Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:11479 - Security Advisory
Issued:
2025-07-21
Updated:
2025-07-21

RHSA-2025:11479 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: ACS 4.7 enhancement and security update

Type/Severity

Security Advisory: Moderate

Topic

Updated images are now available for Red Hat Advanced Cluster Security for
Kubernetes (RHACS). The updated image includes security and bug fixes.

Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

This release of RHACS 4.7.5 includes security and bug fixes. If you are
using an earlier version of RHACS 4.7, you are advised to upgrade to this
patch release 4.7.5.

Bugs fixed:

  • Before this update, incorrect interpretation of Red Hat Enterprise Linux (RHEL) 10 Common Platform Enumeration (CPE) strings caused Scanner V4 to fail distribution checks on RHEL 10 systems. With this update, an updated RHEL CPE major version pattern resolves the issue, and Scanner V4 can now correctly support RHEL 10.
  • Before this update, the failure of Sensor to call stream.Recv() caused gRPC flow control to block image reprocessing every 4 hours. With this update, the reprocessing loop includes a timeout for sending messages to Sensors, which resolves the issue and resumes the image reprocessing as expected.
  • Before this update, you could observe excessive logging of telemetry collection status, resulting in log spam. With this update, the telemetry collection has been configured to not emit repeated logs continuously, which resolves the issue and significantly reduces the log volume.
  • Before this update, a flaw in the signature verification algorithm caused valid signatures to be reported as invalid if they had a certain payload format. With this update, the enhanced robustness of the algorithm resolves the issue, and the system can now correctly assess the validity of signatures.

Security issue(s) fixed:

  • Flaw in net/http allowed request smuggling due to improper handling of bare line feed (LF) in chunked data. (CVE-2025-22871)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Solution

If you are using an earlier version of RHACS 4.7, you are advised to upgrade to this patch release 4.7.5.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le
  • Red Hat Advanced Cluster Security for Kubernetes for ARM 4 aarch64

Fixes

  • BZ - 2358493 - CVE-2025-22871 net/http: Request smuggling due to acceptance of invalid chunked data in net/http
  • ROX-30092 - Release RHACS 4.7.5

CVEs

  • CVE-2019-17543
  • CVE-2023-40403
  • CVE-2024-12718
  • CVE-2024-23337
  • CVE-2024-53920
  • CVE-2025-4138
  • CVE-2025-4330
  • CVE-2025-4435
  • CVE-2025-4517
  • CVE-2025-4802
  • CVE-2025-6020
  • CVE-2025-6021
  • CVE-2025-22871
  • CVE-2025-47273
  • CVE-2025-48060
  • CVE-2025-49794
  • CVE-2025-49796

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html/release_notes/release-notes-47

aarch64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:d196be6afa8e8f414261f338a170ebd603501f5443ebc94bdeafbbce0c9a2bad
advanced-cluster-security/rhacs-collector-rhel8@sha256:5971d1027a17f0f09f491c90803e7fd6b28a8278cc65957c2c609d535f2a57d3
advanced-cluster-security/rhacs-main-rhel8@sha256:b0e8add7c50671a33b5b871765a27c454e9f906972df6ba58e8c7cca6f29577e
advanced-cluster-security/rhacs-operator-bundle@sha256:b25030fe76bfdec49c19a0c463983de579e251e97d1ff79313bcfd817044e53a
advanced-cluster-security/rhacs-rhel8-operator@sha256:0ae31519a4168ec0180ba237e77557aad09642c4f56fc83fa286c77314c7ed3c
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3073389c9ee2eea0acccb7f728a58af9f09ac96f602a128044eb55e2df8a67b0
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:8c1036b0dbd905c9cb5ac5303484dcef6e70bda8ba808a462e286a4d2d35605e
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:8bad558e1b79f535bcb8912d95b5de7d90c00b7c04654b505fe7427033ca72f4
advanced-cluster-security/rhacs-scanner-rhel8@sha256:239aed396aa303b7a2000fb31e00c4e93dbd0de3be1980bef80998dc53e84dba
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:efbc1c135f9b58216feaa68824574cc2da17b7ea023e5c7ed5a9057da4e040f6
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:fd45899205271b4d83f80a965737a94f6db49293619c564c5cb823cc30aa8b17
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:001562a7b331a9507306980f1dba9f666c693f1b470a6bef4bff1270653ff627

