RHSA-2026:20089HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.63 security and extras update

Published
May 29, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products194

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:17d522d1a82e16b31a5d94e20276f73168b32fe2517078b5d24e8bade3ceac09_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:1c104c742cad5bc09a773242059a0a2162f93481857849b2f0af9bc304a94e27_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:1fcf108ef02e921cb14c513152fbd685dbd33329b13eca8f2fceba6716f680ea_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:fd690fa8299e6a2b1c9c5998735ef21b17e83794440fb333f5f9563089c9e74f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:43b011906c41e9bf8f64019b8a582db2041e979c02aa8c9ec53cb10dbeb8e3d0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:767ac36bba35613627b4159756a40c167b2fb854a6aa8df6ed69f8e4049d32ab_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ac93fd6f9633987cac920a0181e1828037662c5aec15f286b744e4407f0d0f6f_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b01919d732c9d8212a264dcaa635963a3ce98c02aa83d3b53428548ffc243003_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1f1f9c9bed26b494d14cfab25c3fbf6c89923957ed69aa41f3b900d32ced46c6_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3a7eb932e6b8ea7b130b0dd87cef47791aff8e72f92f7a8892c5097c9fb44ca0_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:74139172b8ff102e15e958b513cf3a3042a5ada588994eff4955ad490ab38fdd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:bfa3acc4caf549a61a27f2ec4d6be167013061c4c7d9cefe8213c0e8fbd88823_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:1fee714672bc4213506fa55f1d1aaf08e76390a78e468276ce7f0a9c9fe90ffe_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4bd3922a3442149105ac3f5ab123fa3825b26c397830370a6c23a8cf2b554c4c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ae78f482825f17bc2b7d39583a39b2379281ad20d8e4134dbb029b66e91e70fa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d27ec4ad982879fceeb3ec43fcbf67014c9f8ae1be1831895e22080d823a9c58_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:1e01ed6ab0f3a1e92b99b541060eff37c6f1aa95cfc9fdd1d04f56be078dea72_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:332ebe93e5964ba221f27b5b9e00a329ba9dec2af2fb96795f357aa5825943de_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:3507a44159bcf1674d698e67241f09bdd405b1805acdf696301d4629f57e81f4_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:8af05e04e3e4b8a37289e2e3166ba6ddd25f80c39675a93f3a0946a5de149191_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:94ada4115b7cd77fdcc9252fbb71484c451fd453cecd47425c77c7f66563eff0_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9b7f63d0857691e1d9b6cecc6af6f6f0f31cf6dd0fb4d52c7890d625d80f0cc7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d69f959401e008a9aa7d25d81f1fdf7ddaaf79a0848725a4574961b2549a78fc_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:e0a9ac091796dea4cce0538ae9cb40ad2a9d127ef788de8e175fb25a1482a187_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:12e5769722f41cfff3ec88000d157eafee309fe3e7262beb93ee1a26eca26740_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:1c6a5800804b48577101016f1972e5d640d83f4b4662c1c598e3f02ebbdb6451_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:46764b222709391567a6a6f98b47f2d24f8f392ee50e12b839387e516930d5ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:deaa89b74d371ecac06996ffef15fd30e750cac8aa5cfdc6ae47e8dfb39b551b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:605e0e18037a05d24edf8f8f1da2d240a57e18e833c008019d0f50592f4e3cca_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • +164 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (7)