RHSA-2026:4434HighCVSS 9.9

Red Hat Security Advisory: OpenShift Container Platform 4.19.26 bug fix and security update

Published
March 18, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2026-22797 — keystonemiddleware: OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:6ee70216b40fb9fa1629f4817d4e93a212501d31ee5339691739d355a02f9aaa_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ac4eaa2f7cf735b89c7b0a23d968d23b99e398fbf7ec2ce8e2cdcc43578869a5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c31e5a4e0300d5a9444f73bab9f815f5fc43d23929276fe85c932dcfb6f82e78_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e9ff9a3483e6c2c8dd5b06a811642bb690c0be1923c0de4eae673e4795f9c82f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:036bb662ae8841d8f9acc6249419daf627851a5ce8ae77a7c6fca5bd105803de_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:635678ec182eb7a020db41f19589a274de803ed784c5dcf97706a544c0c6e0da_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7766520aa3449089e4e7d0f0d2f30e3b534554f326110cbf5f7091f166047c36_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fa71e884c77fac849de0115db4714cb40e2d8ff8761cb08d5be1c0ce66e5471a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:17c2481a853506f3bb684449b7a130c5197f03630331acb7b802cc5f4e11dc90_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4ebb88ead342a5da74477a57146644b24f506842cd8646fb75e9ef54088047a3_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:951a527a979735c4f4cd3b1eedf736f674b49fd084d97fb1737284ca8804ed7b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f197822b0f5b6bf90f93c0d33a301539e80db2af758620177355245dcbf41c73_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1bbd7695543959300a17f41db29a172eede3215e3c08461aad11fccd82fdbe3b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2c6352bbfb2656b1d7441171ff85896dfa605187281c54a88a85cd6e01cc2713_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5452dfdc650a21170fb5e05eff1631e49e850f47cbc4afdd226fcc85754b2b0d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a453937482c1a6a1b3dd94efc41cd6e2a1a539be09c94c629c635e353029da40_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0e2e02a676f896ab365127eb7431ecee5df387be053e1548b711420c7e98bb3a_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2d330ca9b15037bdad73a52a9b66ccc93a99f1c7bbdcaec7bdd9c7ce27432599_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a13438f2806152ec0430d13675f3dc6bed876fdc97028718b78967f1d8910eea_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ce452a2fd4172799f487422945ca64515b76ab5b94467f4b328ae3c942cf677d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:12b30025b8ede14292c24d02fe94aebd86003c15fadb90c775bca866a0ca8650_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4e6db5dc165d5b8a373646dfad510d9a8cf4b102609d342a0be2a9d18e876e80_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e432a5d98c81d605288321746caef5c981df09d45e51f2ad8095fa3430762e55_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e8a34ef59a6cf062b031f1a53a6259f10c0cb1d142c73a5f23a936f2d4ad35a4_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0e665ceb51607bf11d41907d8c896df596042ebab5deef3d64b22d279275a422_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1f14a36c4774ca253f055688819449538483e76ab6471b5e60dd6fa4e481095d_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3d5d0aa941d40e32550b6e0d3db9109e3e302f970d4877227852756e779950d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b1673d8431d34eaaaee0881ff0dd91f2b393d8ac3e3767d97f8ac40640ba250d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:15b63bf9bc990dfd770048ece2a4ac1f2ebb949d9c169d032de2ae3a449dbd7a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:64d312cc715ccb58e44b7ed0a7a1a24ad407b72be2cb865512f9bf8ff7578524 (For s390x architecture) The image digest is sha256:d597607d81ec8146b6403a37d48605c34c0649cffdd5b9a532936d71e7c02d81 (For ppc64le architecture) The image digest is sha256:ce22c81cb59efaad506ed4c0222611d8ed603a597cca876e1ab87f4ff94523da (For aarch64 architecture) The image digest is sha256:d09f3caab920c99068212112676f4a8c2e7f3ee72f69d69ead2ec90e8918213b All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (12)