Red Hat Security Advisory: OpenShift Container Platform 4.21.17 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-41674 — xmldom: xmldom: Arbitrary XML markup injection
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:316fc1dfac61cc8292d94a44605519126e05e2148a44e8167bf35b78d2e3b58c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:702cdc4d5e9371f2450b8c3af7966a65f09ce3cfb89b0f5530cb032975c7be6f_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:71afe8c9691ee703ac13b0890907f33c75a228b59c814d6b82f2a65a1e47ade4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7e30a211d2b97a8c1bec6f223dce23f02811dc4bab89a5e3e036c65dce3c8313_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6701bb1a62f5ddb5d9c5719efadac413447e4080f36ec50248483f08db51be24_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8043922795aca65bf3e5c32a717e7f362ba912930155e9545b76b78115f7e8c4_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:addf898100293b11d05f3906a75ac36cf4ad33c60760ac55b19a3a89bc828eed_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d89474019a15e0eaa3e057b8d73f34e1e096282a95c67d40391100a9ae6f6d60_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:445de521ad8809eef126683d257edf8feaddf7782ca1fd3d3bda9b357c5e2dbe_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4e179141321360637a43edbb388dc600f56c675d444b531d29fad7b6549ea516_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9ed796cb5314cd8a6a3266394c77549e294a6694d665752e64f86d562de62bc1_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c9e601b1c191fba1e7d2337a2da76274c49c641e881e379453840d7d0e7a8287_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0eb1179715e1b8470c17ff9d69bb500eb5b3f77fa97c8c220859e591db72bc1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:74bd9e1539a761d29ed5df02b7045c1ad1ff40e566199c1f089abf41251925e7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:aa1b79ef23693be43e989f5984a71e5ac944b44077eeddaedb52b76b7a0de451_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d5362e5e028a474505be37ac9a28f93c02f56f3070c4b7bf2dc5067f0ccf4f29_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8634e5311f2796018e9404eb1c65e31a08bde957b8315bb0f2255172ce824bb6_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9b32f48921eb270a0d200f29cd017c30b458e7858b50e51b2bfc66c9242dbc81_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:cd7ddd671959d818f7feecbbf9195d0a6deaf3fe82aff4d3528132c885585922_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f598da04fe75a5c432552fef71d07776a179f5c166152962aba1c7010bba09f4_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:02b7b21ed1f82d9ed22215d78600b368103c59e374ffd6b15dc8250c379c8f70_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:cdb3e6984a5562271dc082c6aeeb96034c4d6322f014ba1d88d10c4c7b7a6af0_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f0eb5b2d683f328d91690623964225dfd1ea42e367fa389dcaf2c8b149416b07_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ff528a5aca2e50b4779c9b7f0f7279fdb166227d0e3bddb1876d53c560a77390_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4131c6a8b2dc8f2bf670b26cbb98e0d41bd7074ddf22c3c975040c1efab4a883_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:940f740fe8306858ce236c60385b0fab6b427ed5db401aacd84c8519ee0541a3_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e616683ea75f1f5125589328e1796e5bd199b1c74e97d02b06eeaea56551642e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:edea191c7f44b154eb08b021fa17b8465e6e8aca4997378b04278b3989ec1c82_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:58f1fc8f8d012ed720a41dc7774502f575b2e9aa7d858d4e079f87cd9ec1d440_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:52a9c863ddc434eedee8c0e75cf610805db2b6b91502688857bc8afa62ed1dd6 (For s390x architecture) The image digest is sha256:e1cd4053fdab99ef5530074cb61596de6d0c3b0fd091763051e93b69b4a47c11 (For ppc64le architecture) The image digest is sha256:91b0028f1b17269e79f04e6638777c378fa6b4f0814f9b7ed26a0ee2cd0d3427 (For aarch64 architecture) The image digest is sha256:370ca00b9618fe7e6a2444f68e63a869f2c4f3cd51f0e61e35b66dd87dda8652 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:20034
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-41674
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20034.json