Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0.0: new RHEL 9 container image security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-11393 — insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: Improper Proxy Configuration Allows Unauthorized Administrative Commands CVE-2025-22874 — crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509
🎯 Affected products6
- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-operator-bundle@sha256:b5f0ff2579eaa5f85452b009a2f7735238f87a05c3f7d503218807f0741c1a9f_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:08f473dec97e110a73e1c9886ee31512bb6937f87bdb95fbe77cb2d85695b936_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:0abc9cd56597eb0983b4c50704f7dca6736e745710ba627fafa0c892f250ed49_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:33ddc7c7c65374ab7b2b2c02f6319e52fe33904a9d951791cefcd72a39b66453_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:72d4826d2f9da25cb841a0f71411ade99515d23efc13420f057cdc4f804f0302_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Add the following to the Cryostat or JWS subscription YAML: > spec: > config: > env: > - name: INSIGHTS_ENABLED > value: "false" This will disable the affected proxy server. (Note: due to a separate issue, the above step will cause a crash loop in the Insights container for the operator, but this is harmless).
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:23236
- externalhttps://access.redhat.com/security/cve/CVE-2025-11393
- externalhttps://access.redhat.com/security/cve/CVE-2025-22874
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23236.json