Bug 2530044 (CVE-2026-87053)

Summary: CVE-2026-87053 operator-sdk-builder: operator-sdk-builder: Final container image runs as root (USER root never reverted)
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gbenhaim, niyer, twaugh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in operator-sdk-builder. Due to an oversight in the Containerfile configuration, the final built container image runs with root privileges by default. This increases the attack surface of the container, as any process executed within it will have elevated permissions. If a malicious actor compromises the container, they could leverage these root privileges to perform unauthorized actions, potentially leading to a broader system compromise.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-08 19:05:05 UTC
## Final container image runs as root (USER root never reverted)

**Component:** operator-sdk-builder

The Containerfile switches to root for the dnf install layer but never reverts to a non-root user before the image's ENTRYPOINT, so the final built image runs as root by default.

### Remediation
After the dnf install layer, add `USER 1001` (or `USER default`) to revert to the go-toolset non-root user before ENTRYPOINT. If specific tasks genuinely require root, set that in the consuming Tekton Task securityContext rather than baking it into the image.

---
*Source: Ex-Wing/Glasswing Konflux CI security assessment (Mythos), finding FIND-001*