- Issued:
- 2026-09-08
- Updated:
- 2026-09-08
RHSA-2026:64827 - Security Advisory
Synopsis
Red Hat Multiarch Tuning 1.3.4
Type/Severity
Security Advisory: Important
Topic
The 1.3.4 release of the Red Hat Multiarch Tuning Operator. For more details, see product documentation in the references section.
Description
Enhancements:
- With this update, MTO has been updated to use go version 1.26.7.
Bug Fixes:
- Previously, deleting a ClusterPodPlacementConfig object immediately after creation could leave the object stuck with a deletion timestamp and finalizer, and operand resources could remain. With this update, the Operator reads the current object state so deletion is processed correctly. (MULTIARCH-6269)
- Previously, the enoexec-event-daemon DaemonSet could fail to start because its ServiceAccount image pull secret was not yet available. With this update, the Operator waits until the ServiceAccount pull secret is provisioned before creating the DaemonSet. (MULTIARCH-6270)
- Previously, OLM CSV lifecycle cycling could prevent the Operator from reaching a stable installed state and block ClusterPodPlacementConfig finalizer processing. With this update, the Operator converges after installation and can process ClusterPodPlacementConfig deletion. (MULTIARCH-6271)
Security Fixes:
- Previously, the Operator and pod placement controller ServiceAccounts had cluster-wide permission to read Secrets. With this update, Secret access is limited to the permissions required for image inspection. (MULTIARCH-6187)
- Previously, the Operator ServiceAccount could create, update, or delete any MutatingWebhookConfiguration. With this update, update, patch, and delete permissions are restricted to the webhook configuration that the Operator manages. (MULTIARCH-6188)
- Previously, the Operator ServiceAccount had unscoped write access to ClusterRoles, ClusterRoleBindings, Roles, and RoleBindings. With this update, those write permissions are restricted to the operand resources that the Operator manages. (MULTIARCH-6189)
- Previously, the pod-placement-controller used hostPath mounts that could create directories on the node. With this update, the /etc/containers/ hostPath mount requires the directory to already exist and does not create it. (MULTIARCH-6191)
- Previously, the image-architecture cache used a hash that was not collision-resistant. With this update, the cache key uses a collision-resistant hash. (MULTIARCH-6193)
- Previously, architecture strings and error messages from container registries were written to pod labels, annotations, and events without validation. With this update, architecture values are validated against supported architectures, and error messages are truncated before they are written to pod metadata. (MULTIARCH-6194)
CVEs:
- CVE-2026-33818
- CVE-2026-56853
- CVE-2026-56860
- CVE-2026-56862
Solution
The Multiarch Tuning Operator optimizes workload management within multi-architecture clusters and in single-architecture clusters transitioning to multi-architecture environments.
This Operator is available in the Red Hat Operators catalog that is included with OpenShift Container Platform.
For more details, see product documentation in the references section.
Affected Products
- Red Hat Multiarch Tuning
Fixes
- MULTIARCH-6271 - OLM CSV lifecycle cycling on OCP 4.16 prevents operator convergence and blocks CPPC finalizer processing
- MULTIARCH-6270 - enoexec-event-daemon DaemonSet fails to start in kustomize deployments due to ServiceAccount pull secret race condition
References
- https://access.redhat.com/security/updates/classification/
- https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/postinstallation_configuration/configuring-multi-architecture-compute-machines-on-an-openshift-cluster#multiarch-tuning-operator
- https://github.com/openshift/openshift-docs/blob/main/post_installation_configuration/configuring-multi-arch-compute-machines/multi-arch-tuning-operator-release-notes.adoc
- https://github.com/openshift/openshift-docs/blob/main/post_installation_configuration/configuring-multi-arch-compute-machines/multiarch-tuning-operator.adoc
- https://github.com/outrigger-project/multiarch-tuning-operator
amd64
| registry.redhat.io/multiarch-tuning/multiarch-tuning-operator-bundle@sha256:4cc2057423f38c28d4b911bddec4d6007209de9cf0d0fa9d05e7ae43036be56b |
| registry.redhat.io/multiarch-tuning/multiarch-tuning-rhel9-operator@sha256:1970fae2f0b8243d4221e233b408f3c343768486eb307a23ade943a82fa86109 |
arm64
| registry.redhat.io/multiarch-tuning/multiarch-tuning-rhel9-operator@sha256:581de0bdc552094a1fba83b1490b62b2673c614ff0fc9a27ccbc31dcb110ccfd |
ppc64le
| registry.redhat.io/multiarch-tuning/multiarch-tuning-rhel9-operator@sha256:db99fc186cb2fe399b3efd7c069a967a2d1cb69f32a083f2e2e50db4601cd128 |
s390x
| registry.redhat.io/multiarch-tuning/multiarch-tuning-rhel9-operator@sha256:159fb5e1dfc27cbafc776f591a5e93b51b60d79e4d66ea7b662d383934c2d101 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.