Skip to main content
EPSS 0.6%top 55%

Red Hat Security Advisory: OpenShift Compliance Operator bug fix and enhancement update

0
High
Published: 04/16/2026 (04/16/2026, 10:06:55 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The OpenShift Compliance Operator v1.9.0 is now available. See the documentation for bug fix information: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/compliance-operator#compliance-operator-release-notes

Affected software

Affected versions
>=1.0.0 <1.9.0Red HatOpenShift Compliance OperatorOpenShift Compliance Operator 1amd64registry.redhat.io/compliance/openshift-compliance-operator-bundle@sha256:e2cbcab60fad0718e63a8c9bacaca97d205735e968505a56ae1a1c523d5ee2da_amd64Red Hat OpenStack Services on OpenShiftRed Hat OpenStack Services on OpenShift 18.0registry.redhat.io/rhoso-operators/barbican-rhel9-operator@sha256:a7f59f1e7c7381cb1cc9d9deb8e05811233683432db49bb03439709c056e35f8_amd64Builds for Red Hat OpenShiftBuilds for Red Hat OpenShift 1.6.1registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:6696d83a6b93b43d56b9363fce455b46983a081dc5acaadaf9397645c01466da_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v.9.6)srcpodman-5:5.4.0-15.el9_6.srcRed Hat Enterprise Linux AppStream EUS (v.9.4)buildah-2:1.33.13-2.el9_4.1.srcBuilds for Red Hat OpenShift 1.6.0Compliance OperatorCompliance Operator 1Red Hat OpenShift BuildsRed Hat OpenShift Builds 1.6.4Red Hat OpenStack Services on OpenShift 18Red Hat AI Inference ServerRed Hat AI Inference Server 3.2registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:e2a077acf23766ef900942296ce963a624d2c4b45ff22ca77cadeb94c051fd95_amd64registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:c17e6f7e40e6de8a08799b65ce90092d09340dd7f92378ca26dd38cf8c2e870f_amd64registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:7536efb184e4161d6b8a11477392b93613408c7d68daebb5cbad73b57a985e26_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:22:51 UTC

Technical Analysis

CVE-2025-52881 is a local privilege escalation vulnerability in runc, the container runtime used by Red Hat OpenShift Builds. It allows an attacker with minimal privileges to redirect writes of LSM process labels to dummy tmpfs files, bypassing the correct application of security labels and potentially enabling container escape. This vulnerability is a more advanced variant of CVE-2019-16884. The flaw arises because runc does not adequately verify the target of LSM label writes, allowing improper link resolution and arbitrary file writes within procfs. Red Hat has classified this as an important flaw with high impact on confidentiality, integrity, and availability, but limited to local attacks. The vendor has released an updated OpenShift Compliance Operator (v1.9.0) that includes fixes and enhancements related to this and other issues. Mitigations include running containers rootless to reduce privileges, but SELinux and AppArmor cannot fully prevent exploitation due to the privileged nature of the container runtime.

Potential Impact

The vulnerability allows a local attacker with minimal privileges to bypass Linux Security Module protections by redirecting writes of security labels to unintended files, potentially leading to container breakout and unauthorized code execution. The impact includes high confidentiality, integrity, and availability risks within the affected container environment. However, exploitation requires local access and user interaction. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released an updated OpenShift Compliance Operator image version 1.9.0 that addresses this vulnerability. Users should apply this update following Red Hat's official update procedures. Additional mitigations include running containers in rootless mode to reduce the privileges of runc and block most inadvertent writes. SELinux and AppArmor do not fully mitigate this vulnerability due to the privileged nature of the container runtime. Users should ensure all previously released errata are applied before updating. No urgent action is required beyond applying the official update and considering rootless container usage.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:8433
Cve Count
7
Additional Cves
["CVE-2025-61726","CVE-2025-61729","CVE-2025-68121","CVE-2026-4645","CVE-2026-25679","CVE-2026-33186"]
State
PUBLISHED

Threat ID: 6a160954e29bf47b5061950b

Added to database: 05/26/2026, 20:57:56 UTC

Last enriched: 08/14/2026, 22:22:51 UTC

Last updated: 09/11/2026, 22:06:30 UTC

Views: 125

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:8433https://access.redhat.com/security/cve/CVE-2025-52881https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-4645https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:22030https://access.redhat.com/security/updates/classification/#important24047152407258Canonical URLhttps://access.redhat.com/errata/RHSA-2026:0050https://access.redhat.com/security/cve/CVE-2025-66418https://docs.redhat.com/en/documentation/builds_for_red_hat_openshift/1.6Canonical URLhttps://access.redhat.com/errata/RHSA-2026:0426Canonical URLhttps://access.redhat.com/errata/RHSA-2026:39894https://access.redhat.com/security/cve/CVE-2026-23490https://access.redhat.com/security/cve/CVE-2026-32280https://catalog.redhat.com/software/containers/searchCanonical URLhttps://access.redhat.com/errata/RHSA-2026:61627https://access.redhat.com/security/cve/CVE-2025-62593https://access.redhat.com/security/cve/CVE-2026-0994https://access.redhat.com/security/cve/CVE-2026-11822https://access.redhat.com/security/cve/CVE-2026-11824https://access.redhat.com/security/cve/CVE-2026-40192https://access.redhat.com/security/cve/CVE-2026-41523https://access.redhat.com/security/cve/CVE-2026-44222https://access.redhat.com/security/cve/CVE-2026-48586https://access.redhat.com/security/cve/CVE-2026-48746https://access.redhat.com/security/cve/CVE-2026-50193https://access.redhat.com/security/cve/CVE-2026-54060https://access.redhat.com/security/cve/CVE-2026-54234https://access.redhat.com/security/cve/CVE-2026-54235https://access.redhat.com/security/cve/CVE-2026-54283https://access.redhat.com/security/cve/CVE-2026-54399https://access.redhat.com/security/cve/CVE-2026-54512https://access.redhat.com/security/cve/CVE-2026-55379https://access.redhat.com/errata/RHSA-2026:61628https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2025-69223https://access.redhat.com/security/cve/CVE-2026-21441https://access.redhat.com/security/cve/CVE-2026-24049https://access.redhat.com/security/cve/CVE-2026-25087https://access.redhat.com/security/cve/CVE-2026-28684https://access.redhat.com/security/cve/CVE-2026-42311https://access.redhat.com/security/cve/CVE-2026-55380https://access.redhat.com/security/cve/CVE-2026-55969https://access.redhat.com/security/cve/CVE-2026-56208https://access.redhat.com/security/cve/CVE-2026-56209https://access.redhat.com/errata/RHSA-2026:61629https://access.redhat.com/security/cve/CVE-2026-55574Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses