Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.7%top 51%

Red Hat Security Advisory: RHSA: Submariner 0.18.5 - bug and security update

0
High
Published: 05/12/2025 (05/12/2025, 15:04:37 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Submariner enables direct networking between pods and services on different Kubernetes clusters that are either on-premises or in the cloud. For more information about Submariner, see the Submariner open source community website at: https://submariner.io/. This advisory contains bug fixes and enhancements to the Submariner container images. Security fix(es): * quic-go: quic-go affected by an ICMP Packet Too Large Injection Attack on Linux (CVE-2024-53259) * golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336) * crypto/internal/nistec: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)

Affected software

Affected versions
>=2.11 <2.12>=2.12Red HatRed Hat ACMRed Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9s390xrhacm2/lighthouse-agent-rhel9@sha256:83336a9d35b707e9a91868916882e008156f3633f23349fd52e1f26e381224ec_s390xRed Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9ppc64lerhacm2/lighthouse-agent-rhel9@sha256:30ec5310eb49a4b6636b043c3c44186aafdf80cdefb5bb83a193f2966bc438b9_ppc64lemulticluster engine for Kubernetesmulticluster engine for Kubernetes 2.1arm64registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:835b56c294aa95e066dd0e4d37e4559e11450f39f31ac2e66d096da528d0e8f4_arm64Red Hat OpenShift distributed tracingRed Hat OpenShift distributed tracing 3.5.2amd64registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:d23b9c8d0266de7ce5427d125b2749053d2e4b44d632e3eb484775a5eede41b0_amd64Red Hat OpenShift distributed tracing 3.5Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 8)srcdelve-0:1.24.1-1.module+el8.10.0+22945+b2c96a17.src::go-toolset:rhel8Red Hat OpenShift Service MeshRHOSSM 2.5 for RHEL 8openshift-service-mesh/kiali-ossmc-rhel8@sha256:30059f1449c3397fa40946efa91ab009be4d56dda97116e471f62495d94f9446_s390xmulticluster engine for Kubernetes 2.10registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b69db5c2aac4decf99a4c97c09e9c7055b642c4849f7e78d74f78877702428e8_amd64Red Hat Enterprise Linux AppStream (v. 10)delve-0:1.24.1-1.el10_0.srcRed Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)aarch64Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)Red Hat OpenShift distributed tracing 3.5.3rhc-1:0.3.2-1.el10_0.srcmulticluster engine for Kubernetes 2.11.0registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:0451628c58cb6738977a1a5499f204b07e8ab02b41e949b27b263fea3ea61f88_amd64multicluster engine for Kubernetes 2.11multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:45985b45748ae291d47aa64078fffc8dab0e8bfda806b9939625ad774e6b3ef4_amd64multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:89c0187bbae1316dc2b339188399d35056da419ca5681c3c6b6c9ada8426ff5d_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:03:25 UTC

Technical Analysis

The Red Hat security advisory for the multicluster engine for Kubernetes (CVE-2024-45336 and others) addresses several vulnerabilities including a flaw in golang's net/http package where sensitive headers are incorrectly sent after cross-domain redirects. Additional fixes cover an ICMP Packet Too Large Injection Attack in quic-go (CVE-2024-53259), timing sidechannels in crypto/internal/nistec, and memory consumption issues in golang OAuth2 and JWT libraries. These vulnerabilities affect Red Hat Advanced Cluster Management for Kubernetes versions 2.11 and 2.12 on RHEL 9 for multiple CPU architectures (x86_64, s390x, ppc64le, aarch64). The advisory includes updated container images for Submariner components that facilitate networking across Kubernetes clusters. Red Hat has released patches and updated images to address these issues. No active exploitation has been reported. The advisory references multiple CVEs and provides links to Red Hat errata for further details.

Potential Impact

The vulnerabilities fixed in this advisory could lead to unintended disclosure of sensitive HTTP headers after cross-domain redirects, potential injection attacks via ICMP packets, timing side channels in cryptographic operations, and excessive memory consumption during token parsing. These issues could compromise confidentiality and stability of cluster management operations. Given the high severity rating by Red Hat, these flaws represent significant risks to the security posture of Kubernetes cluster management environments using the affected versions of Red Hat Advanced Cluster Management for Kubernetes.

