Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.8 security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2025-52881 — runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products121
- multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:057fd34d241f2cd9344227dc85cfc85776c63db54c315b4f1aca56f3ceda4645_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:6628101e37ac81a9af9441b896e53bf931c84082c8f783a8542130e7c2ad437d_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:bf66ea4c38039411444125a6b55315b13b41ed47c9d525302975bd3d8f855647_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:c646f2a99ed436a478a28a12e5e29e8efc105ff4e04da65a43eac261f4fa30e1_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:6f65ad79a0f5d2de5008e50507318be5334e5cc52a7b3f1764762c21947eeafb_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a628c921b704cda8f3c2784abfb38d784b024bb985b70b5a082a2d6a08c0e0b4_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:b74b42109558ba235b6482a6c829d8c283fe25f9dde2b7b57a695fc1077bf3c2_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:f92cf1f99652bacfee9358bf38db1b7bb33b1453eae98751a2f0efbd05cdf60b_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:1d08f94f0efb5b19c8dcd2227fceef012ef318039bdb7a323ebc32fddd536000_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:5f161f35286baa8af600a24840774addff0544b72a3af7a6f67475653cac27bd_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:c871b387e3feb7a235c42a03856f2e0dedc7c6fba905c34f4574ffafea4f310d_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:ee2259875a44383bb4ec730d743787286e9343b2ad29edb6b23854bf26fbaa84_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:040c9dcd35c9f92f2a07b8812819ad40e3e7e93c07668ade9f73dd006fec2006_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:c8284da185fae0dd7b69944d72a076f41b945dd3d250d220a60b4412e1c29ecb_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:edacc49c36bd33709d3538bf724768a9963da540e556accf9806c629be56e779_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:ee33c966652ffff57da40ecfb567367285f0cd26ba7f40c2cfa2b0c633f76704_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:1713f6e512989217a3ff46178816b7cc8660b88fd651630ce9dd60c5e754cd1d_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:3ac529257f1b8e01c13e802b3c90f52b0c783b59431e7c7a87d53d1acfb51605_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:496bb23156f44e7b961552daca393f4c8107368d6ee4a9042182017731689568_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:a75ed15cc22db70549f6e9d67fd208e0e3fa2b66f51b7c978f04dc425bbce2ad_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:0b097c5962c8368279a30203a91dfd581024c16987c4c77b0c14cbedbd347801_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:5d65473211f82fa88f1228c57ddee5e5efed9ab6b11a7f444d85c8aee0a0cc06_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:72f4b1c0ccf15807fb3931ce56efea002f9612887ddab844a0d58e9de3b822ad_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:b8286f1b14391e2dacd0ed3db50e480a643440a871ad454d1eea13637584e16d_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:0b346b41e6eb7fda286ff5b994d9629577d9a54b2399952613e806d2e4178528_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:79c771c2ed8aaab144cde8c8424ae4a84d374cc59c94feed4bd0b3a66356cc54_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:86518cf2f5efc7eda54a2d062d51eabbc647caf7674d7ed678f949bf2e44dc26_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:e4e1c2f7626ddf2cfe32667fdbf396c380e67d3ceb40c6bdc03fc50eda715fa6_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:1a2d44523594387bd57d89fdd6a33ee901e2134fa036cbb2cda46d92cb2c0a74_arm64 as a component of multicluster engine for Kubernetes 2.9
- +91 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Potential mitigations for this issue include: * Using rootless containers, as doing so will block most of the inadvertent writes (runc would run with reduced privileges, making attempts to write to procfs files ineffective). * Based on our analysis, neither AppArmor or SELinux can protect against the full version of the redirected write attack. The container runtime is generally privileged enough to write to arbitrary procfs files, which is more than sufficient to cause a container breakout. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:72851
- externalhttps://access.redhat.com/security/cve/CVE-2025-52881
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72851.json