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:0e33392da0d7bbb235b4b66cb8d78942b18e17346bef10debf66c94c2eb919cd
advanced-cluster-security/rhacs-collector-rhel8@sha256:84c178fa81e2d734f443f324f68a69dcb2e9343c9e117aee1d17cdc06b262975
advanced-cluster-security/rhacs-main-rhel8@sha256:84f6213a7e624f6840dc333a9b026bde8f8dc5b138def8ad34f77ad4c8290a7d
advanced-cluster-security/rhacs-operator-bundle@sha256:3164da1efd6901ed655b9f47177a841060e576b6045e8ba2f8fd527b6dfdead5
advanced-cluster-security/rhacs-rhel8-operator@sha256:b361c57d1b4b145a0704d6e386fce75cde046fcc4f5e4313f6abcb85f0f2c917
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:41e74ab416bc94255ba81807cf94f5b6dbd5fee0be33fdd79b94beace693053d
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:540c97fdc8a7a802f44597e3a831e7e0a08e2dd19fd532303ab2745fffb2dd0a
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:8aa8d37a96b7749aca258238799d742756971dd12542eac1a376658de04816f7
advanced-cluster-security/rhacs-scanner-rhel8@sha256:b9a3446b842615f255d80ea7860e5776df8d51c6977fe679953bcda2da8a3967
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:871d1bb3f623723e9e401e685a9a39101eb626e8d3e09b81d4698f0c9498629b
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:7b2f15e4dedc7936cadecfc2750ed6d50cff5c5c4374ba5940baa648e8ca59a3
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:08987210a572cfa013c68a0d671de7bb90b7ddbbdbf81215e2af762d273682e5

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:f2d6d9ad43674206c737c80a9bddb16e399dcd6cc6dde768bc1e551e442685f6
advanced-cluster-security/rhacs-collector-rhel8@sha256:dee0c583b23b994947bc5a3460b00b38ac42b1c9c9fa2120ae2671f1fcfdaa8f
advanced-cluster-security/rhacs-main-rhel8@sha256:4bece34ab6f756802f34902b56b2c58b2004f785d1ac9a144d7b6c60fb468f94
advanced-cluster-security/rhacs-operator-bundle@sha256:4c6cbd9b76fc8f075ba6e6224931b2c83b321d6738c2ce0e47450c0415ebfa22
advanced-cluster-security/rhacs-rhel8-operator@sha256:b5c099016b002a2cbf77f945c7b5226d7c2b3d9dfd7eb5612d188bc78b1d2ed5
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:1f4e220c147304bd90aca478f58d8d00caf96bb231ca8f4d8c61dd9146272f2d
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:593c13b2add7323424985a86fb78c5632331ec63219a1db89d84ae4924923318
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:f666c610910a6ebf1a6b27f6a7208d11d9f25090895b5e6ddbba1dcbb53498ee
advanced-cluster-security/rhacs-scanner-rhel8@sha256:7795400c46d7161a83eabd75899cb39dd47b3a9b6d6f9307df42b818a7e73d92
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:634bdfd5abfb3d0ee01b17353c3a2b75e2dcfd28045ded6527e85a5e6d10132f
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:549a4d03f7a7597445afba4155f9d03f479e693c05358d25367e5f34f1b38b74
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:904c3e32561f485c92c70265b92ec1a8f740a7920c9dfbe8b539ccc1cfaec3b8

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:3658f562db59177ca5fa2fa6abdcacf422d4e990ba5f252742d921dfb33031c4
advanced-cluster-security/rhacs-collector-rhel8@sha256:373e1d052319793c422f5bf1a2813ab28b127ed3ddbfa59d438dba981a22390f
advanced-cluster-security/rhacs-main-rhel8@sha256:b3c49717ae9d165c49899fa2229259dacc8e1b50b790ebf4e5ee2a2c9937f40e
advanced-cluster-security/rhacs-operator-bundle@sha256:15338b82f8d118e34a3f83fc5a7a487f98c7ecfeed63b3109de36260d0ce8193
advanced-cluster-security/rhacs-rhel8-operator@sha256:677fc19a2525e922f719c5520b25771693221912633236a63376e30b8735b077
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:cff0015b4de3aeb6dd25ff7ed914dbcc75dd610928262f45e07568e6eaaecbe9
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:68c2c3ef584110c7073caf2a30c06193c79cb393f04b6febd7f187b9a5380821
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:6cf7465998f4ffb5875678b2c8f99ab8d48349a47efedf87f83ec95d89179f2e
advanced-cluster-security/rhacs-scanner-rhel8@sha256:cf31fa05dd1136e9f59464e16fcf07aa86c2c6bf0f1b337d57f598d9852b6610
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:1290bb181f6fbddebf6116ad649af8126ea288e3bb755a2562b227b74d9e7689
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:bc031662fe92831d1ee1994d024436405ff953d4bf7bf77022a04172776acdf7
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:636eeb96634713bc5a59284349bfc92fe766fbd569e4b22d27947a424ea8cd31

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility