required, consider disabling or restricting its use to reduce exposure. Workaround: To mitigate this vulnerability, applications utilizing CMS_decrypt() or PKCS7_decrypt() should ensure a recipient certificate is always provided to identify the specific RecipientInfo for decryption. This practice helps prevent the Bleichenbacher-style oracle attack by ensuring proper key identification. Workaround: The vulnerability arises from specific application implementations using OpenSSL's AES-SIV or AES-GCM-SIV modes with custom protocols and an atypical handling of empty ciphertexts. As this scenario is not a default or commonly deployed configuration in Red Hat products, and no direct configuration or operational control exists to mitigate this specific flaw without patching, the following applies: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory. Workaround: To mitigate this vulnerability, in applications processing user-supplied dates, implement input validation t…
🔗 References (79)
- selfhttps://access.redhat.com/errata/RHSA-2026:72502
- externalhttps://access.redhat.com/security/cve/CVE-2024-34459
- externalhttps://access.redhat.com/security/cve/CVE-2025-13151
- externalhttps://access.redhat.com/security/cve/CVE-2025-14087
- externalhttps://access.redhat.com/security/cve/CVE-2025-14512
- externalhttps://access.redhat.com/security/cve/CVE-2025-5278
- externalhttps://access.redhat.com/security/cve/CVE-2025-6170
- externalhttps://access.redhat.com/security/cve/CVE-2026-11822
- externalhttps://access.redhat.com/security/cve/CVE-2026-11824
- externalhttps://access.redhat.com/security/cve/CVE-2026-11979
- externalhttps://access.redhat.com/security/cve/CVE-2026-13757
- externalhttps://access.redhat.com/security/cve/CVE-2026-14164
- externalhttps://access.redhat.com/security/cve/CVE-2026-15588
- externalhttps://access.redhat.com/security/cve/CVE-2026-16118
- externalhttps://access.redhat.com/security/cve/CVE-2026-1965
- externalhttps://access.redhat.com/security/cve/CVE-2026-2100
- externalhttps://access.redhat.com/security/cve/CVE-2026-28390
- externalhttps://access.redhat.com/security/cve/CVE-2026-29111
- externalhttps://access.redhat.com/security/cve/CVE-2026-31790
- externalhttps://access.redhat.com/security/cve/CVE-2026-33845
- externalhttps://access.redhat.com/security/cve/CVE-2026-33846
- externalhttps://access.redhat.com/security/cve/CVE-2026-34180
- externalhttps://access.redhat.com/security/cve/CVE-2026-34181
- externalhttps://access.redhat.com/security/cve/CVE-2026-34182
- externalhttps://access.redhat.com/security/cve/CVE-2026-34183
- externalhttps://access.redhat.com/security/cve/CVE-2026-3783
- externalhttps://access.redhat.com/security/cve/CVE-2026-3832
- externalhttps://access.redhat.com/security/cve/CVE-2026-3833
- externalhttps://access.redhat.com/security/cve/CVE-2026-40355
- externalhttps://access.redhat.com/security/cve/CVE-2026-40356
- externalhttps://access.redhat.com/security/cve/CVE-2026-4046
- externalhttps://access.redhat.com/security/cve/CVE-2026-41989
- externalhttps://access.redhat.com/security/cve/CVE-2026-42009
- externalhttps://access.redhat.com/security/cve/CVE-2026-42010
- externalhttps://access.redhat.com/security/cve/CVE-2026-42011
- externalhttps://access.redhat.com/security/cve/CVE-2026-42012
- externalhttps://access.redhat.com/security/cve/CVE-2026-42013
- externalhttps://access.redhat.com/security/cve/CVE-2026-42014
- externalhttps://access.redhat.com/security/cve/CVE-2026-42015
- externalhttps://access.redhat.com/security/cve/CVE-2026-42764
- externalhttps://access.redhat.com/security/cve/CVE-2026-42766
- externalhttps://access.redhat.com/security/cve/CVE-2026-42767
- externalhttps://access.redhat.com/security/cve/CVE-2026-42768
- externalhttps://access.redhat.com/security/cve/CVE-2026-42769
- externalhttps://access.redhat.com/security/cve/CVE-2026-42770
- externalhttps://access.redhat.com/security/cve/CVE-2026-4424
- externalhttps://access.redhat.com/security/cve/CVE-2026-4437
- externalhttps://access.redhat.com/security/cve/CVE-2026-4438
- externalhttps://access.redhat.com/security/cve/CVE-2026-45445
- externalhttps://access.redhat.com/security/cve/CVE-2026-45446
- externalhttps://access.redhat.com/security/cve/CVE-2026-45447
- externalhttps://access.redhat.com/security/cve/CVE-2026-4878
- externalhttps://access.redhat.com/security/cve/CVE-2026-48864
- externalhttps://access.redhat.com/security/cve/CVE-2026-5121
- externalhttps://access.redhat.com/security/cve/CVE-2026-5260
- externalhttps://access.redhat.com/security/cve/CVE-2026-5419
- externalhttps://access.redhat.com/security/cve/CVE-2026-5435
- externalhttps://access.redhat.com/security/cve/CVE-2026-54369
- externalhttps://access.redhat.com/security/cve/CVE-2026-54370
- externalhttps://access.redhat.com/security/cve/CVE-2026-54371
- externalhttps://access.redhat.com/security/cve/CVE-2026-5450
- externalhttps://access.redhat.com/security/cve/CVE-2026-58010
- externalhttps://access.redhat.com/security/cve/CVE-2026-58011
- externalhttps://access.redhat.com/security/cve/CVE-2026-58012
- externalhttps://access.redhat.com/security/cve/CVE-2026-58013
- externalhttps://access.redhat.com/security/cve/CVE-2026-58014
- externalhttps://access.redhat.com/security/cve/CVE-2026-58015
- externalhttps://access.redhat.com/security/cve/CVE-2026-58016
- externalhttps://access.redhat.com/security/cve/CVE-2026-58055
- externalhttps://access.redhat.com/security/cve/CVE-2026-5928
- externalhttps://access.redhat.com/security/cve/CVE-2026-6238
- externalhttps://access.redhat.com/security/cve/CVE-2026-6653
- externalhttps://access.redhat.com/security/cve/CVE-2026-7383
- externalhttps://access.redhat.com/security/cve/CVE-2026-8286
- externalhttps://access.redhat.com/security/cve/CVE-2026-9076
- externalhttps://access.redhat.com/security/cve/CVE-2026-9547
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72502.json