Red Hat Security Advisory: Assisted Installer RHEL 9 components for Multicluster Engine for Kubernetes 2.10.3
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-32285 — github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products21
- multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:5d24f1068bac5555543881c41e5231d350ddcc9969b46dee50534727230679a8_arm64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:975b240b2e2f7eb955bd06acf36a9e3a4da8dbeb579ec23fb855da954c4ed46d_amd64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:a6fbb0152c42ec1ebaf91366028901d68d3eb20ab0a117d8558ebecf0bf8b1c9_s390x as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:fba8bf16dc461879e3669e81252229c0beb278efbea3193245fe3320eb0ad56d_ppc64le as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:01eb4feec1f88060499ba1d6dfcae4932542ff7ed45fa527522906b24f49798d_amd64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:1ec213a62c21a2b8da457e35499b0c1330b58638a2adfd8c44d647c73fbf7e1c_arm64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:33427bfd363db78d04996f37352b5dd77eb5ccde30055fd1bc49bd11a80af57c_ppc64le as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:7cab87bbc7c0de99680e959fc78ab84b9cd63f5929a11200a00180cc4aa8e86e_s390x as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:055922c629f46db60d21bc850a65eff3e1dd8cb2428591d464c6a9f5cfb97951_amd64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:0d5e3dca2317ddf5a25054606e06daf60592b6701e7451c2b2f65801f949aaf0_s390x as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:dbc2a04e7b9305d604e470225546610b2820349c276886ca0a57c6740b3b9080_ppc64le as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:f2dbe411f3af386282fa458544ce9c4f36d3a0f64e4a6d6efebd3c7087368779_arm64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:0befdb95081a251d79e7e629ffd31f367e8c61377fa9cc1786b11b9b9728791f_ppc64le as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:52ab915f5a790a05f756efb0c5f5ef45f3f9580029dceb4054f522a636e811bf_amd64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:9bce8a272554dad1cb79e08629bbacba5fdcd022083f9e6c95cdd2a5b98b0e62_s390x as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:cf8f9082509467538880188013567d671c666b50fcc8d9554cfd9630d43dc056_arm64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:10fa93f21c1452b729b6496984d3a40d104eb4b0d97aa18ac1b7def1260da1b1_s390x as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:2e9a932c8fa8300300b855cf9cae629cdafe46de59aae0b1c8592a4b38f3ad27_ppc64le as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:bc322f9d13d2d933d790f1e10cc5999369987f716f270be26ade5dc0cd1caa65_arm64 as a component of multicluster engine for Kubernetes 2.1
- registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:eef0df18ed2293d18c2b686e977b7aaedcaeeb25ab28e9689ddded9cffd4dbaf_amd64 as a component of multicluster engine for Kubernetes 2.1
✅ Remediation
For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.15. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:19099
- externalhttps://access.redhat.com/security/cve/CVE-2026-32285
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19099.json