- Issued:
- 2026-07-23
- Updated:
- 2026-07-23
RHSA-2026:44624 - Security Advisory
Synopsis
Red Hat OpenShift distributed tracing platform (Tempo) 3.10.2 release
Type/Severity
Security Advisory: Important
Topic
Red Hat OpenShift distributed tracing platform (Tempo) 3.10.2 has been released
Description
This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides security improvements.
Breaking changes:
- None
Deprecations:
- None
Technology Preview features:
- None
Enhancements:
- None
Bug fixes:
- Punycode labels are no longer processed incorrectly: Before this update, the golang.org/x/net/idna package incorrectly processed certain Punycode labels during internationalized domain name conversion. As a consequence, an attacker could craft a domain name that resolved to a different host than the one that was validated, which could lead to privilege escalation. With this update, Punycode labels are processed correctly. As a result, converted domain names match the validated input. For more information, see https://access.redhat.com/security/cve/cve-2026-39821.
- The os.Root type no longer follows symbolic links outside of its root: Before this update, the Go os package did not correctly restrict some operations performed through an os.Root value. As a consequence, an attacker who controlled a symbolic link inside the root directory could traverse outside of it and access files elsewhere on the file system. With this update, operations on an os.Root value are correctly confined to the root directory. As a result, symbolic links can no longer be used to escape the root. For more information, see https://access.redhat.com/security/cve/cve-2026-39822.
- The ungetwc function no longer mishandles specific wide character encodings: Before this update, the ungetwc function in the GNU C Library mishandled certain wide character encodings. As a consequence, an application could disclose information or terminate unexpectedly. With this update, the wide character encodings are handled correctly. As a result, the affected applications no longer disclose information or crash. For more information, see https://access.redhat.com/security/cve/cve-2026-5928.
- TSIG record processing no longer writes outside the allocated buffer: Before this update, the DNS resolver in the GNU C Library did not correctly validate buffer boundaries when it processed TSIG records. As a consequence, a crafted TSIG record could trigger an out-of-bounds write and cause memory corruption. With this update, the buffer boundaries are validated correctly. As a result, TSIG record processing no longer writes outside the allocated buffer. For more information, see https://access.redhat.com/security/cve/cve-2026-5435.
- Crafted DNS responses no longer cause a crash or an uninitialized memory read: Before this update, the DNS resolver in the GNU C Library did not correctly handle malformed responses. As a consequence, a crafted DNS response could cause an application to read uninitialized memory or terminate unexpectedly. With this update, malformed responses are handled correctly. As a result, the affected applications no longer crash or read uninitialized memory. For more information, see https://access.redhat.com/security/cve/cve-2026-6238.
Known issues:
- None
Solution
For details on how to apply this update, refer to:
Affected Products
- Red Hat OpenShift distributed tracing
Fixes
(none)amd64
| registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:40c77256530f670a5951bb76fd98780b04756f5bc533c885dcd227a0155ad303 |
| registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:28219c674953a66c96fe7db3c684c26829a295f3ba1ded42f739124c2da040ba |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:10a722d4a344473cbcf8c808800328d4f7ebed295defeb5c415e17e0398b0b5b |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:ddb66284889add51287b8d61052bd00d8a0ef516fbc0829a2a4b4b99bdeba5fc |
| registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:0ff040679a174fa9d9d23042349d5071dae8c7e7091dccce4c6ee2123a69ae35 |
| registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:4043b1f73650dae9fbaa0f68eb50930011763abeab0f123f04a2c849fd413023 |
| registry.redhat.io/rhosdt/tempo-rhel9@sha256:bc2a9f9b0174d8bb70d6ce582c197bf2c397f0b9be70df5d32cdecbc352665a4 |
arm64
| registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:90d32605a91f99e3bf54577014cb33bc19afb96f6f3e47b8b00cd5e2628512f3 |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:b911ca02d5b6503b37854c840be1cd1abb08a66160ab5a5a7a9d0d77881739ca |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5d37a9295fcff51eae08cfda93f8fd9150ed8481bf65a71744ad5535b861225d |
| registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:fefa59c75182e18ec20e3efe5acd1456e113c36e3347fae4fe457d5bde7761f1 |
| registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:50d6dd1edf4bf2cbf4cc03946d0ea3db17b5a7b72b8ff827a0be7a0981403c4d |
| registry.redhat.io/rhosdt/tempo-rhel9@sha256:cdf828754abcd22e000f52ecabc500ac632cc2a46280332f49ebf8fd4e479387 |
ppc64le
| registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:52c3188a11918718364db6dd46fb1b9cfcdd06bb83e6262b874368a5d9c3242d |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:390785f43baa818e969bc4deff6734ef30cbabb442acf0c40af205caece7b3cd |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:ebb47074d9e7e06f56284253edaefb60ed4bf5efc1c3cecf9f4c49edeaf3a209 |
| registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:948718d12957aca408a173259fda1151e30644d6423eeed740ea21d7f7bb2262 |
| registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:8e2efa2a279952d22dba9703d08ea887121a969b045923764063a10f167a3412 |
| registry.redhat.io/rhosdt/tempo-rhel9@sha256:d95e74f5a3c907455a884c5a0c23bdf668e4a8dcea44c124bf8c862daf6237f9 |
s390x
| registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:0df194c5cb39115f89e8df733e39d94ea12c834fa9e8a29198a8a5cdb84553e0 |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6818877323264424695b25c3353b506b659424d07f55f128a3add92c32ca9747 |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:faf4ba531c623ea0d19755b77f2138dbaa43a51a0775b4ee02d1225316dc654c |
| registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:d1ecde6e98b112a31d78156b1df2490eb4529e46f52b3a5253680c8ad0ce0e6a |
| registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:2ba02d10898f9d23098f89fdcc873ca2902159d598077a8a793cde6924ea0ea2 |
| registry.redhat.io/rhosdt/tempo-rhel9@sha256:1fd5fdd5a09d85f2cce8ab19726e68606af7a45012bfc0a7a9f8aa9af2cee255 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.