Red Hat Security Advisory: OpenShift Container Platform 4.13.67 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products192
- Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:799ef4b259c6aff562c5a3b15c8b0fd83b2d7b5cff526b342ecbf4e5896373cb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b35755c010da1f4e77a53f43485156e0d0bd9fff3093a719ba7cc04fb070edbd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:fce28fa7d558f19025d935f50c27af647d8e183345d82f53956536b2b121aabf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:57b6e075f919d85ab8faf4f639b521a1ea730bade44d379c3e79e1fb67feab78_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:360e784b29fff56c23f83228efbbe63e69eec1649f0e9f53c53c8889aab664dd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:888089a33c80f0c97b1f90b31487695814fead6910fa5c5e1ab2e931d15f0724_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:0ffccf7d46e03493058c33451201744fc6f9cc6902fd33db34d2ae2acf5469ef_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:85c3565310c61c86fdf36ae04d0c741478c66f8792a0b47d0ab337503c9a4ef5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:25ffc183febfa2cf8c94b15af292c9afd7a8ceffe2d2904ca4d17fc9f60ecbbd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:2d6001a648da62a0eda639c4f377d551cbe9bae0f5eced64bdebec9a8dc4700c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:6dd3b2fe4e877c77d37362e0ac3e67067067b1ff8be8ccd8b32861900d7a52f5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:0c5631a9b7a93fd6b815d20463b3a551590cfa1b09f39d77b8b276471d2eee26_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:e3c6e35aab5401f48d8e6c867692b4aacbe05a33748fdcbf83840689a39521e6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:a6ee3962bb6846e591065bddc2acf914d5048728534747e8dd8cc5c4f5918839_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:69c529b75d7ab8c920eb22c86fc400c7b94678808744fdfb56fa31702f309b71_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:925b8ead8e5260ed7f6fa46ffe4d07e7c646e42ac21af414e6de308c082d91d9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:de4106d4a3b7256395242b3aee01f4738febbd37ddd3b6253c1c3b2a59d1669c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:ee0b0585fc8f9decf11c0fb0fbcf76dae1400c484871f827b9625151a177075c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:395ab217ad32811c672eb7e19292b61b243cd92a356b880c19a72fb4e8d75fa7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:08e7b8fd2d452682cb268199a515252c71b94b71a960de4859109e8456155684_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:3ef12071ec1593ce3f0635df6fec2ef262c61c8c522bc3edc2b18d0c42c15c07_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:96da7667e39837305b8312e36eb2c2e7ac656f56412c37c53d7ac89ea87ea9cd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:f88b9694e9747f12e2891b35c065f163e76a8c102ca4f9f49c3429ddd7c570aa_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:1a4982644bf9a77620fc2c42eac567bd2b58e99c0c9edfdc6b2bc3183a181e93_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:d736b2a8185b5883af8c2a22efae106fda1e78357287372c3395212a2723f69a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:9098ad9d6b5aa177e16a59b9f240b0f63f0a2ed990bde697ea0c31bb96a2d61a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:e598f2333d30c0018aa047621cddb3fe54bc7df8a0a5ac09bb5ced20a812e6a7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:4ce1d6fcf4681aa020ce6f69a9636302f666b1d81e6f39e730835e48f28ab02e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:6a2b202042078efcb131d2d3e063f1af42a5eaf10bcf4bc42514668040cb794f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +162 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:596514a0fcc2e3110cbcdf2fc57295c2df375f2f0ff36452ff0d7d181ad6c603 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:21691
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61731
- externalhttps://access.redhat.com/security/cve/CVE-2025-61732
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_21691.json