Red Hat Security Advisory: Cost Management Metrics Operator Update
🔗 CVE IDs covered (10)
📋 Description
CVE-2025-5278 — coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification
CVE-2026-0915 — glibc: glibc: Information disclosure via zero-valued network query
CVE-2026-4878 — libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
CVE-2026-5450 — glibc: glibc: Heap Buffer Overflow in scanf with %mc format specifier and large width
CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-42764 — openssl: NULL pointer dereference in QUIC server initial packet handling
CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
🎯 Affected products6
- Cost Management 4
- registry.redhat.io/costmanagement/costmanagement-metrics-operator-bundle@sha256:fa43be2fd285110e13fb4e782479b28a6e59ffc25da384d4aae745b6d70c74c7_amd64 as a component of Cost Management 4
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:093ff7d3b7e420f4cd6650314bea628408ec38e2965e770295f4a5eb8e9b97ea_amd64 as a component of Cost Management 4
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:1c4cf70fef001a66b2d93b43668e21e87ccb1203e8206e7449c5a70d9204c593_arm64 as a component of Cost Management 4
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:7d1fc978c1e10cf51876a725fa41c53c52ecec884c2d25d6f782a7cbd87f4ca1_s390x as a component of Cost Management 4
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:c76ae9a58852c1e1d7b8745e7152ea06548dfcb07c448618d0f22ee01e110ddf_ppc64le as a component of Cost Management 4
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.openshift.com/container-platform/latest/operators/admin/olm-upgrading-operators.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Systems configured to operate in FIPS mode are not affected by this vulnerability. To mitigate this issue, ensure that OpenSSL is operating in FIPS mode by enabling the system-wide FIPS policy. This may have broader implications for cryptographic operations on the system and should be evaluated for compatibility with existing applications. A system reboot may be required for the changes to take effect. Workaround: To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack. Workaround: To mitigate this issue, ensure that the OpenSSL QUIC server has client address validation enabled. This is the default configuration. If the `SSL_LISTENER_FLAG_NO_VALIDATE` flag is being used with the `SSL_new_listener()` call, it should be removed to prevent the vulnerability from being exploitable.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:39981
- externalhttps://access.redhat.com/security/cve/CVE-2025-5278
- externalhttps://access.redhat.com/security/cve/CVE-2026-0915
- externalhttps://access.redhat.com/security/cve/CVE-2026-31790
- externalhttps://access.redhat.com/security/cve/CVE-2026-34182
- externalhttps://access.redhat.com/security/cve/CVE-2026-34183
- externalhttps://access.redhat.com/security/cve/CVE-2026-42764
- externalhttps://access.redhat.com/security/cve/CVE-2026-45445
- externalhttps://access.redhat.com/security/cve/CVE-2026-45447
- externalhttps://access.redhat.com/security/cve/CVE-2026-4878
- externalhttps://access.redhat.com/security/cve/CVE-2026-5450
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/cost_management_service/1-latest/html/getting_started_with_cost_management/steps-to-cost-management
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_39981.json