RHSA-2025%3A19335
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:b7bfd21a3a383f631488e0cc979ea9969dc3cd6f2db10960f524e37b058dfd5c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:b7bfd21a3a383f631488e0cc979ea9969dc3cd6f2db10960f524e37b058dfd5c_amd64 |
| Red Hat | registry.redhat.io/rhacm2/thanos-receive-controller-rhel9@sha256:e41d647fc468bb3f44bad88b4656b33e557427beb0191b0fcdc5f1f0df66c07b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/thanos-receive-controller-rhel9@sha256:e41d647fc468bb3f44bad88b4656b33e557427beb0191b0fcdc5f1f0df66c07b_ppc64le, * |
| Red Hat | registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:646a6afc52c83362e32549a0ec09ff4d0677a239ec2b58a82e4374ee3b38053b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, * |
| Red Hat | registry.redhat.io/rhacm2/prometheus-rhel9@sha256:a1896f5f7d19945fe045b3f148c1802fa05bf6cb2d029d57a6ad618984f9b213_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/prometheus-rhel9@sha256:a1896f5f7d19945fe045b3f148c1802fa05bf6cb2d029d57a6ad618984f9b213_s390x, * |
| Red Hat | registry.redhat.io/rhacm2/endpoint-monitoring-rhel9-operator@sha256:5c3b02c97bc9d3383b69157f98c8e9091905973af181692a11caf414ca366331_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/endpoint-monitoring-rhel9-operator@sha256:5c3b02c97bc9d3383b69157f98c8e9091905973af181692a11caf414ca366331_amd64 |
| Red Hat | registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:05847c2e995e681bdcc3f809e76f512767f40ac4498c14fad4afb4cae83f33d1_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:05847c2e995e681bdcc3f809e76f512767f40ac4498c14fad4afb4cae83f33d1_arm64 |
| Red Hat | registry.redhat.io/rhacm2/cert-policy-controller-rhel9@sha256:fee7a4ef5d73d6e81e0b913a0c15ed8254f138ba8115fae8c3819a2cc6144fdc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, * |
| Red Hat | registry.redhat.io/rhacm2/endpoint-monitoring-rhel9-operator@sha256:3fd793aaa8b22670c9a863613bd20e1fbbd946b8a15bc684bb952364d98a0c28_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, * |
| Red Hat | registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:d90541f7b7746118a800776cfe26ccfffb99862bdcda46b4ddabb1669d22f7cf_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:d90541f7b7746118a800776cfe26ccfffb99862bdcda46b4ddabb1669d22f7cf_amd64 |
| Red Hat | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:feffbb2c5cd8b8edb0944e5d1c49bb49aeb902bb6f44343a7e882c060efaa108_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:feffbb2c5cd8b8edb0944e5d1c49bb49aeb902bb6f44343a7e882c060efaa108_arm64, * |
| Red Hat | registry.redhat.io/rhacm2/thanos-rhel9@sha256:231f3779db0ac8489f4d0333b176b2dff83eda3778573e1f990eafcf18317bd6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/thanos-rhel9@sha256:231f3779db0ac8489f4d0333b176b2dff83eda3778573e1f990eafcf18317bd6_arm64 |
| Red Hat | registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:f534b88cb3db85b58b6f48ef64c433c673d422bf41d09fd303ffb5d7091a3b34_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:f534b88cb3db85b58b6f48ef64c433c673d422bf41d09fd303ffb5d7091a3b34_amd64 |
| Red Hat | registry.redhat.io/rhacm2/insights-client-rhel9@sha256:d978057f781d3ef887909cab4211f892017e76de317f3d2f17cd6314ec883939_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, * |
| Red Hat | registry.redhat.io/rhacm2/console-rhel9@sha256:86c711091d0a954427d4dcd667cee8feda6dbc6fa2616de9f3316750b04c27e7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/console-rhel9@sha256:86c711091d0a954427d4dcd667cee8feda6dbc6fa2616de9f3316750b04c27e7_arm64 |
| Red Hat | registry.redhat.io/rhacm2/acm-search-v2-rhel9@sha256:5f225c8b7cec9c965cdfefdfcc34371b1dbd3a39d1e6a74f121ef9feffcb4f11_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/acm-search-v2-rhel9@sha256:5f225c8b7cec9c965cdfefdfcc34371b1dbd3a39d1e6a74f121ef9feffcb4f11_amd64, * |
| Red Hat | registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:fdd3dc61d0214588fdfdc0260cd75c395e02615bc73633d84184dee02effe404_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:fdd3dc61d0214588fdfdc0260cd75c395e02615bc73633d84184dee02effe404_s390x |
| Red Hat | registry.redhat.io/rhacm2/acm-siteconfig-rhel9@sha256:1740b9e687e829ddc242fa400cf496ce94bdd875de8e9a83589f540231770016_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/acm-siteconfig-rhel9@sha256:1740b9e687e829ddc242fa400cf496ce94bdd875de8e9a83589f540231770016_arm64 |
| Red Hat | registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6b34944da4fcf630306c6bef503b659b7ed578faf0f5b5e3c0bf2938b1f18247_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6b34944da4fcf630306c6bef503b659b7ed578faf0f5b5e3c0bf2938b1f18247_ppc64le, * |
| Red Hat | registry.redhat.io/rhacm2/config-policy-controller-rhel9@sha256:e951334f9a85760ad85e96695e35ff045ea274ca0203a96ef7394d4905379325_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, * |
| Red Hat | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:0ee74288b19b217b917a4719d08bd1ddead9fdc90bac9f9868b8d721e12a8576_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:0ee74288b19b217b917a4719d08bd1ddead9fdc90bac9f9868b8d721e12a8576_s390x |
…and 157 more
Timeline
- Oct 30, 2025 CVE Published
- May 7, 2026 Distribution Patch
- May 7, 2026 Distribution Patch
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- Jul 26, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:19335 advisory
- https://access.redhat.com/security/cve/CVE-2025-47907 advisory
- https://access.redhat.com/security/cve/CVE-2025-53547 advisory
- https://access.redhat.com/security/cve/CVE-2025-58754 advisory
- https://access.redhat.com/security/cve/CVE-2025-7195 advisory
- https://access.redhat.com/security/cve/CVE-2025-7783 advisory
- https://access.redhat.com/security/cve/CVE-2025-9287 advisory
- https://access.redhat.com/security/cve/CVE-2025-9288 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_19335.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2376300 issue
- https://www.cve.org/CVERecord?id=CVE-2025-7195 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7195 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2381959 issue
- https://www.cve.org/CVERecord?id=CVE-2025-7783 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7783 advisory
- https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d8d0fd0 advisory
- https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2389932 issue
…and 28 more