Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.8 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products185
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:0af4961d4ffd9a29b8334c74db1c2d5725725cec59d40b270a743f2b1c01902b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:58eee948855e93b728c5f689ad05573ecf737bf055c4e744aef4c36a4ff17d2b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:6d413a68b161df10357835c60038391e787265705d0272531bef2a02ad0d99bb_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f62767a0933c00dfe0a915e134338b83d250072df96794337bbad5306da4e336_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:135b27452fcefec146015f1ec45b95f70de0105be3644c7d1cba45f5f0728239_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:487d14e3a9ace1bd9c86e4bc687de0538a6bec5704d8fc99f52dcb496380d385_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:82fcbfc5c6fb6ac31152ef79a2916b60346d1f2e159884f906674cb058df7454_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:cc0455c65413b4ff30aadc404f67a53e30daf08a4eb0b8038fda256813652d5f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:aa1827bc5143dcd102ddbdd32771dc9a4f54d557065ecbed647f13c6739bd147_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:b778cf97914b3f682b164ed8ea1155e918e7248d327c566a2756f2cdcc739a94_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:e6726557385bc53ff2ddacce08912fdcb07396ee1693c9c22bfce95b47610237_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:f61e10ec440a03eae98d14795fead552c68d6b25361e4cdce692455a142a9e3c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:897dfe98139acb39400bc49d79322d5ffb41a071ab64056b636cacd6a1282c77_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:bf37ff8d3c6b2d6c8d68cc1dc7bfa92a07dd470f560c3747244f0345bef6d3d3_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:cbad311b4605a75485499df225d633311e931a7553894755150ee17628d25d82_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:eee6a9d0f9ca3d85ebe65eda6f63913bc29ab74e647fa2373056a9645edfa69d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:311e211f165f151d561f1b5c18a108768fd4dc448d540e2c979b5fa0cb46d8b8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:3f475e746aec5cbc23c9f5f389a2f0df29359cd5faeeaaca30265e69871c6482_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:5d00e92ac89981a77e1c5bc26296300617d7d23b8e2800d57c4019eb7d1e1bea_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6f78c96001c9ab90d7c10d437a2744b93f0c741463eaf95b1b0fba4858068c20_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:0da54b9c8cb6d9b17d62e4d2d6912bff231ea50753ebf659d8b4a14320e38466_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:3344f2367d39caeae7e0e0dcce2b91c647c8cbd0f6adb88a1d89e118180a7d46_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:3e7e18e9884efbceb31bc472e60eaea6ca604282d4b88f078ed78b217b791bf0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:7ffa85676a5c41082024514e1e7311ad5e9949e94806c67da962f3271e7b18cf_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:2b96b7905f75a1aa1d0726e12148110eded0d3a731328aac0a06742409e57907_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:865f91c109ecce4168d7845130ad5cdb2d744966b817346b412192f2bda5821a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c91d3720f78c937afa04ca6160a7e180fe9f172bddbde8e88d8aecb516fcc93a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:e1c7dcfba5eff7d14c6383712781e3d670dad1501377b2d047d33daf705f3a09_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:1551c36281a93d16bb9d115b68aaa008acaaf89a21c1bc4042aa69a7f84ed177_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- +155 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:72884
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72884.json