Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:36873 - Security Advisory
Issued:
2026-07-08
Updated:
2026-07-08

RHSA-2026:36873 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Submariner v0.20 security fixes and container updates

Type/Severity

Security Advisory: Important

Topic

Submariner v0.20 General Availability release images, which provide enhancements, security fixes, and updated container images.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section.
Red Hat Advanced Cluster Management for Kubernetes v2.13

Description

Submariner is a Kubernetes operator that enables cross-cluster connectivity for services and pods, implementing KEP-1645 (Multi-Cluster Services API). After deploying the Submariner operator, it can enable direct networking between pods and services across different Kubernetes clusters.

For more information about Submariner, see the Submariner open source community website at: https://submariner.io/.

Solution

For release note details, see the upstream Submariner release notes:

https://submariner.io/community/releases/

Downstream-specific issues resolved:

  • ACM-17819
  • ACM-21727
  • ACM-21731
  • ACM-24786
  • ACM-25148
  • ACM-25152
  • ACM-25169
  • ACM-29510
  • ACM-29564
  • ACM-29565
  • ACM-29574
  • ACM-29584
  • ACM-29585
  • ACM-29586
  • ACM-29587
  • ACM-29774
  • ACM-29775
  • ACM-29800
  • ACM-30133
  • ACM-30722
  • ACM-30723
  • ACM-30724
  • ACM-30725
  • ACM-30970
  • ACM-36662
  • ACM-37000
  • ACM-37038
  • ACM-7515
  • ACM-8292

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/

Affected Products

  • Red Hat Advanced Cluster Management for Kubernetes

Fixes

  • ACM-17819 - Submariner Connectivity E2E failing on OCP 4.18
  • ACM-24786 - Submariner documentation : add workround details for OVNK SNAT issue
  • ACM-30970 - Add in prequsites section : Avoid port 4500 for openstack
  • ACM-8292 - Assess requirement and identify work (if any) - Multicluster Networking

CVEs

  • CVE-2025-47950
  • CVE-2025-59530
  • CVE-2025-61726
  • CVE-2025-61729
  • CVE-2025-68121
  • CVE-2025-68151
  • CVE-2026-26017
  • CVE-2026-26018
  • CVE-2026-44740
  • CVE-2026-53488
  • CVE-2026-53492

References

  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:f856073e50bb0cc5519d7ec413e4ff92da750fbce141cefbeaf3dd945149ea06
registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:4fb8d0f81059a89c233aa55d72b5007c42811557a815ce0ec7f3ee042cb6a560
registry.redhat.io/rhacm2/nettest-rhel9@sha256:e17325bedd6b7212772ea2888a703b159115cd573320c5313bd649c962674e60
registry.redhat.io/rhacm2/subctl-rhel9@sha256:438c6d99281497b67dfdf4d2bb5f5c13abf1fce3ea6f50d96ed5f5c88fe5086e
registry.redhat.io/rhacm2/submariner-operator-bundle@sha256:dddc574f9c2ed8e7266522761842ea2c88e9cad3e284cf9c3522fd5e834d82ef
registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:3ddcf732be3481259c42b647cb273b5968ddf2d5ff5c31de4ee8cfbe3182c238
registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:4e0213961fd6865df9076e5c613370a45f68ba6fef646e0e23492358d00d167c
registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:bda6bd1cadc353bf93dbb387b0e473840efa4488a11488b9e0f91e22a86cb834
registry.redhat.io/rhacm2/submariner-route-agent-rhel9@sha256:6eea9dda872fe39f1f8b6ca114434dab0d98c9da64864ee6281362b992e59f7b

ppc64le

registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:b6aac33c3af11a883a7c45d6dc8392d9ffc8fff09b21f31404b97e48beebbe7b
registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:2d9c2c52df2251db58f47eb0b982ecf62175d9aa29ba7a6a3d72001034441390
registry.redhat.io/rhacm2/nettest-rhel9@sha256:74f9c159bf2af9e6fc2188234ba7146f00519f130e9d7c2d14902e73a0c115bd
registry.redhat.io/rhacm2/subctl-rhel9@sha256:e0e37798c3c66494c68259d79ead0e18fe7327f27c7babf72386b210595f1877
registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:e2da53cce8f1e6fa1a6d235047b709835f08d1186833baae48ce106dd9029e25
registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:21f72fb118a708fcf5e0bb6dc5091954275f0496c0f4fbd67937c2ef6e94a12b
registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:85cf9cf1f440604ad7346608d6920720acc9e75b2a0c3579439e73d0a7278554
registry.redhat.io/rhacm2/submariner-route-agent-rhel9@sha256:fb70c6acd3110cef92807982f8c66403552507d2bc52e212b0ef97ae116a50c7

s390x

registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:c045357b268bc940f2ccd50d17eaeba2a80f332a4b76baff1fcfdec8992eb785
registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:f10f17672a539dd7a7f5f40b52d9bed10ea03438141259e7fbe75373c73985f5
registry.redhat.io/rhacm2/nettest-rhel9@sha256:cbbb16e36221a15955a62d54ff631029080ab27f92d8c6b9e4507bf4d32b686f
registry.redhat.io/rhacm2/subctl-rhel9@sha256:d6e2d8f486276918329ca386bd54385d944009a412830d8d3c175ab38f23dcf4
registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:9abe7999226734514841159e0555e5a13be581b84c7bd9899f7f956dae5fea07
registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:cdb56f8231fef80d46bf68132c1e7a40fd2592e3024590cea801ece6d3de6b14
registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:62857f91e51e167d39fcf932c444d04b6105720299372789fe97941aafa5ff52
registry.redhat.io/rhacm2/submariner-route-agent-rhel9@sha256:132249054adcac03505c8ba0668c0d625ac17187252b529f547a60c48e5e5ab6

arm64

registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:08c46fced26b98ad3e1a07a3f3c7239521d916bfe116d2e7a44068011319ccd3
registry.redhat.io/rhacm2/lighthouse-coredns-rhel9@sha256:548a13d40574a1efd59f327a0d9193ff8e0109b571645ea16721347a89774e0d
registry.redhat.io/rhacm2/nettest-rhel9@sha256:0bafca38a2e80233c1b859d4bc2d9bde815678460cf71d5aac5804a1524344dc
registry.redhat.io/rhacm2/subctl-rhel9@sha256:a8b2139b2664316d43fc31479c468b4af7afb0d370a81a794bd71dbb4d97de0f
registry.redhat.io/rhacm2/submariner-gateway-rhel9@sha256:cdd5f5b983486e39cdaa76f3fb97266994863b68be8dd1fabdba8592f0f4b581
registry.redhat.io/rhacm2/submariner-globalnet-rhel9@sha256:1605dc6f3baba80be77d26e09d32a3adfc4711fdbf90dca8f821dcae6131cb95
registry.redhat.io/rhacm2/submariner-rhel9-operator@sha256:cda143023feee01e4cd88a075c93a587ed14f6071611ef2516d89ad33f51ee0d
registry.redhat.io/rhacm2/submariner-route-agent-rhel9@sha256:816d881aa7a3c8c7257877a6b84239fed4e3b66d582fd463f1b877bde5d6e378

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility