Red Hat Security Advisory: OpenShift File Integrity Operator bug fix and enhancement update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products5
- OpenShift File Integrity Operator - FIO 1
- registry.redhat.io/compliance/openshift-file-integrity-operator-bundle@sha256:bafc11174a80529da7f954f1636d3b3f83e4de63c445210293b20eee04527a3b_amd64 as a component of OpenShift File Integrity Operator - FIO 1
- registry.redhat.io/compliance/openshift-file-integrity-rhel8-operator@sha256:0c7dc211b2a8c47feba627e330a7dfb446110d31fc660cb95a68845469c12918_amd64 as a component of OpenShift File Integrity Operator - FIO 1
- registry.redhat.io/compliance/openshift-file-integrity-rhel8-operator@sha256:2fe717888d8e7cedfdecb8b0c6c9a52a114d5c886295259f8b1cb7da96cfe28a_s390x as a component of OpenShift File Integrity Operator - FIO 1
- registry.redhat.io/compliance/openshift-file-integrity-rhel8-operator@sha256:78c550a290beb65d30bc966c167b1d1a55d8768b71d02c097b2737a444ef5b7f_ppc64le as a component of OpenShift File Integrity Operator - FIO 1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.openshift.com/container-platform/latest/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:74025
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74025.json