RHSA-2025%3A19961
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhacm2/multicluster-operators-channel-rhel9@sha256:e53d09785f1417554adef6952e32638c0ece003228e125d4a0dc4f9bb59ee979_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/multicluster-operators-channel-rhel9@sha256:e53d09785f1417554adef6952e32638c0ece003228e125d4a0dc4f9bb59ee979_amd64 |
| Red Hat | registry.redhat.io/rhacm2/cert-policy-controller-rhel9@sha256:39b29d526fa7db7f866c0649f0e473cca3572c9bbec967cf64f97378e60602c2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/cert-policy-controller-rhel9@sha256:39b29d526fa7db7f866c0649f0e473cca3572c9bbec967cf64f97378e60602c2_arm64, * |
| Red Hat | registry.redhat.io/rhacm2/console-rhel9@sha256:c6ca869945e799980dd5ce97b3c4074c3919382937aa4e055e973033b9e70fc7_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, * |
| Red Hat | registry.redhat.io/rhacm2/thanos-receive-controller-rhel9@sha256:518f33d781f4594435770e0d15c47942bd95eae6d20880ed717ceaf17ae33b73_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, * |
| Red Hat | registry.redhat.io/rhacm2/thanos-receive-controller-rhel9@sha256:d98fdddf628e39fb19ba481eab8bb5d1338d959cc7b2b383abbe97deaae17b64_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, * |
| Red Hat | registry.redhat.io/rhacm2/kube-rbac-proxy-rhel9@sha256:4e7c86685a1e0171a5f78d0b23026f0354e37146885123bdef0e0f83d7ad42a7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, * |
| Red Hat | registry.redhat.io/rhacm2/thanos-rhel9@sha256:b0519b7c6f231ee7786277f028d966079dcacf4f985c5fa988f1dcafc8a87895_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/thanos-rhel9@sha256:b0519b7c6f231ee7786277f028d966079dcacf4f985c5fa988f1dcafc8a87895_s390x, * |
| Red Hat | registry.redhat.io/rhacm2/insights-metrics-rhel9@sha256:7d18b501ee306e88e226169e51bca0fe7efaf68f08a5f7ca2d55ed3bcae596c7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/insights-metrics-rhel9@sha256:7d18b501ee306e88e226169e51bca0fe7efaf68f08a5f7ca2d55ed3bcae596c7_arm64, * |
| Red Hat | registry.redhat.io/rhacm2/metrics-collector-rhel9@sha256:dd35887ebaa1c609ff4f580368594f60a375359547cee4bd327028739cc69038_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/metrics-collector-rhel9@sha256:dd35887ebaa1c609ff4f580368594f60a375359547cee4bd327028739cc69038_amd64, * |
| Red Hat | registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:607c3a286a39915e0c34fe9d14fb474013c40369bb9505cdd45fc87c4f946905_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:607c3a286a39915e0c34fe9d14fb474013c40369bb9505cdd45fc87c4f946905_s390x |
| Red Hat | registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:f63bf240d195ee88063630dc28cc8e980fdaab7c74390bcd9a84cc459097d96d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:f63bf240d195ee88063630dc28cc8e980fdaab7c74390bcd9a84cc459097d96d_arm64, * |
| Red Hat | registry.redhat.io/rhacm2/search-collector-rhel9@sha256:e898528a081c0b4e48e681295e1b9553ae011cd16e78213a8ac055dce0702139_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/search-collector-rhel9@sha256:e898528a081c0b4e48e681295e1b9553ae011cd16e78213a8ac055dce0702139_s390x, * |
| Red Hat | registry.redhat.io/rhacm2/multicluster-observability-rhel9-operator@sha256:289757ac1d2f8807f9358de5abac8c99ea0eb1d61cc5150eb611dc7ff3ad3351_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/multicluster-observability-rhel9-operator@sha256:289757ac1d2f8807f9358de5abac8c99ea0eb1d61cc5150eb611dc7ff3ad3351_s390x |
| Red Hat | registry.redhat.io/rhacm2/observatorium-rhel9@sha256:b1f5557c91ae17664972762ba5ffe7629423d27ca7a590fb0bfbbe63b53d3857_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/observatorium-rhel9@sha256:b1f5557c91ae17664972762ba5ffe7629423d27ca7a590fb0bfbbe63b53d3857_arm64 |
| Red Hat | registry.redhat.io/rhacm2/acm-search-v2-rhel9@sha256:aba275fe96698bbd9a5f49e897b3d9a708cd49cd0a95ff75fac2189c9d89385c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/acm-search-v2-rhel9@sha256:aba275fe96698bbd9a5f49e897b3d9a708cd49cd0a95ff75fac2189c9d89385c_s390x |
| Red Hat | registry.redhat.io/rhacm2/multicluster-operators-channel-rhel9@sha256:38019d9ba07f59515345dddcd1800da3408be06b3620f4b1c1dd2034e939d26b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/multicluster-operators-channel-rhel9@sha256:38019d9ba07f59515345dddcd1800da3408be06b3620f4b1c1dd2034e939d26b_s390x, * |
| Red Hat | registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:87da30613e1af8c2d3f6591ccdb1d34ab7827b63aef4d9f951af4604815b16a6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:87da30613e1af8c2d3f6591ccdb1d34ab7827b63aef4d9f951af4604815b16a6_amd64 |
| Red Hat | registry.redhat.io/rhacm2/search-collector-rhel9@sha256:74e44163da33f17d65b620f751ff3c9e5003c48e5c657f0097badf32cef500ad_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | registry.redhat.io/rhacm2/search-collector-rhel9@sha256:74e44163da33f17d65b620f751ff3c9e5003c48e5c657f0097badf32cef500ad_ppc64le, * |
| Red Hat | registry.redhat.io/rhacm2/config-policy-controller-rhel9@sha256:f06ae673c94ed152c38fe83a1cfcbf3c7da157acc27d327c702b95bf108431a1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 | *, registry.redhat.io/rhacm2/config-policy-controller-rhel9@sha256:f06ae673c94ed152c38fe83a1cfcbf3c7da157acc27d327c702b95bf108431a1_ppc64le |
…and 158 more
Timeline
- Nov 10, 2025 CVE Published
- May 7, 2026 Distribution Patch
- May 7, 2026 Distribution Patch
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
- Jul 26, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:19961 advisory
- https://access.redhat.com/security/cve/CVE-2025-47907 advisory
- https://access.redhat.com/security/cve/CVE-2025-53547 advisory
- https://access.redhat.com/security/cve/CVE-2025-58754 advisory
- https://access.redhat.com/security/cve/CVE-2025-7195 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_19961.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2376300 issue
- https://www.cve.org/CVERecord?id=CVE-2025-7195 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7195 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2387083 issue
- https://www.cve.org/CVERecord?id=CVE-2025-47907 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-47907 advisory
- https://go.dev/cl/693735 advisory
- https://go.dev/issue/74831 advisory
- https://groups.google.com/g/golang-announce/c/x5MKroML2yM advisory
- https://pkg.go.dev/vuln/GO-2025-3849 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2378905 issue
- https://www.cve.org/CVERecord?id=CVE-2025-53547 advisory
…and 10 more