RHSA-2026:2572HighCVSS 8.5
Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.2 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-53547 — helm.sh/helm/v3: Helm Chart Code Execution CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68156 — github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:2572
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-53547
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68156
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2572.json