Red Hat Security Advisory: OpenShift Container Platform 4.20.25 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-1784 — ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3cc8af76a34d2744241372da99f99aaed094ab834012b0f9d02d792e72980529_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5a1f13a9a3edb3b54c67416d67f95f081c3dc75afbb979a6d9f8a29d86edae8f_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:72d1c53957ea07656681edd6da3b9a8c892b7c066727cbf6863d49cba166cd11_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9d35fca883a52887fab497b7ec34639d7554d0f65d8212c2040aa4932f49c686_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:94a6c83950055e8e6d334fb574ad9d26014b92f38a14cf9d14e5aca4514b6999_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9d761a4fe1c43b790b3cbd84fecf2fa633060bd365ef77edc1b48a74b7867f26_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b8701132ee8a7dc4641f23cdab3238951c90c592717c6230a5b03e5d1339c526_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e29931c28d6ee43ce049d127f7ed6ddcce31c808f168be3431ea5dc5993d7d5b_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:400e13750c8398c3a89351770396f89bd15efb059ed66ff80422e32275dd7c50_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:82f3c0fd5254590794c6fddf14d315dc78afd1bdce962fc697a99bdc579a3d5a_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cdc85493d3656b76494ef07c494a7546f3ba369250ab0924ebc46c4e9dc74fcf_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d507bf78a84574b0a05bc844d069855c3a827e29962ac63abe077642c5c36b43_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0a29515ee2aa03916cccde9d22d2aa1cac84ca41bb2d9f606ad8509d607e6407_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:35d1c1456675b78ec1236f01c04700efa8fc0c6c42cb01673379a745d4b19de0_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:41aae64dd70ac812324792ba15cccbc292fc5f48a5d78cd9a8fa465582b0dfb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:816bbaa3be315d63a9faa59567cdcdb639f7d515bd1065e8ef5f01b21f7a1c29_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4e4a50b140c9d7c056f152ad24245abba6ca247824c779da6d765bf84e394815_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:72ec7062a6b2c66866ff7c00c0fb87217001435dc08f36e9f7c49bc9d737133c_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a4eb05b2c7a38cd7c76d1e546a0bc5672abcf0c417b0f37bacbf809217fc37b0_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e561ba7bad57ae3524b1f15d9e08dca3ee56580cb8b941e7e20c3fa8e864038c_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:24701bc5a9a6db92fdf4f0e12bd5fff8de217e155fc7afb31f641cf2cc95d4a3_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:42cc8319381e9be602455f45f0671354cb21b7f09a7888926ba1046b1b78dc1a_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:66252add6250845724abf0139a5c48799e54655e62e045cff5e9494ef6529bfd_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:bff29c061bfb1257fe5c491e3e1b79cfd6778687b599b3a5a59070855009222f_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0db75e89241ad5b4846fb2d75e49f52a76ad9009e7c4589c8637b7e6a8eb354b_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:459e942ee31f991b1ea9f586026d7a7fca9fe7e3f705fb3bd12602383ea286b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cc5a005982a5540e666de29589266fb6a714c2e218aff134fc9e7b2611f9a198_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:eb66227be61cb6c279302c3f7f3f98dd48de13ae7951473436bda28ac7d3338a_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:96ab2c42ed76936ad280b478d30e884e935268f6959b718666f6da31f6cd917e_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:490002f6d1363683178f4b9999f52602588f3cb75a9267a190fdfdee06e2db7a (For s390x architecture) The image digest is sha256:4b17edb77f71d8f32fab03e233a63b13eae84de232535a3386b44c9bf2dbb95b (For ppc64le architecture) The image digest is sha256:9154fd7ab04d202ecb43304419e5974acad03f16a9c5b61f52f8841dd310269d (For aarch64 architecture) The image digest is sha256:ce5d55048f0cbbe54394a24c37e54435e1c5032252eee4dfaa1d684fe00f7cd4 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:25194
- externalhttps://access.redhat.com/security/cve/CVE-2026-1784
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25194.json