Red Hat Security Advisory: RHTAS 1.4.2 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39833 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
🎯 Affected products21
- Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:15a1e1d82e2ac631cb5bd6aa420fad3f7e52c414d4efba2d642ace24c5b9f3b4_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:4a1174f4cdc367db08f99ccb9586bf0ff8faa47c3360482b4fb33e75588b53eb_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:e1b929b778eb5dc42b81c18cf1cab4a989ec9124de99dbabdaaec8f0531b41ae_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/cosign-rhel9@sha256:f8a19541958467e3f1aa9ddd2868f20ce7cb760581c3c965941bedade78058ef_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:55bf157183d6a9df8032ca0ab62c418a3cc8b591b1a26a193c5eed36bebd01ac_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:74f364bbf2fe939ce8a02f19afd8f43aa2478090c99067add41b6aff004fda4c_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:c9094568f2e694d6a3c7b0162f3b68a2ef9d2f299efce735afc582f66a27130b_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:f8b01d3f2d6400b4208d80d8b66eab7b1f4ec2cd4dcdef06552c3d05db0e896e_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:4f95c088ef66165779e4b2d5ba89cf2594dd0d837bb707350712dc13b8a27c90_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:7c443c3f2c72d1c3cd6ce6cde49a3b781a1b6336bd9b2d974cd69cdfa4c94098_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:ce50f18c962fc813d635461aa9e9bc4fdbf7e8236731caa49b05c1770465cac2_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/gitsign-rhel9@sha256:f9877376bb17567472e84a42ce27273ec3c537103a58d3ff5b616da1b9c18b75_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:0187f0248ce7d219797450636bedd086e14ee6932e676bb51d35592306965583_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:0ef106aebc41f050e4833a546a4259c877f3852b94ee914c16a6d646c82d6ec2_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:4565fb543e312c3d113f415fe7d59267086c16a98d8567d2094aed58ff63586e_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:ad6c77b11bdde5dcd5bdddcedfea9f0422e3b685fbf224165a20605b1882d8fc_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:01024a46eac2bb846cee776132a6ce78a69fdc9dfe75df7a0fb379bed6444db1_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:205ef0889fb950e337a07d793cec8cbdfd713c4190ddb374f8c2a6206506a66e_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:3a7241f722dbbc7f3bc86cfb15cf2b0d96738ad60ad49dbb0b413c524d50013f_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/updatetree-rhel9@sha256:d034bb82bde1eafe676ce11295bcac3a1e653cab1aa0eb1c61e494b8069f1582_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
✅ Remediation
Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Update affected Go applications to use golang.org/x/crypto version 0.52.0 or later, which rejects unsupported ConfirmBeforeUse keys instead of silently ignoring the constraint. As a workaround, do not add keys with ConfirmBeforeUse to the in-memory keyring from golang.org/x/crypto/ssh/agent, or use an SSH agent implementation that correctly enforces confirm-before-use.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:37271
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39833
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37271.json