Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.11 security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products109
- multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:5f55721704a1d20c614e07a8c414b0f0a2482074ee9e3837e08716e1b861865d_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:bf1d8960a000de065fef5e175ff0c90f0c427c74a80d756e37f2993ab0a8fea7_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ca2c75933839c2134b4dab6f23a298365a07dd6505ad084d085340b93b1b46a3_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:cfc444d9eb1bf8d0187c7f3484e55eccc1b0ed82715cc6e97fb26065487d69b5_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:2147450627a117f21f26e3ca717660c91adb5950360cb1ad2c891cb5a99f1ca8_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:269ca8acdc31e26477f1f2a987804c9086a9c2af84bc253c7ea68c66ee539cc8_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:6932ce6e4bffa365b815c6b300e34830049436f81db36db0ab68853cb958c427_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:9f7de602026a9cae7eb91f9cb1f646b51354540ccdebc0bb509833ae34fb60c9_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:09dcd6574d4a756b2960875a0c41e337c91d903bf7de4d66ef9d85306a58b846_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:2bcd2192549905073660ee81ccf0432d934c578c1132eef1068d89b615dd3196_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:7268b6e49bcecb9a8c0251b3513681ee1af28be5b3cc51575cab26042f51011e_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:a4dc076661efb239bea1fe183f6e1f9eaf3a37fa2aa436394bdc2d8122861567_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:089f9f84cfebb9f4797957e7395894046415d42b3a83cbd3b21fb8710324e2d6_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:61110d98325953756fa239515e8f9679c3a795b3f63079de3b746f1bfeeff981_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:d9eae30ed01d2118e1061c62c446faf1e99df0efa40b6bf7459fd48e72be1d74_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:f243dd20ee86391580fb6da952e47411bb89b13ea77cc4586953815d46956a4a_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:4f61508b8bef54545f5a5f37f0eb3017998cbb58dd86a4943357355f03335fc6_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:67cea638700ed536e58c6329ec09035cd25f2cbdd82edaee1e7d6a544768ffe1_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:9ecc3771e685a567c952fa20a609e109cdb0dc4c29a670e26b1ebef514660434_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:cb44dca7eb4b06c5f1ef1ab33394e0b5e8b103f7371cf68e2fe79aefdf21ea32_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:0470f5c06a12c22d29a7c806fa0d86a09100239ad462e20a9c7058cdee86d6bc_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:0fc3591790456632cf00458526cf43b20a1f3233e6662b0c816b2963bc90abe5_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:1b20a9c427d44b8851eb9e70db36cc54dd511e65fd33aa372a5caa622e9e7613_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:8dd4ec4795d56ea6916a0220562e63e0dbe8c2613a4487051bfd019f49b87092_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:091d76a2b7b7591152f307ab6743327118a53cb69954488fe8cca6147016401d_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:1282fda1dc211b76b35fa7cb460ac52b486a0f27b21d4ecbdfd09135cf97a5f9_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:7039931da4cfe77fa115bf09e78274f9f893149c37062293d75f8c90cd3a2acb_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:8b52e36fecd0f1a117b999d906de9404c0aedd2c19559166bb5c4f1807bf1f0a_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:043d69f9ffd5d0332ae3f8fd221799dcf03eaa1b314da7838e8dd3cb56a063fb_s390x as a component of multicluster engine for Kubernetes 2.8
- +79 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:72854
- externalhttps://access.redhat.com/security/cve/CVE-2025-22866
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72854.json