Red Hat Security Advisory: OpenShift Container Platform 4.14.68 bug fix and security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-1784 — ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35172 — github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:0b18d8e32ab150cbd44167ada0fac93220ec1b317cd1f14c558626b937fbdf88_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:0fc2dba94d1016e038e2c956be293bf7ce1b36ce33a6909b7140273376a240b0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:15ce08a73f571387245cef97b7e129b030c9d5ab74cc5f8c12e8594199ee876d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:5922bd1eb86ce77c784a2711be5b5ea6b64edd0f225091c17e147c090005e0ec_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:35e217c8600a1ea8c6ab65441a94ca84de2f9c8b5911752725c1eaf767964a60_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:564a3c384ed0d18196478cdf1393745b104d659cead801b47e95fb9831b53d50_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:647a47e09f9d767eea7b1cd2187a985bfdd9ea0067230b7392b35fe88025279c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ac7819e848aeae9dba4a69da03e7e86f624a4c6236f04c68772af74de5255c8e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:58909e954a52ba226e4a74265cf50ddf7dab153a46572478867c1ae7448c5c60_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:a75606335fdd8c4f7e6c984d1900abe561cf4d76960ac92c7325272febb4527c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:e0a1038d90d900f1bcdf110cd749af4a76aa86da15bb748f060425246bf32278_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:fe1e0a072cd3d2d5525061e4f441ed8f2a20848f1ae9d5b0ef570bc5626c9da1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:0fb3a9bfabe49bdefa595d284ad4757b2aa859f95d695ff152e2be82477c93b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:2316e14fa515bc4814f32a66b4544a0001ede863bbd3275ca2735023eefd2f65_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:430bbeb7953b706671f9503b2c68a41c3b5377b03a485ac74f579a42bcdb3e36_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:91bcad450f1aeb0cfaef5f88dac0fc835d280f746f4c102a93efba21730f2a2e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:7d271c8066a6bfcda94cd96d57c46c0eef4e2b9404fe25c4dee4ed0ca986bc55_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:8cba4ea3728b92ad166837d1190dc5db35e5fdd48ced36770c0239cb7fe0d1d0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:bb91ad11225aa7a3bbfbaf0c28b7a201df4eb7109e132300360357a6887e53a1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:d8e8f842d22db29d0b7adbfc4bf59c88b1cb0235d2c41dfdf05bb79bb932f07a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:1268aea3d7ab5c15c1fd0b95903935d0e292316ddc3fbafce8efcab523ce9521_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:5ace1a3a379c1758da632c47afdb76f8d7c16f9b6682ed2e32b5408f3c4ee586_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:b5c668a6ba45737746354837aa4515a23c26578e969d1efb5849040cbd0f801f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:f39f5807d4beb3bc3c8f63ba68b31bcac2fe8e807bd9ccf862b0086efaeadac5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:2ecbcd51c285c4a52c8ed069dac61ee838a39c25b25467371ac0157b2bb705a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:aa58d837b628928430e04c53d769becc53a89e17482f068e2c313a8b8142ccbd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:bce35b42adf0275f5964a7838de9993de6e325f549ef432103252905786218a6_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:e1359958edc312c897abdba577e06f67dac6a31048475e6ebb792acdc9205d90_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:570841fbed6519fdbbcef96bfd2bcc5f15f99db574a12a1674be412634e40ffb_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e042266bfafccf3f8f6afe39da6b9b91738fa836ba5159fa485e7eede34aefe3 (For s390x architecture) The image digest is sha256:8d95bf587d1e567ee1d8f0635da6dcc6f458d8de115bf7fff93719ea008d4f20 (For ppc64le architecture) The image digest is sha256:e5f2c65060d18b90639543de234f78356cefa2d77a8d4dbbaa00675171e7a2cd (For aarch64 architecture) The image digest is sha256:027ef407502543950504fd28ac3e4258594b52444fd471610bcc3da9656e816e All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:28893
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-1784
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27143
- externalhttps://access.redhat.com/security/cve/CVE-2026-27144
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35172
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_28893.json