Red Hat Security Advisory: OpenShift Container Platform 4.20.16 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-22797 — keystonemiddleware: OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:53b47cc5cad449bb388468486726593c6f5f0a20e23b035c2bdbe283d77fdc16_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5e268fb9530fc6ea702bfe64e5ad3864f40d9c0e3beeb2581fe2a8229e191336_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9414bd27ae196de5d952d6689530d09632bc529ea73e29ab09a2a9e8aaed601e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b1ca3d740fe69d29817827b9b5475172b8cfe21546b59c99c82cb1c61d19844f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:879e40240f8a9e6f323bf40d226586f5ecfdb91bfdeb0a2126dfaa67c3e3fd85_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9b4085029ca2e11663e7adfeee36a9f5783ce7106521fe02a99132be4bf4d9a9_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:acbd8e36fbcccc23f3fbc2013321c793d724592e637988ddc1b0d81b0a538ffd_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f51d6640749d0b80892428c7eb2b54e1e75fc69311ce456c425afac40caec745_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2e7fcd6eaae5d8e35155b811ad6fe4cc9934b31a0076e80df6d409b11ca8d226_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:828ac94fecfe5b6e8263621a62187f070f9e3cf2668d24f00620ca47b29c37c2_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b152b96f3e1c5e6ea18ee532c4f747ac0e0bcf082c1bc0fd8ba60aaf7d914ba9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c5f8bb01174a32ba07070a5488b2fb27ca7820508491914337a6433d4766f039_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1e024a95761866be7a23ddcd5fd0dbbabbda249218d36ba9cf51d561575009fd_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4a5cb39ccce3520bbbd2bb98b84df278724e9084cf7abe9f100963b05f6a51a8_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7b3dac83c616876919f2bed7ef7318dce0f20bd12bcb6cf754814233f19710e3_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b466e339cfa61e214e09f1b47171616d59dc1748b8e02a096d74d0975b955c5a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1675f4cf4337e6ee6f4b0506017f95e48775b58ae80b02f24d2d6cf4b24e0897_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7b91722c7e9d1fda1994adeb21ebd50726d916378b50b942cd2a6bb636d98a4c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a4f190f8c7699860fef711a4ea52e922d840b0ae7f7b99f431d29be088e16b12_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c72327fe63c1e302e35dbb0fdf46787529e6583c544a20c0c7507fec8a9916f9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:148d1267925de54e2ff67cc04f7e1eea48e4812881eb13a6d4ac84fc9edf3960_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4728a45a6f0d6184637de454fa23aa87fdab1ad388c0f82dc97a63780d848148_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7ed045e8c4ffd8421d54d6a4ff9ee3b8af00169d184f39fafdcbe689429e9a94_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ee8ef9b71b81d64e1c95c28aa12093098c55dbb4a970f16237aee5cfa1f1756d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:11ba356bc22603fdc9da30ce02a56e0841715ffa1be1533e409f680525e35a95_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:313103a205fe81020b9acec854f03b3c35de728e2a8ee7f8b778eefcff1e9adc_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:48ed707b531cc589ab67cc34196bd107b85250edf3619a3c348c45dfc6f535a4_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b7e689a159a17e702266acb3e5d7487f9ce17eed2c1f5166948103010747f2db_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:377373ba5a37f2fc8fa27875afb5ab500820c68e660b1cab11cb52ad14541577_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5e2fb7977a82237e497443e2bb53fd1c196e083fc5095294699399b61ce02746 (For s390x architecture) The image digest is sha256:dfc309cca8f14d497793502deace618448e55a97686b49793034a16e014a5843 (For ppc64le architecture) The image digest is sha256:097c91d50e665781b82929c57911fff13b453d1ef3ee1759d84a0ce88da8e03b (For aarch64 architecture) The image digest is sha256:665bd6fff9282786782e17b6b70520e798087d06eaa840e0bb37e2ed3a9ac59e All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:3855
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61731
- externalhttps://access.redhat.com/security/cve/CVE-2025-61732
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-22797
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3855.json