- Issued:
- 2026-09-15
- Updated:
- 2026-09-15
RHSA-2026:67707 - Security Advisory
Synopsis
OpenShift Compliance Operator bug fix and enhancement update
Type/Severity
Security Advisory: Important
Topic
An updated OpenShift Compliance Operator image that fixes various bugs and adds new
enhancements is now available for the Red Hat OpenShift Enterprise 4 catalog.
Description
The OpenShift Compliance Operator v1.10.0 is now available.
See the documentation for bug fix information:
Solution
Before applying this update, make sure all previously released errata relevant to your
system have been applied. For details on how to apply this update, refer to:
Affected Products
- OpenShift Compliance Operator
Fixes
- CMP-4716 - Bump Compliance Operator Go toolchain to fix stdlib CVEs (net/url, encoding/xml, net/http, html/template, crypto/tls, encoding/asn1)
- CMP-4609 - Contradicting statement Compliance RULE ,about permissions set to 0644
- CMP-4601 - Operator HTTPS metrics endpoint stays dead when it starts before service-ca mints the serving cert
- CMP-4571 - [CO] Switch Compliance Operator base image to ubi9-minimal-pqc
- CMP-4493 - Add NetworkPolicy for Operands for CO
- CMP-4424 - CIS Red Hat OpenShift Virtualization Benchmark v1.0.0 rule content
- CMP-4341 - Investigate kubelet configuration rule remediations for RHCOS10
- CMP-3922 - Broken link for rule "route ip whitelist"
- CMP-3730 - banner_etc_issue has hardcoded remediation
- CMP-3618 - "rhcos4-moderate" remediation leads to "chrony-wait.service" timeouts
CVEs
amd64
| registry.redhat.io/compliance/openshift-compliance-operator-bundle@sha256:d570f559988ff9ac6dae93191593d32fe72350c9e869ae72c0d9e27d2cdb66c5 |
| registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:15aa0b19576a5045db03943b5212b06f181bb4a0398470f5030ca98c7ba4f27e |
| registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:2f577b5c99d6c61f81c51f88913288fc78390464f4cc1c2478a3456a37a064fd |
| registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:8d9902d42dcc03b52af80c7d3be127a6c24a49abae8cc7c2f571e529720ed00a |
| registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:f90c82b9df6dd6d65928f84fbfed6011b0b280c9be2bcdbb7bb733af30cb6caf |
arm64
| registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:ca2ad51304a75e4a235ea4f94faf09e6a1ec0c932b074f2a66f81229baa4f33c |
| registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:9c412cee0b734047e96cdf1908bccca25c5185c82552c5105ad6d46f096284fa |
| registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:6ce9872ca6f32df3b3a2fa7dcb7dde39e7ae0a298c1a33eb7dfccc262772021c |
| registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:f8173db83313879cca3221df85fdae8b564f3dd576519bb1a518034773a5539a |
ppc64le
| registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:44098da4bf9006975f2c97c8191c97c6d2bf708a8f4049dcc8168651879fa10b |
| registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:101bc16f3e3821ffcad3a55c86105e47568ec6e90d78119f1f36bd89f8b44c01 |
| registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:d18a06409ed1f8d2e2a93b0dd3c0a9d510da9c32af4c0714c9a8cd26ff590abd |
| registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:982e0adb427850c290bf89e63fc58da7d93c35c100b867bdbafdd2a310374f30 |
s390x
| registry.redhat.io/compliance/openshift-compliance-content-rhel8@sha256:f8c4171a4dd77dccf5f0299c2a9d162cf71bd00d5846765437b2d393bc6f8d74 |
| registry.redhat.io/compliance/openshift-compliance-must-gather-rhel8@sha256:4f50a235e45f4082c45619abf3299249f9ae70bb9d7dc0aa8d2f02c4883428da |
| registry.redhat.io/compliance/openshift-compliance-openscap-rhel8@sha256:19e1853d054a81bb13c970f9e4a2785bf55beb9ed96018d3ab1dcd7da78603c5 |
| registry.redhat.io/compliance/openshift-compliance-rhel8-operator@sha256:85b246016bbab0f0bf5b6fc001b576071a53ed011a5edc40a63ad941ff34707c |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.