RHSA-2025:3439: Important: ACS 4.6 enhancement and security update
Important: ACS 4.6 enhancement and security update
Other sources
This release of RHACS 4.6.4 includes security and bug fixes. If you areusing an earlier version of RHACS 4.6, you are advised to upgrade to thispatch release 4.6.4.Bugs fixed: Fixed an issue where Scanner V4 performed TLS validation even for integrations where TLS validation was disabled. Fixed an issue that prevented the "Container CPU Limit" field from being added to security policy rules. Fixed an issue where the Network Policies tab in the network graph detail view would hang in the PatternFly Code editor due to a potential issue with the Monaco-based text editor. Security issues fixed: CVE-2025-27144: Flaw in Go JOSE versions prior to 4.0.5. CVE-2025-22868: Flaw in Golang in the token parsing component. CVE-2025-22869: Flaw in golang.org/x/crypto Secure Shell (SSH) file transfer implementation. For more details about the security issue(s), including the impact, a CVSSscore, and other related information, refer to the CVE page(s) listed inthe References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3439?
The severity of RHSA-2025:3439 is classified as Important.
How do I fix RHSA-2025:3439?
To fix RHSA-2025:3439, upgrade to the patched release version 4.6.4 of Red Hat Advanced Cluster Security.
What products are affected by RHSA-2025:3439?
The affected products include various versions of Red Hat Advanced Cluster Security for Kubernetes.
What enhancements are included in RHSA-2025:3439?
RHSA-2025:3439 includes enhancements and security fixes for the ACS 4.6 release.
Are there any bugs fixed in RHSA-2025:3439?
Yes, RHSA-2025:3439 fixes specific issues including performance problems related to Scanner V4.