Skip to main content
EPSS 0.5%top 62%

Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI

0
High
Published: 09/08/2026 (09/08/2026, 07:57:24 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Release of RHOAI 2.25.11 provides these changes:

Affected software

Affected versions
>=1.18.0 <1.19.0Red Hatcert-manager operator for Red Hat OpenShiftcert-manager operator for Red Hat OpenShift 1.18amd64registry.redhat.io/cert-manager/cert-manager-istio-csr-rhel9@sha256:4e186b76cec8f162904aae30c97214d0ea0848d604359e4af82c3d00085ba78e_amd64registry.redhat.io/cert-manager/cert-manager-istio-csr-rhel9@sha256:e64804e94fe3781b7d371097e53749867a2b4b1783ada1660b5363e9df3cdb44_amd64registry.redhat.io/cert-manager/cert-manager-istio-csr-rhel9@sha256:41df7aabbce42599bad7fdc721cd12aa6e12d17e1c0658fb3294a1f68483d656_amd64Red Hat Web TerminalRed Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:423baadb7daeaf78b5df584e7e5e8f2ad991e0db803a22ec7a90f7d468e55415_amd64Red Hat Satellite 6Red Hat Satellite 6.16 for RHEL 8Red Hat Edge ManagerRHEM 1.0 for RHEL 9srcflightctl-0:1.0.3-1.el9em.srcRed Hat OpenShift AIRed Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:89cdb5783188b1b594cd7e0c6da1993397d60fe706e3469c331693f38c168b4d_amd64RHEM 1.1 for RHEL 10RHEM 1.1 for RHEL 9

Weaknesses

CWE-1050CWE-409CWE-1286CWE-295CWE-770CWE-367CWE-764CWE-551CWE-1341CWE-787CWE-1289CWE-281CWE-1284CWE-772CWE-476CWE-256CWE-303CWE-606CWE-22CWE-1333CWE-940CWE-346CWE-918CWE-306CWE-250CWE-338CWE-915CWE-639CWE-266CWE-79CWE-835CWE-444CWE-88CWE-212CWE-502CWE-93CWE-1287CWE-201CWE-805CWE-824CWE-617CWE-347CWE-807CWE-911CWE-776CWE-674CWE-214CWE-78CWE-1389CWE-125CWE-914CWE-414

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 18:03:44 UTC

Technical Analysis

CVE-2025-61729 is a denial of service vulnerability in the golang crypto/x509 package used by the cert-manager Operator for Red Hat OpenShift. The flaw occurs during error string construction in the HostnameError.Error() function when handling a specially crafted certificate, causing unbounded string concatenation and excessive resource consumption. This can lead to degraded performance or denial of service. The cert-manager Operator for Red Hat OpenShift versions from 1.18.0 up to but not including 1.19.0 are affected. Red Hat's advisory (RHSA-2026:0981) details the issue and recommends upgrading the operator. The default installation policy is automatic upgrade, which will apply the fix when available. Manual upgrade requires user approval. No explicit fixed version is provided in the advisory, so users should monitor Red Hat errata for updates.

Potential Impact

Successful exploitation of this vulnerability can cause excessive CPU and memory consumption on the affected system, resulting in denial of service conditions. There is no impact on confidentiality or integrity. The vulnerability affects availability by degrading system performance or causing service outages in the cert-manager Operator for Red Hat OpenShift.

Mitigation Recommendations

Red Hat recommends ensuring that all previously released errata relevant to your system are applied before upgrading. If the cert-manager Operator approval policy is set to 'Automatic' (the default), the operator will upgrade automatically when a new version is released, requiring no further action. If the policy is set to 'Manual', users must manually approve the upgrade. Users should follow the official Red Hat documentation for cert-manager Operator upgrades at https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html. Monitor Red Hat advisories for the availability of fixed versions and apply updates promptly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:0981
Cve Count
3
Additional Cves
["CVE-2025-66471","CVE-2026-21441"]
State
PUBLISHED

Threat ID: 6a160972e29bf47b5063a4a7

Added to database: 05/26/2026, 20:58:26 UTC

Last enriched: 08/10/2026, 18:03:44 UTC

Last updated: 09/14/2026, 10:01:28 UTC

Views: 117

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:0981https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2026-21441https://access.redhat.com/security/updates/classification/https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:41019https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_enterprise_linux/rhem-integrating-with-aaphttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_openshift_container_platform/edge-manager-install-rhem-ocp#edge-manager-verify-rhem-acm-console2418462244534524453562449833245597224559752456333245633624563382456339245772924665052466507246782224806802480681https://access.redhat.com/errata/RHSA-2026:270762458856SAT-44720SAT-45906Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1038Canonical URLhttps://access.redhat.com/errata/RHSA-2026:36796https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/managing_device_fleets_with_the_red_hat_edge_manager/assembly-edge-manager-introhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/edge_manager/index#edge-mgr-intro2456335https://access.redhat.com/errata/RHSA-2026:42047https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-42504https://redhat.atlassian.net/browse/WTO-359https://redhat.atlassian.net/browse/WTO-402https://redhat.atlassian.net/browse/WTO-407https://redhat.atlassian.net/browse/WTO-413https://redhat.atlassian.net/browse/WTO-418https://redhat.atlassian.net/browse/WTO-429https://redhat.atlassian.net/browse/WTO-433https://redhat.atlassian.net/browse/WTO-448https://redhat.atlassian.net/browse/WTO-450https://access.redhat.com/errata/RHSA-2026:1166Canonical URLhttps://access.redhat.com/errata/RHSA-2026:65126https://access.redhat.com/security/cve/CVE-2025-67030https://access.redhat.com/security/cve/CVE-2026-12151https://access.redhat.com/security/cve/CVE-2026-12243https://access.redhat.com/security/cve/CVE-2026-13149https://access.redhat.com/security/cve/CVE-2026-15075https://access.redhat.com/security/cve/CVE-2026-15154https://access.redhat.com/security/cve/CVE-2026-15378https://access.redhat.com/security/cve/CVE-2026-15581https://access.redhat.com/security/cve/CVE-2026-16745https://access.redhat.com/security/cve/CVE-2026-18608https://access.redhat.com/security/cve/CVE-2026-18611https://access.redhat.com/security/cve/CVE-2026-18617https://access.redhat.com/security/cve/CVE-2026-18620https://access.redhat.com/security/cve/CVE-2026-18621https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-27904Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses