Red Hat Security Advisory: OpenShift Container Platform 4.18.43 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:00dbbd309cec902c4d16c80fc0ca3e903a43aefd0e0e9455169682fef52153c3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6f3b29cb3f4b1befcf3dc0976cc1f634e411886b964e5d1743bbd265fa946c99_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ac5e790d66350db62fe054ce1c1091d10a35bad5fd81327fea4d80fa91fe80cb_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:edbe4fdb0bdced2c9795b9dd20dc59f4a8b6fffef33a0a9a852cf69ab5381e3b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6430412d4963f6a614844ec54f60130ba5520a69a07cfc4eb208f76c0ea36c2a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c5824d23f4f118885cce18cbcf6132209956abd2f38ba8cd48d4de0fe5105ab1_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d26fd89dbb2bdf450f30f616798203a69b92f20967d3034e1f9056079044d898_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d71fa80be1a2b6912d8541c560b54d64d09eee17edec5e310956b841feea2d9d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1635a173f7ab23d91e3150b2b27281ba9d13cbc7b80375f2d21790ac439ad9bc_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1a4e1a2cc959755263ae9adae81b0877af80196f01de84a4659ae0e465afa30f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b515dda885892f12e14e1a442ccf4fe2d9386d59f8efbd31d3a1bacff3be563d_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f178bbb0a5e86fe869f8f1ae858c407d249a54c3fed6b90c41c84dab108361f6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:48f715b8b704774e56ded9b4be2fb8c5c7791dd946f5bcf4c409f04884cd5c27_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:594a1fac3cea32c3c92b010dbac4cf20ac0c94932288cb12b414bf4e52f240df_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:95edf7ac3e36d57faf08b5bb634d00ce9b87b10b4132a130a301e2cdb41e2182_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:96e98a75060c99a8e3e97550647a3315560789da726aace89a4b109b2b3185a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:131006cf6201069a826237fefcdafda4041dcf5c003fc8588e81cd9ebcda82af_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7c6209994b381d6f5b189d7b5b0a74f3478f74cefce0777b67e3516029d390d5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a775ad8f6c588d41b715fc7ebd8583c51c12afddc91c9fcbc0d205dd19727c58_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f3377ea4ec953d264615bf763fed6deff6bd23a8ea68f345146172afbcda3947_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:442bad27a52a10688cdc7d57c3ebe79266e61e171bb52bf3b867b954e3ac9935_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5c74fb391430a0e96e24412b2936e66d117f1314320989158f6ede73d8433d70_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:79bb57d9bf99cfd31d79cdd4aa3d618178f83257dbea98bc004af933b97f2580_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b2dc6315b37a8d8665d2fb3797ae49df279f88ad2650799bacb79ab685b388eb_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1123bd5d873f32ff23ee39f8a6f3f74d29ba7b89ad231005c1190666e257f194_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:8c232660842bb14dc43a5cfebf4d8056c575f49150b05354455b39c42c157f23_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a463ee137cfdac297a6873105bf80f4b37c4e7b5194826f1acee218e261bc9fb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:ff0169b8b8b2cd42fc9e1016be984ed673d580b4bad4d005ecb471cfbb2cbda1_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:0ab2ffa80eee4b67bd19b29ca7f3de8c087b99efab968ce752ed7384850733fa_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:27eafee2d15ebe7d66cf14aeefbb79f91512669ecee1facf3ee5f06019dca651 (For s390x architecture) The image digest is sha256:928917977895d721b3355e93031ae9da26e0e34f4f4fa1aee5723a22ab98432d (For ppc64le architecture) The image digest is sha256:12d6af49e535ddf1a786f40c18e2bc195ca21602cfdd37552fcdb762c6d00922 (For aarch64 architecture) The image digest is sha256:d84590b666012baf94ad1dd3216779f5e851da6571702b2440b9071a5d1e9f55 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:21657
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27143
- externalhttps://access.redhat.com/security/cve/CVE-2026-27144
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_21657.json