RHSA-2026:17449HighCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.18.42 security and extras update

Published
May 20, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products37

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:112b9bfb652715915016d89e87b2e18512f70397a01dd97c7dee842f47406691_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1c26fe2d637af61b0ae3659094002b34638f479ae8ed4b206f8042a72243b743_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:471d16a66025c08233be6d357cd4dad5fc4ed2dc2a9b44c70cb3d31f2079a775_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:7f2613af9de4ddcfee3e0e2fb2b8ed582a0c76ad9b4bef45fc7f4ba81c959393_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9352f6dd61c87088d2cd424d69ee861c77809311b9776142025fc70b5d3e6e6e_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d8620fea16a31192af6ec38435ecdd90b5e4f65403812f34f3f3041edc4d2052_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e7741a8fe04ec6a0f3983a4910732969fb42b5d749099269a08c97384c32507b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f347fcb1d73cdbe471c057606c966d61b916e88c0beab5d033c4a189eb9c1597_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:26bdcf0d92b6359c6370b240aef6aa0f6ea5c3daee63b40f9cd156daa206f723_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:63c359be316faaf8fc53a6096767a9db4b167b9dfdd2f3f90d7b682db9ca101a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ce93d9f6e35e585055c6c50791657ed16a515549972a9426833aa26e0518f5d2_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eae0748bdf7caf6513a668c0d28d0a8a29bec7d122fa6c2f39ff1c9ab5d05772_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:7cd96e78530cfbfeb787d75c079e26bf6195cc98ecfedefb735dda3f043d8d29_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:a3998bd36675ca4c793448426c7887e95954f667d170fea12c998b850313c127_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:0154160ced0c0de1c57beab8e82576314e403e9ef811ac444a7bd83705b5bd51_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:0aa2466ebbaa3d030135fdf5aa377c9e6c1fc023322f7cd2e28299fa875ad74b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:375400574275e237d2f391a9c6f0bfe3479d18b02c5cebc30b4a20725bc71d19_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:7bd5bee84c08ce7cc18733e44bcf697c533ebb67eb90a991b0f3dc4fc2af1acc_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:3303b011dcb878e2165e92b3b71b1839e4ea3af1697250653ddc18bafb2ea039_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:4441cec5cf072fd128cc399aa959d69eca4806468b79d6ac8191934fa3f8e773_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:a43248e0dd8815db87a4ebc56c693d4766ad2afe4b6b37b57bb10659997c3b08_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:b8eb3e481eb73dbd36591becedfa31f732a3de32807af82a840f5cda9416f474_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:06bbff002a3e1730447b1c039b8b7658c6bd133e64d9e80bee18bc5a13c27465_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:4c6615389b809e0c5e97c718180e1cb26114809b40b21f8418f6492ac2ed6cec_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:5bbdbae11350d7a5aae8407dd9b9751abd8bdeee0327797b28d6cde9d0549668_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:ea83152d42e616fb7bbf0cdebbce0360c70a4de261d841e0e4ec897266eca77d_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:04173570c570318c693f9545061be72c39cf6f7b42ba62d0527a9faeb80ae858_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:d3b3288633257e3e0cb31313c97254c51396518a68cbeab8f34615db5a2aa464_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:e17d381e2b5d4ba7a306d2edf0d74afe78dffb646f1ef54be71146df41458c94_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • +7 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (4)