Red Hat Security Advisory: Gatekeeper v3.20.1 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🎯 Affected products10
- Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-operator-bundle@sha256:553df1c01fb5af70f42f32566ec9770ada039236fd634c512897010fc782e1cd_amd64 as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9-operator@sha256:0786205331ca629fb326c7239ce856206e4843da1308c74097b1cea8e41a6c7f_amd64 as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9-operator@sha256:2cc909243fab02d360477f11c857cf0bafc1388a3ed34cd77a6fd8f74f5358b4_arm64 as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9-operator@sha256:6f240a461b9736dda251112115cf4f226990963c266772c7bf8cb742a1245c33_s390x as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9-operator@sha256:cc13a5a7035928f24f40e0959fc105111c47ceea5c4de920171ed16062ff2109_ppc64le as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9@sha256:07474cc4fa38c312df45aa140ccbdf86de8fc6dd841d619d709b309ac88f844c_ppc64le as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9@sha256:17480df2c9bbb1c7ae8c276a6231784b6a1835ba2cb60bea5470d37a562f0e52_arm64 as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9@sha256:1ca76ad02ddf38c6330452d55e91d6400794698465e9cb041efb2f15093a8fca_s390x as a component of Gatekeeper 3.20
- registry.redhat.io/gatekeeper/gatekeeper-rhel9@sha256:e85d20ddc26eeef4a82e6c065f8b55e94d48ba8798aad32b4fe3d56c1a962e2a_amd64 as a component of Gatekeeper 3.20
✅ Remediation
For more information, see the following resources: Documentation - Open Policy Agent Gatekeeper documentation: https://open-policy-agent.github.io/gatekeeper/website/docs/ - Red Hat Gatekeeper Operator documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/governance/gk-operator-overview Support and troubleshooting - For support and troubleshooting, Gatekeeper is supported through a Red Hat Advanced Cluster Management for Kubernetes subscription: https://access.redhat.com/products/red-hat-advanced-cluster-management-for-kubernetes - The Open Policy Agent Gatekeeper community collaborates on Slack. Join the #opa-gatekeeper channel: https://openpolicyagent.slack.com/archives/CDTN970AX - Open issues on the Gatekeeper GitHub repository: https://github.com/open-policy-agent/gatekeeper/issues Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:74791
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74791.json