RHSA-2026:21704HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.20.24 security and extras update

Published
June 3, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products178

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:582dbca498a316625cfaddc58377e5c26390bdcc796d0d3c86f284bbb648b917_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8c5d19e96a561c57422e1d7247c4072af4e7acfdc15e2214198fafe5fe83d9ce_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b9479c81d02b606739c6c4aa6cfd7b11c5c6d53fbe2d4301498ccbc1ce3d987c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:cd31a78dfdc24276a48e8134f1781094f5c145c1ea5a9ea5d62baa10a9bd8bbd_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:014d8af558f89393f69cde4bc0474592088a9f83a262337a1510f1c7506c3f16_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3c98c36a211a102b87cc280629f2071970e142f10923777e31955f85e631b705_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:8f904d76f6c23eefab3ad77bd5dc815e8553bf2a3090afd013e9ec878f16cb12_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:bdce2e1c771d2af2a9bda5e1ffedac0bfdbf93316bcf8c22aaf8d2ad5a131464_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:52a5f99385579f6953720a80b976ff234b392154eb324457ecafb4158c710c69_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8503f8452d772a93be50f0cacc14b4af76d1925798d6f6da9d693a7d1671687c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d3dc82041c2e7f6b78ab528f2884a0aa8ac8f4be69a80b21ab52b0ea2caa9ecc_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:dcea3b1cc4097f375225e64bb0d931adc2d4cc16c9b75d74bbc6f3a7cf10dc8f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:0b878e929677cfe4ac20a1e676baf530250e6ab24c25ae38c6613760b219a7ab_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:561f66f0f3e63e8aa65340ec52acc35778a48edda586bdce18ad2e9dea754c0d_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:96d6dd4f889cce35adf4b0b2c7d99a8fa383dd52d6d8945922a71167781b2bf5_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ad05fa5fb88f3810861b2bda4f8e0a0ab2e6055fabd31b17d5a8b570cac6efc6_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:17a529d2879517de7496a2b9408b82d437fe0e858cc5f62aea1ff22151b4d86a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2ea346b1e04324a2200d6ed4436c590ddbf81b4e82a0e59a846d2b03006bb642_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:aded691d63ceb8000c0fd9950da59f1e8eb4c6b2407ddeec5548675f88607eb9_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ee080dacd013ec3ec50d401a1331dd0bbb0434049c1b5c63733fc7c37eb19127_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:a3d271f13de8eb67ad1aa19ab8a0f808769df10a42cd303e8c9c3784575d4f08_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:d641d7235a0ecc39b8e0bb0d437962611f44602ab030791c04dbbc7d8e11c885_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:fb34c0072b1a1cd96ab2a449944f1daf32672e8c3efb7b867c4c8568de3d67f6_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:fddc73c40ddc0c36a36a9c488a4b36ed2d44dca0ec2f01f28c1d6684fc277b8c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:0436d577e65b1bcfc4f4741e123efc29ffc6b5f0bfcfe69d3d0ff34077f0c089_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3bf2d5fbb780de667ad48e0102ef7d2abd032bf1a490bb8344ff7b8fa745446a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3f72b792349d310655665719a2962551542ea19acd0e2ff90998781e143b0c2c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:88a4e855564c1e7054aa90b6ae2c9513e84e55b3a6de8354ea180ac84b3b4e0e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:1c41e7f793c543751125fd43eb0d400d80b50cd5f0341e8994eb1403c9367ad4_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • +148 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (5)