- Issued:
- 2025-07-09
- Updated:
- 2025-07-09
RHEA-2025:10678 - Product Enhancement Advisory
Synopsis
ACS 4.8 enhancement update
Type/Severity
Product Enhancement Advisory
Topic
Updated images are now available for Red Hat Advanced Cluster Security for
Kubernetes (RHACS). The updated image includes new features and bug fixes.
Description
This release of RHACS includes new features and bug fixes. If you are
using an earlier version of RHACS, you are advised to upgrade to this
release 4.8.0.
New features:
For a list of new features and information about them, see: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.8/html-single/release_notes/index#release-notes-48
Bugs fixed:
- Previously, if messages contained non-UTF-8 characters, the Secured Cluster sensor would remain uninitialized and offline. It prevented proper monitoring of affected clusters. With this release, the Sensor now handles non-UTF-8 characters in user-provided data. As a result, the Secured Cluster sensor no longer fails to initialize due to these characters and correctly monitors all clusters.
- Previously, warning messages in sensor pod logs incorrectly indicated that images were Not Pullable because the system attempted to determine pullability even when the image ID was empty. As a consequence, images were skipped from workload CVE scans. RHACS 4.8 correctly scans the images for vulnerabilities.
- Fixed an issue where signing images multiple times with different keys led to failed image signature verification.
- Previously, sometimes RHACS did not correctly initialize the Scanner V4 integration with default indexer and matcher endpoints, which caused scanner pods to fail and prevented images from being scanned. With this update, RHACS correctly initializes the Scanner V4 integration, scans the images, and creates vulnerability reports as expected.
- Previously, creating a security policy with a cluster scope using the cluster’s name would cause the UI to crash upon viewing the policy. It was due to the system’s inability to resolve the cluster name to its corresponding ID correctly. This update enables proper resolution of cluster names to IDs in security policies. As a result, you can now view policies with cluster scope in the UI without encountering errors.
- Previously, the Scanner V4 failed to identify some critical CVEs in Java workloads because an unidentified jar error caused the scanner to skip valid JAR files during the scanning process. As a consequence, RHACS did not detect these vulnerabilities in the scan results. This update eliminates the `unidentified jar" error, enabling the scanner to process JAR files properly. As a result, the Scanner V4 now accurately identifies critical CVEs in Java workloads, providing comprehensive vulnerability scanning.
- Previously, the Cancel button on the delegated scanning page provided no visual feedback if you made no changes, leading to confusion about its functionality. This lack of feedback occurred because the button only reset the form for unpersisted changes. This update introduces an Edit button to initiate editing, making the Save and Cancel buttons visible and enabled only when you make changes.
Solution
If you are using an earlier version of RHACS, you are advised to upgrade to this release 4.8.0.
Affected Products
- Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
- Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
- Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le
- Red Hat Advanced Cluster Security for Kubernetes for ARM 4 aarch64
Fixes
- ROX-30000 - Release RHACS 4.8.0
CVEs
aarch64
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:0bb8f6827f37984043aad15cf3f82a5b1934db29a0dd0bee19bdfe9807956510 |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:719ac0ed5e4cfed0c1fce3b312ddd95fa6184566f688a2f56f98ce1ad536fa6d |
| advanced-cluster-security/rhacs-main-rhel8@sha256:edce208379b37ff92012d37c3568f5e8e12d673685a2e26a8ecf644488ccf3c1 |
| advanced-cluster-security/rhacs-operator-bundle@sha256:7f79ccd0c81cf72796dd21e805a107339e1f1fb60fca8d0aeab138323d5cdbb5 |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:c6540841a6a37e8f6e893eec0a720743d57106d1b4673c7641c24b5316ea0a5b |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:154e6f5018af945e8479e812847cf1e3f0a06fb9942e3e6ce0fdfbd77918442a |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:6b39235ce1bbb298822b44d5080e7677b67bcc8bc4d0298963452a940466a91f |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:c5c84c01e9a6a182225c947344bc8114edf5b5ec0a7c1cd4cd348552d5e19722 |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:65393c549e75134f733f8cc3f53785104da5843b620cf238cf5efe4b03b53d34 |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:db659ddfec0f9da7849f0ea85817023585526d50dd7890008306e2deda4bc715 |
| advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:715c9734ffc3d604e2cf02fbbb944eef312bae491533ea53f7ef3ff613094b49 |
| advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:c0dc2c62330105208b249ffaf7345745622f11ccf9e86b2c75fe39ef41e3d0df |
ppc64le
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:4d36055a2cebfef58c276ebae271c74b8259f38451967ab9c580a7237ca13cc1 |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:7039a4744ad9555133d394f3813564a295a29a7257b750a158060823630d2d0d |
| advanced-cluster-security/rhacs-main-rhel8@sha256:caa4e1c402b76d58fae3f8ff916feee52f76ee4ac3dd237c9e25b3d37dbdb79c |
| advanced-cluster-security/rhacs-operator-bundle@sha256:5e824301db864b7cadad42df50670314008e4466d3d708c5e1aad24045fc8d88 |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:9f802f3a074bf549d0fbd2bfd2b235c6fb57e198e203860b02a4f03860e2eab7 |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:52075d5026f80d6732595e36c7edeea886182f69d62a12330b5c6fb2e315213d |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:ba2262702a01c324b2fa0263fdf349e2d8dbaff88acb5e759793dc65b290c81d |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:b0fa1ba0021e7d96a2e47c529c454524d5d9f5626e4c80027e99b0205f4a26ef |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:912fecb78af08a7ead07a12da7903da38ba5505de4c61f0d440e869970e10173 |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:0e7c37c84058f04b619c603cf029d1114b33d32fcba4701ef73adb41a589cdd2 |
| advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:839836e2f3d1197ca6748192b400aae968f73536d9eebe3d50c4506604e75a10 |
| advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:19ea7516e235a9d9f66a083d1472db325e628cd95d546362262345a94688ecac |
s390x
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:f7fcc5d6b6841d650167d1de77936df159ed202585bfdb9783b924223d6af877 |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:49f7389a2a68e4db98054e65d5c0217059b3bec5766ca09c01e91cc9b2c1c0f1 |
| advanced-cluster-security/rhacs-main-rhel8@sha256:31adaa21d8726074ca834904bdc07bf27fdd62901da168f013b1592df4ca3143 |
| advanced-cluster-security/rhacs-operator-bundle@sha256:42c9c24bde43c739b4aaf50f6172c4c94e01e29994def60e89c13a1ffeae3881 |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:6bbddc3b4f45626398a3f58181b5fc1c38db53858eea3891bbadb65531d2d2aa |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:f17cc9146c58fc8ecac1ffaa1f58a10cabf343d1f90543b969fbb5e59f3add8a |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:b05aa5d7f5f2d61b441a5160f17754cfb17949d871f0f83c3a6b5134b007bbeb |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:acf55e6f23866d713bb2e9f0ab904e66fee0cd535dcd118f71cea7a3233334fa |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:da9879529175ed56f8ec8c3ae6db87e7a08ab3b947d324de310e44e0caaa3db4 |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:be7988830230c6aa09edc0d200c5e0d5b5401e8a51e2a13df4e8bc9469e12750 |
| advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:4e9ce34b9e7450199b9b85ab92e9f69df94580bddebd8f0295790b5aca5abd95 |
| advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:a0ba6ffbcf2d4235e3e63be9e0f29d6072b868bfaaa5a42babddfb3db54da483 |
x86_64
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:2c79a968652f8a9a0c5ea6c2cae634d75406e146a1ddf14791833ea0822b4a31 |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:9859659e93bbb1f98f017bf269b041177e99c602d020c42be4c9020fda9cac70 |
| advanced-cluster-security/rhacs-main-rhel8@sha256:bc817617f071d7ac488d4da54668cccfc05125874e6370f7c0a2aa3da37c25bb |
| advanced-cluster-security/rhacs-operator-bundle@sha256:1d82a14dbd8b224ef3121b728fb1b0fe71e777d0346052bc639a048595c846a7 |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:1a0298d2eb982dad6f1f2f18631206321a7c9ec84b52476b744d9a628c7561f5 |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:6056c58f2159449c69e1fb65cfb3aedd811fe2daac6fc88645de98df2da10c7b |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:b68ddf2b351118d884a4a94a629841fc13202d95f54482824f24f7fbc89b0e92 |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:39326a7195cd2bc97293c7bf066c68c889655794ddce60d3a3be3b9b50e13ceb |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:ddca0eb151ef1ff0d539247dfb9e0ceba21ea2a0378447417ca5593bfb4c351e |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:4d87e0fc3af791beec84199ef9d8175bb44169436513a729ab701e3ff5ec9393 |
| advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:3ef86270479748ffb2f06482340e7064c2b197c7c9ef412d81519f8d32e41340 |
| advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:cb4e1777501c82bad3645d60eb5b472b9ac7ab580174a9f29e8dcd49f08919c5 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.