Skip to main content
EPSS 0.3%top 78%

Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.10.1 release

0
High
Published: 08/04/2026 (08/04/2026, 15:29:30 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This release of the Red Hat build of OpenTelemetry provides new features, security improvements, and bug fixes. Breaking changes: * None Deprecations: * None Technology Preview features: * None Enhancements: * None Bug fixes: * None Known issues: * None

Affected software

Affected versions
=7.2Red HatRed Hat OpenShift distributed tracingRed Hat OpenShift distributed tracing 3.10.2amd64registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:356d387d225f1d73142d8ce3fb50086e4412c84313a2707032fdfc9c7ba4ab03_amd64Red Hat OpenShift distributed tracing 3.10.0Cost ManagementCost Management 4registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:093ff7d3b7e420f4cd6650314bea628408ec38e2965e770295f4a5eb8e9b97ea_amd64Red Hat DiscoveryRed Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:fa528360848fc7e33946c1e5d0617cad56963243ccc1c7fd7fa77075e744c8b6_amd64registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:3553b5e91195dcf76755e3c59bcc3ec8edda71dd367c6dc1b1ddfb4c38ab1d66_amd64Red Hat OpenShift distributed tracing 3.10.1Red Hat Enterprise LinuxRed Hat Enterprise Linux BaseOS (v. 9)srccoreutils-0:8.32-41.el9_8.srcRed Hat Enterprise Linux BaseOS (v. 10)s390xcoreutils-0:9.5-8.el10_2.s390x7.2Cost Management Metrics OperatorCost Management Metrics Operator 4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:39:11 UTC

Technical Analysis

This vulnerability (CVE-2025-5278) affects the GNU Coreutils sort utility, specifically its begfield() function, which is vulnerable to a heap buffer under-read. When a user runs a crafted command using the traditional key specification syntax with an exceptionally large character position value, the program may read memory before the allocated buffer. This can cause the sort utility to crash or leak sensitive data. The severity is considered moderate because exploitation requires an uncommon input pattern and does not allow code execution or privilege escalation. Red Hat's default security configurations (SELinux, ASLR, memory protections) further mitigate exploitability. No patch or workaround meeting Red Hat's criteria is currently available. The vulnerability mainly impacts availability due to potential crashes.

Potential Impact

The impact is limited to potential denial of service through application crashes or minor information disclosure due to heap buffer under-read. There is no known ability to execute arbitrary code, escalate privileges, or directly compromise data confidentiality or integrity. Default security mechanisms in Red Hat Enterprise Linux reduce the likelihood and scope of exploitation. The vulnerability does not pose a critical risk but may cause service disruption if exploited.

Mitigation Recommendations

Red Hat has not provided an official patch or mitigation for this vulnerability as no suitable mitigation meets their criteria for ease of use, deployment, or stability. Default security features such as SELinux enforcement, ASLR, and memory protections help reduce exploitability. Users should monitor Red Hat advisories for any future updates or fixes. No immediate action is required beyond applying standard security best practices and updating when a fix becomes available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:28911
Cve Count
1
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a3c3b2b4853345fc1c944d4

Added to database: 06/24/2026, 20:16:43 UTC

Last enriched: 08/14/2026, 23:39:11 UTC

Last updated: 09/21/2026, 22:01:30 UTC

Views: 140

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:46836https://access.redhat.com/security/cve/CVE-2025-5278https://access.redhat.com/security/cve/CVE-2025-6170https://access.redhat.com/security/cve/CVE-2026-11332https://access.redhat.com/security/cve/CVE-2026-15308https://access.redhat.com/security/cve/CVE-2026-42055https://access.redhat.com/security/cve/CVE-2026-48864https://access.redhat.com/security/cve/CVE-2026-5435https://access.redhat.com/security/cve/CVE-2026-54369https://access.redhat.com/security/cve/CVE-2026-54370https://access.redhat.com/security/cve/CVE-2026-5450https://access.redhat.com/security/cve/CVE-2026-58016https://access.redhat.com/security/cve/CVE-2026-5928https://access.redhat.com/security/cve/CVE-2026-6238https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/subscription_central/1-latest/#DiscoveryCanonical URLhttps://access.redhat.com/errata/RHSA-2026:39981https://access.redhat.com/security/cve/CVE-2026-0915https://access.redhat.com/security/cve/CVE-2026-31790https://access.redhat.com/security/cve/CVE-2026-34182https://access.redhat.com/security/cve/CVE-2026-34183https://access.redhat.com/security/cve/CVE-2026-42764https://access.redhat.com/security/cve/CVE-2026-45445https://access.redhat.com/security/cve/CVE-2026-45447https://access.redhat.com/security/cve/CVE-2026-4878https://access.redhat.com/security/updates/classificationhttps://docs.redhat.com/en/documentation/cost_management_service/1-latest/html/getting_started_with_cost_management/steps-to-cost-managementCanonical URLReference 30Reference 31Reference 32Reference 33Reference 34Reference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43https://access.redhat.com/security/cve/CVE-2026-42507https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/distributed_tracing/distributed-tracing-platform-tempoCanonical URLhttps://access.redhat.com/errata/RHSA-2026:50205https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-39823https://access.redhat.com/security/cve/CVE-2026-42504https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/red_hat_build_of_opentelemetryCanonical URLhttps://access.redhat.com/security/updates/classification/#moderateCanonical URLCanonical URLReference 59Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses