Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:44624 - Security Advisory
Issued:
2026-07-23
Updated:
2026-07-23

RHSA-2026:44624 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift distributed tracing platform (Tempo) 3.10.2 release

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift distributed tracing platform (Tempo) 3.10.2 has been released

Description

This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides security improvements.

Breaking changes:

  • None

Deprecations:

  • None

Technology Preview features:

  • None

Enhancements:

  • None

Bug fixes:

  • Punycode labels are no longer processed incorrectly: Before this update, the golang.org/x/net/idna package incorrectly processed certain Punycode labels during internationalized domain name conversion. As a consequence, an attacker could craft a domain name that resolved to a different host than the one that was validated, which could lead to privilege escalation. With this update, Punycode labels are processed correctly. As a result, converted domain names match the validated input. For more information, see https://access.redhat.com/security/cve/cve-2026-39821.
  • The os.Root type no longer follows symbolic links outside of its root: Before this update, the Go os package did not correctly restrict some operations performed through an os.Root value. As a consequence, an attacker who controlled a symbolic link inside the root directory could traverse outside of it and access files elsewhere on the file system. With this update, operations on an os.Root value are correctly confined to the root directory. As a result, symbolic links can no longer be used to escape the root. For more information, see https://access.redhat.com/security/cve/cve-2026-39822.
  • The ungetwc function no longer mishandles specific wide character encodings: Before this update, the ungetwc function in the GNU C Library mishandled certain wide character encodings. As a consequence, an application could disclose information or terminate unexpectedly. With this update, the wide character encodings are handled correctly. As a result, the affected applications no longer disclose information or crash. For more information, see https://access.redhat.com/security/cve/cve-2026-5928.
  • TSIG record processing no longer writes outside the allocated buffer: Before this update, the DNS resolver in the GNU C Library did not correctly validate buffer boundaries when it processed TSIG records. As a consequence, a crafted TSIG record could trigger an out-of-bounds write and cause memory corruption. With this update, the buffer boundaries are validated correctly. As a result, TSIG record processing no longer writes outside the allocated buffer. For more information, see https://access.redhat.com/security/cve/cve-2026-5435.
  • Crafted DNS responses no longer cause a crash or an uninitialized memory read: Before this update, the DNS resolver in the GNU C Library did not correctly handle malformed responses. As a consequence, a crafted DNS response could cause an application to read uninitialized memory or terminate unexpectedly. With this update, malformed responses are handled correctly. As a result, the affected applications no longer crash or read uninitialized memory. For more information, see https://access.redhat.com/security/cve/cve-2026-6238.

Known issues:

  • None

Solution

For details on how to apply this update, refer to:

https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators

Affected Products

  • Red Hat OpenShift distributed tracing

Fixes

(none)

CVEs

  • CVE-2026-39821
  • CVE-2026-39822
  • CVE-2026-5435
  • CVE-2026-5928
  • CVE-2026-6238

References

  • https://access.redhat.com/security/updates/classification/
  • https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/distributed_tracing/distributed-tracing-platform-tempo

amd64

registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:40c77256530f670a5951bb76fd98780b04756f5bc533c885dcd227a0155ad303
registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:28219c674953a66c96fe7db3c684c26829a295f3ba1ded42f739124c2da040ba
registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:10a722d4a344473cbcf8c808800328d4f7ebed295defeb5c415e17e0398b0b5b
registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:ddb66284889add51287b8d61052bd00d8a0ef516fbc0829a2a4b4b99bdeba5fc
registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:0ff040679a174fa9d9d23042349d5071dae8c7e7091dccce4c6ee2123a69ae35
registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:4043b1f73650dae9fbaa0f68eb50930011763abeab0f123f04a2c849fd413023
registry.redhat.io/rhosdt/tempo-rhel9@sha256:bc2a9f9b0174d8bb70d6ce582c197bf2c397f0b9be70df5d32cdecbc352665a4

arm64

registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:90d32605a91f99e3bf54577014cb33bc19afb96f6f3e47b8b00cd5e2628512f3
registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:b911ca02d5b6503b37854c840be1cd1abb08a66160ab5a5a7a9d0d77881739ca
registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5d37a9295fcff51eae08cfda93f8fd9150ed8481bf65a71744ad5535b861225d
registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:fefa59c75182e18ec20e3efe5acd1456e113c36e3347fae4fe457d5bde7761f1
registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:50d6dd1edf4bf2cbf4cc03946d0ea3db17b5a7b72b8ff827a0be7a0981403c4d
registry.redhat.io/rhosdt/tempo-rhel9@sha256:cdf828754abcd22e000f52ecabc500ac632cc2a46280332f49ebf8fd4e479387

ppc64le

registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:52c3188a11918718364db6dd46fb1b9cfcdd06bb83e6262b874368a5d9c3242d
registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:390785f43baa818e969bc4deff6734ef30cbabb442acf0c40af205caece7b3cd
registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:ebb47074d9e7e06f56284253edaefb60ed4bf5efc1c3cecf9f4c49edeaf3a209
registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:948718d12957aca408a173259fda1151e30644d6423eeed740ea21d7f7bb2262
registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:8e2efa2a279952d22dba9703d08ea887121a969b045923764063a10f167a3412
registry.redhat.io/rhosdt/tempo-rhel9@sha256:d95e74f5a3c907455a884c5a0c23bdf668e4a8dcea44c124bf8c862daf6237f9

s390x

registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:0df194c5cb39115f89e8df733e39d94ea12c834fa9e8a29198a8a5cdb84553e0
registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6818877323264424695b25c3353b506b659424d07f55f128a3add92c32ca9747
registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:faf4ba531c623ea0d19755b77f2138dbaa43a51a0775b4ee02d1225316dc654c
registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:d1ecde6e98b112a31d78156b1df2490eb4529e46f52b3a5253680c8ad0ce0e6a
registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:2ba02d10898f9d23098f89fdcc873ca2902159d598077a8a793cde6924ea0ea2
registry.redhat.io/rhosdt/tempo-rhel9@sha256:1fd5fdd5a09d85f2cce8ab19726e68606af7a45012bfc0a7a9f8aa9af2cee255

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility