Red Hat Security Advisory: OpenShift Container Platform 4.18.36 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2026-22797 — keystonemiddleware: OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers
🎯 Affected products198
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:34cc8ad01ba89008f6df06d07d210e6e001b3cfda445127a9388740c542507d7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:49f1fe7ba5b54de47c0572c9b07dffdc83d26bcb179a5514dea0ebfc040d583c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bd8feffb01445307436ea73374d881d66b58bac66d0340a6011a16e20319baf6_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c0eb1d8711e6715dfd268a59c6b09035ec34d450bc3e6976a69fdc2d42eaddd3_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-exporter-rhel9@sha256:4bff8e6c2036c475175b402d239dddd1a7ba3f60ac6651ea3f6667707741bc9d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-exporter-rhel9@sha256:69b424286ed4e80a126a9217186e629d52c676c5ea1260111d78b10c40e73f2c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-exporter-rhel9@sha256:801f8700ff29e49647adbdd757a301b779b2846f95e30056e8e194458fe5f273_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-exporter-rhel9@sha256:a5262731aa0163ff87456fdd63c5b9c65ad9e583a212173c58ee71238a1705bf_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-extractor-rhel9@sha256:109053e224bf641a2293c1796bfea1a321ef7c2d856f2308eb6fc73554344b7e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-extractor-rhel9@sha256:12521bfd441d9b3db4d86a4f0d1c2818064ecc152bb9d78cfdad35652f173703_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-extractor-rhel9@sha256:9d8822302599359ffcaec951198ea2d2caf3527a0f4d8f59ed8f66c971193207_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-extractor-rhel9@sha256:a7e6c4bfaf4dba2a1b47fa8463b1a70f3f1cac016eb586937318e739bd22ee13_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:123267516e01068997318df62a2bf764579c0ef2cbae0bf2670b2fdac77150ec_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:be8895a8c39b5934ca537b0395b4abe3ed5bccceb9e64fc6ce4e238dd1bde148_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:d2e4f1ca958dfe68cb6a9525582973b58fd0e3f17b13b9985bd0731758436951_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:fd3e60bc24de6ec4065fa463ab0b47680a335de84c7689e1b5d3f513e258eb20_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:068de0f11e334773d0fca9d269b128b571f89e5ab97586de75324814fd5c6278_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:5a3945e350248697a15a6c76fe1ce18a6bccf75c671431a007011e0382f3c0ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:6eb891b890138f876ac4a8f5bfdd286512c9a8840702406189e122dd8bf27347_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:aa74cc9c7c0905c6771b8ae6dc4bc2da32858806f1429e522386621abc51bd10_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:53e8497893e6f46bd7ad043ff6bfae1cbfe6c4c07fad1f885a36f4be795e721a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:f0dceee9fe9848ddfa0df9bec4d3d893fd0b358da42f8c7102b2c37c542540ec_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel9-operator@sha256:0a000512658f155e80ec0b035579f74a3253d53912f43bf9440ef8fa7bad2d85_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel9-operator@sha256:1a519196155e2b7a81d5bc098c5bacac53753fe20de6472cd7181943c39e3da9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel9@sha256:39f7c7176125c49d751b48b42dd9dbd62a4a315e40994a02a747a46db8cc860a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel9@sha256:46b9c8e94d1d368c96b958a65d5dac7e0c3f97bafe29e0777d516c428bf4249f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel9-operator@sha256:3de0436153d1716bcd562a5418bf3cc0d8d968ab916f90ae6e0365b9359f23aa_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel9-operator@sha256:b79947b0015b88a5e6b09d99d6f5026d868ca2c810bb7be21832362a62918f84_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel9@sha256:b7a0b21d56bdaa50d96bfcef2bea8cdcfbefd8ea57ab6cfc70d2f6a6d22b8e6b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- +168 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7486ca2ec3bce0ee41dd2c03d75e120b6f660929ea50240463937ae1c4b118f7 (For s390x architecture) The image digest is sha256:907e10c7c312b21ba21efa0bf9610da3d69a97173eefba4510699a86c27b4b1d (For ppc64le architecture) The image digest is sha256:d08e99e6ab216fda7fc09188df598ebedb315b49680d6490e9df0b42ab4d5e0a (For aarch64 architecture) The image digest is sha256:9e1da5b54dab49265e57f7e95a7c912f2ad0d32dc6b013def90cb045fd1510b3 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:5133
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/cve/CVE-2026-22797
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5133.json