Red Hat Security Advisory: OpenShift Container Platform 4.15.64 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products160
- Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/frr-rhel9@sha256:2e92bc3a93834a5a2f8c4105e9a85092d2d62a43372446ae32664981e6418e96_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/frr-rhel9@sha256:5949180eb6b3eeeefcc1867a4327e4bf33e0da58f2cddca7473e64ed32fe5d80_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/frr-rhel9@sha256:baf01464f82738b2136246766cec84873c616abaa1bcc1cf277c9c1eb6b5a098_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/frr-rhel9@sha256:ff63c932ed1b193132e9496820d3b6ad469a81f9479c698666fb2c3bf14c6752_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:579e5b4a5b037a6d41e57c0bdd6ac8a00c768456c850fbd9c8007adad9500f81_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:9bb4a0883febeb4fc364d151d0c698bd33143cfc86da84782a68cad3aab4ab76_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d06946df9ff9d46bc81ced4be0b3ab0ba9ecbfc33d0ccc7d66dcabc541877968_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d75d7412c513795e89c52bab5c67c261fd9d666e429e22692a2bcbe45b3d72b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:39c74de4408b0c0ad5f3fc79869d2b981c768ddfcd5f286b83b8c21dd8a17754_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3a3e7802b06bd038d59d7199551d5e8022447faf99b3b492838c8d165cc2b0cc_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:51831cdc6ef63fda135cd70c4bc62c156a0b7ca74ef1362fb185d1724561aa6f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:aab9c8ef47d1e7fd1aa22add79a054d2a346447696d1e06a4863718ea2b727c6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:04011b9eea7e7988b749d665621fe501736194983cf3facbc18c9a73f3c330ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1c47d5c709920c8b6244653b5fbdd0599361736b433b0560bef3c3688c3e2851_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c657d513655a23fdfa62b43ea6768ce771e976739253e3d5be57747fa90c280b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:dc8c92fbd78f110a5fdd544001993967053f119cbd2256a64a5396b20f630a79_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:11afd173704d838825ff151117d2e85048e8a2856e2a87c21709f3ec960f0e8f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8c85fcb5287624eef169bede14a31b89cbeb2ec25587817fedb0b5205276c5c5_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:99e1a652d2d18b51cb02d5d81bbb12a1e8328b7d617146b50d37baabdd6e1a99_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b1be9ba6af51d85b040041f13c509139720292f14a4ef55a7f8afd9a2c509558_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9@sha256:74a51ca2fa5e9c57b3e0ae0168c27ef1960b10815a2259f016b28a31163eb745_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9@sha256:9125aaa715545b7b06b6bddfb5950351c152fed3b898e5eeb0b2800aae1a6195_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9@sha256:d3a1439e156a7a9c27a6671d9b3ffcd8e452ce557a5fe62a434cb79e3b8eb780_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/metallb-rhel9@sha256:d9178d1b74a01a795033c9b27c4968fdbaa3fb68308e7785194e71e90ab69a59_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:30959a0b6e29bde29ff879254360319f7faa88ebca5065aad5a530d587938697_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:9446713fc061e233bfd83d7df83a3dc4021e55f3f754496946a20f8db9ed6038_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:ab97bb213c9039e268509f770178bf7d6d1671bb5d4d4baaf11fd41997cdebdd_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:ccd8eced21e470b77b70fdccc3bdf8aef1c65e62dffc9339efa3423404eb52a7_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/ose-ansible-operator@sha256:297219d164f3c8020cf557c7bd079f8128d537b83985c43407514a7c91d4c557_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- +130 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.