RHSA-2026:73193HighCVSS 7.1

Red Hat Security Advisory: OpenShift Virtualization v4.19 Images

Published
September 29, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution

🎯 Affected products4

  • Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel9@sha256:0c4f01c6c75052e66b2c227ddfba2b37ac4b369135d3b3dfa022aa0d54cfd5a5_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel9@sha256:d5088c45b132e6cc09c80d854dc55abac014e4552e65eabd8fead2fd5232b191_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel9@sha256:fb5dfbb4f852ecfb0d4ad0ce5e9b7f5e4f7250aced2a086e34d1c64faf6138ef_s390x as a component of Red Hat Container Native Virtualization 4.19

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).

🔗 References (4)