RHSA-2026:73380HighCVSS 7.1
Red Hat Security Advisory: OpenShift Virtualization v4.20 Images
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
🎯 Affected products4
- Red Hat Container Native Virtualization 4.20
- registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel9@sha256:296eb5081b77bace58d5ea32961d0b43d0152ba3ee7f3e881eeb0874efbd2f94_s390x as a component of Red Hat Container Native Virtualization 4.20
- registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel9@sha256:eb0b0a3f068ece61aaa4d0559d876b32490121df884ad9520509d6541a4b73e6_arm64 as a component of Red Hat Container Native Virtualization 4.20
- registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel9@sha256:f2a2923596334eabd060f72278bfaf9f6d7bae73019519ee0f2d0f09611035ab_amd64 as a component of Red Hat Container Native Virtualization 4.20
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).