Red Hat Security Advisory: OpenShift Container Platform 4.21.16 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products66
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4ab083b5f6807ff483da1da8558808beadb785ab8716fa4c72e1648b8ccc5b08_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4b5be0fe4c266d9cb9fec524f080b4e943eaaab975a75932bdf057cfa351e7ec_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a7894d3c00da71769ad80b1c1b7cf118fef354d85dbc80c6a136daf744d03837_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e8e1512345c3190b39f4ee2b696069174bfe68e1ab29846666f7d9af49b4b0c8_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0dcec8ef82fdb64117b817a7e61ff01d9a39dc3c67783aed266d4a466ff84d81_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:1a3fb3273e15923e10c501450387b1eadcadd020d75a5773bc6932df3b15c3a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2fa26ecd87d0bd6df1531db4484eec462704e941d5a39e00d2edc5924ae64b21_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:523f22a66224ba7c8cef228bef27d636e69cc946360a9d752147b07ec993b3c3_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3dc9b9bb0fa20101ee45f1c64f54f8ae46b481b1a734568da2453a946982b274_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:52d4e5b09f1558e8a9fa05397ef1ac7ab97eee0348db25774f4bb7e02257db8b_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b0af149ffe653cd25f0fd05da45a6fd41d55c097b8d607e671bb85ecdb081dae_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f78a36784ea6369b3f8a20d7e114f26fbcf261a9d03e0b26ac0e00b5a2d68b6c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:12068ac89f6d2ebee4c7324782348eeb48e30d94479bd3b6a5971e0bdc330b1b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:8fd2a36e86e007f3fa99a911f97f2bfb15c1a514640e1c3a05c025a43d2ead9b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:b7037e3dbbb1d9a038395af84764459e4d1ea707367fb7df85e1d552e50050ff_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:d042d76a54588563b61b2e2500ad6c6f355f2841072723dfcd85fcab19bb88bb_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:2a223da7f2e09d76f048ef74ba9e18d29ada46ad43d676af32a6e32c02efa867_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:8d96de0d9faccc93865c46b1ee881d2e0be2d5ead520a0049030b188d7258646_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:5826a835b7506abd9863c2860b14cf2da3975bccc82c20e8dd379d19a0899f38_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:ce50c466e22e13cfcdb2fc9669b4b8f80fe09b96ee0a354b8aad522e7dfe1352_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:fbd1cb60808dde27ee424adca3d48f1f345992044082f4cb452b528101769b34_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:55af6d0b6f04aae9227108d33af2589ec2b08def27b0a96bbd8cf5dcd96a0b34_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:a6bf966202e30907b5083d11cb1ccab1ff54bf17bd478fef3b85d2ca704cff77_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:e8dcdd83456aad01d1c0fee3faf4ab2ac18e3372181d0fa0998e49bf365200d4_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:f9041e865aa3e0e8bee3b4f49bff0929e815dde98239d381dfa824f2823010a6_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-dpu-intel-ipu-p4sdk-rhel9@sha256:61d37eaaed9e2149311c1b5e6df751ba0bb5b63a6e4a459488a1cf6461a27e2e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-dpu-intel-ipu-p4sdk-rhel9@sha256:c9e74a81597d2877abda1a30bcbb81da7a28bf2601f2dbbfc7a747c0abcea57c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-dpu-intel-ipu-vsp-rhel9@sha256:2065fec82aea506533da4f614cd605712a3d8dab0f1d5d8adb8303384b06e2ab_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-dpu-intel-ipu-vsp-rhel9@sha256:30467acbef1e5354694a2dde7c16835eb206ac6b61f39c7700b4504b70de18ae_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- +36 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:17475
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17475.json