Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: kubernetes1.36: * kubernetes1.36-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-client-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-kubeadm-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-systemd-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-1.36.2-2.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-47262 describes a flaw in containerd where a remote attacker can supply a maliciously crafted container image that triggers uncontrolled resource consumption and memory exhaustion, causing the containerd daemon to terminate and resulting in a denial of service affecting container runtime APIs such as Docker Engine or Kubernetes. Red Hat's container platform uses CRI-O instead of containerd as the container runtime interface, and while containerd libraries are bundled for OCI image operations, the vulnerable containerd daemon and its CRI plugin are not executed. Consequently, Red Hat Hardened Images are not affected by this vulnerability. The advisory also lists an update to Red Hat Hardened Images RPMs for Kubernetes 1.36 components, but no fixes for this vulnerability are needed in Red Hat products. The vulnerability is associated with CWE-770 (Allocation of Resources Without Limits or Throttling).
Potential Impact
If exploitable, this vulnerability could cause denial of service by exhausting system resources and terminating the container runtime process, making container APIs unavailable. However, Red Hat products are not affected because they do not execute the vulnerable containerd daemon code path. Therefore, there is no impact on Red Hat Hardened Images or related Kubernetes components.
Mitigation Recommendations
No mitigation is required for Red Hat products as the vulnerable code path in containerd is not executed due to Red Hat's use of CRI-O as the container runtime. Users should ensure they apply the provided RPM updates for Red Hat Hardened Images as per Red Hat's instructions for general bug fixes and enhancements. For other products using containerd, consult the respective vendor advisories for remediation.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: kubernetes1.36: * kubernetes1.36-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-client-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-kubeadm-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-systemd-1.36.2-2.hum1 (aarch64, x86_64) * kubernetes1.36-1.36.2-2.hum1.src (src)
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-47262 describes a flaw in containerd where a remote attacker can supply a maliciously crafted container image that triggers uncontrolled resource consumption and memory exhaustion, causing the containerd daemon to terminate and resulting in a denial of service affecting container runtime APIs such as Docker Engine or Kubernetes. Red Hat's container platform uses CRI-O instead of containerd as the container runtime interface, and while containerd libraries are bundled for OCI image operations, the vulnerable containerd daemon and its CRI plugin are not executed. Consequently, Red Hat Hardened Images are not affected by this vulnerability. The advisory also lists an update to Red Hat Hardened Images RPMs for Kubernetes 1.36 components, but no fixes for this vulnerability are needed in Red Hat products. The vulnerability is associated with CWE-770 (Allocation of Resources Without Limits or Throttling).
Potential Impact
If exploitable, this vulnerability could cause denial of service by exhausting system resources and terminating the container runtime process, making container APIs unavailable. However, Red Hat products are not affected because they do not execute the vulnerable containerd daemon code path. Therefore, there is no impact on Red Hat Hardened Images or related Kubernetes components.
Mitigation Recommendations
No mitigation is required for Red Hat products as the vulnerable code path in containerd is not executed due to Red Hat's use of CRI-O as the container runtime. Users should ensure they apply the provided RPM updates for Red Hat Hardened Images as per Red Hat's instructions for general bug fixes and enhancements. For other products using containerd, consult the respective vendor advisories for remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:11102-1
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-50195","CVE-2026-53488","CVE-2026-53489","CVE-2026-53492"]
Threat ID: 6a3aab62eed863c81e3a5ce8
Added to database: 06/23/2026, 15:50:58 UTC
Last enriched: 08/16/2026, 17:49:21 UTC
Last updated: 09/22/2026, 01:52:43 UTC
Views: 177
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.