Red Hat Security Advisory: OpenShift Container Platform 4.16.64 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-1784 — ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35172 — github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4f89e916f1566d11a5ff7b264151f3aea6cc925516393f533bd86a6f5fdbe041_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5be328a131be1ec78e0b3989a5d2362f65c79261fad26eddb1c121525f241972_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e607e539e5a9f0fa981449034513ae8a2e35e0fe6902906c4323a33cc9096385_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ea7da904a8488ed2a83ba7e898d18a849906c31c3830f9f8ab5c16927a441430_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3d28584601d98981f8a53f2416972a705a097cb685215d9d1fa176a99b6f10f8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:45177d65d7245c5493591f835bccd7dae7b385fda7946c09709125ce5cc9ac77_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5782c0ca95cabfa28226f4024159c3be509916cb72707f7b08ff21de53a94fd1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c2d9559b5bde056c303ebedc9eebad0c51e846ddfe3bf7f0b4f2ec10aecc11a3_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:249486d7063e28987398f36144b63be7fc41f73316409b608ff0e52a113244b1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ab5a90137c5983e547d121da59fe3eb44068c832e084a39e85ca2c130ba7d9a9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bed843d9b83c75df42ee6192e1eadec3c8d4479539cbebb74d38a3de3328b836_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d99a4551794ab99503e6ba88a3f35ae99c163e6ff5a5fcefb11e3b127ae42790_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5418a90638dd6218926ac533880453302338c469f0629b67f018bbf62bfefabb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6e4213e7aab2ebc2b7117ae2633908aba929399ec47d50c347d5c1ba9a784509_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dcff3a566484624264aee0d4d27758e2e24cee98562ba6cb0f73dfd13f19ec15_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e3bb70dc060c4de6883c231962ee172430371a5e779bffd79786c3f7a30b6414_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4bc3a60afbfc20e981040f351e4951a245f5ec2e4a7db4dd4ed8bfcb8ea88a61_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9624f08393403f7b6c65f755bd4be36eda4cdacfb78365ad2beb6061d83b5cd1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f481b8731608abb2d2a1afcb6ada4e5b47860742bbc4a729d46bb01ea27a8258_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f7f0e338ac3bf7364a1f2f450a123a2bbd033985832f588e9c8bb779a98468e5_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5aaf888d66b114f00e5cad1ee30c0328cdee0a205169bf1828b52b5c71b6ea86_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6631596c7b3aea7a0d7e2622186a18cf30db9164b0681a95957d9839e0f9f04f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:7def3bc3c8c49766507845f7b7b958013d50677c02b0f3fe077a845fdc017c87_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a949718df83bfe9eb7f09374d4804c8dc2b560a307fdd73f6912a0204b4ead0d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:27c89e9bf4a8a45a82ea5f912e2fcba5b5b9459a4dad3cd335bf6ef32fae28f6_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:51c9bb1cdfe28bc2dd34c516812bfca1b8243d0093692f43ab5da558fc3b6ca7_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:8ce9b27334d78ce3225d847f2d82b2bb42333d4280c96fd44b63359937fc31e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:e5980c74656c38bec2fc6c7d9ffaedfa4a1b9af36990011c756b4bf4688eac62_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:021afeb5e6b4b441dc0d41dfaeb7f45cfaba4a336a0d274fb89814065945c839_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:ad8022623b6accc6c6d27fb415027c7f2b61d9a118e4e402f6492ee613bd340c (For s390x architecture) The image digest is sha256:f191592af6e6308f387d91b00bba04e4b1b398bb261bd2223b00c9e153d81b24 (For ppc64le architecture) The image digest is sha256:6562cc1250b96eaafdabba0d6618d9962574a794fa47f2630a02963a8543c842 (For aarch64 architecture) The image digest is sha256:4f7e3ee3145158e72bd4b4997232756e6f476c23ce2fc0469d43e8f717a401ee All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:25045
- externalhttps://access.redhat.com/security/cve/CVE-2026-1784
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35172
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25045.json