Mitigation Recommendations

Red Hat has released official security updates and fixed container images for Red Hat Advanced Cluster Management for Kubernetes versions 2.11 and 2.12 on RHEL 9. Users should apply these updates promptly to remediate the vulnerabilities. The vendor advisory indicates that updated Submariner container images are available and should be deployed as part of the remediation. There are no indications that no action is required or that the issues are already mitigated without patching. Patch status is confirmed as official-fix via Red Hat errata RHSA-2025:4810 and related advisories. Users should follow Red Hat's guidance and update affected components accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:4810
Cve Count
5
Additional Cves
["CVE-2024-53259","CVE-2025-22866","CVE-2025-22868","CVE-2025-30204"]
Cvss Version
null

Threat ID: 6a160971e29bf47b50639dcf

Added to database: 05/26/2026, 20:58:25 UTC

Last enriched: 08/14/2026, 22:03:25 UTC

Last updated: 08/29/2026, 22:52:03 UTC

Views: 81

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:4810https://access.redhat.com/security/updates/classification/#important23299912341751234421923483662354195Canonical URLhttps://access.redhat.com/errata/RHEA-2025:3039ACM-17297HYPBLD-614Canonical URLhttps://access.redhat.com/errata/RHSA-2025:2789https://access.redhat.com/security/cve/CVE-2024-45336https://access.redhat.com/security/cve/CVE-2024-56171https://access.redhat.com/security/cve/CVE-2025-22866https://access.redhat.com/security/cve/CVE-2025-24528https://access.redhat.com/security/cve/CVE-2025-24928https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/red_hat_build_of_opentelemetryCanonical URLhttps://access.redhat.com/errata/RHSA-2025:3772https://access.redhat.com/security/updates/classification/#moderate2341750Canonical URLhttps://access.redhat.com/errata/RHSA-2025:75922362345Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3922Canonical URLhttps://access.redhat.com/errata/RHSA-2025:7326https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.6_release_notes/indexRHEL-53958RHEL-59506Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54432https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-39831https://access.redhat.com/security/cve/CVE-2026-46597https://access.redhat.com/security/cve/CVE-2026-66805https://access.redhat.com/security/cve/CVE-2026-66808Canonical URLhttps://access.redhat.com/errata/RHSA-2025:7466RHEL-58723RHEL-61262Canonical URLhttps://access.redhat.com/errata/RHSA-2025:9514Canonical URLhttps://access.redhat.com/errata/RHSA-2026:57194https://access.redhat.com/security/cve/CVE-2026-13676https://access.redhat.com/security/cve/CVE-2026-25680https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-27141https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-39817https://access.redhat.com/security/cve/CVE-2026-39819https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-39823https://access.redhat.com/security/cve/CVE-2026-39825https://access.redhat.com/security/cve/CVE-2026-39826https://access.redhat.com/security/cve/CVE-2026-39827https://access.redhat.com/security/cve/CVE-2026-39828https://access.redhat.com/errata/RHSA-2026:59556https://access.redhat.com/security/cve/CVE-2026-10059https://access.redhat.com/security/cve/CVE-2026-12143https://access.redhat.com/security/cve/CVE-2026-19130https://access.redhat.com/security/cve/CVE-2026-42507https://access.redhat.com/security/cve/CVE-2026-66794https://access.redhat.com/security/cve/CVE-2026-66795https://access.redhat.com/security/cve/CVE-2026-73266https://access.redhat.com/security/cve/CVE-2026-73267https://access.redhat.com/security/cve/CVE-2026-73268https://access.redhat.com/security/cve/CVE-2026-73269Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59557https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/cve/CVE-2026-66804Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59579https://access.redhat.com/security/cve/CVE-2025-30204https://access.redhat.com/security/cve/CVE-2026-39832https://access.redhat.com/security/cve/CVE-2026-42502https://access.redhat.com/security/cve/CVE-2026-47219https://access.redhat.com/security/cve/CVE-2026-54272https://access.redhat.com/security/cve/CVE-2026-66806Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses