RHSA-2026:34050HighCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.12.93 security and extras update

Published
July 9, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products41

  • Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:3895d8f92a3c7da912bdc84afd1c5a9f917a0438f41f167a777836a8f6efb3f8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/frr-rhel8@sha256:7b3c1d7b52ebcfb420cc923f94a195e11d0bc08e20f3db13a5408def1ab2bfae_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:cb3eb03ecf3487ef0a66c8c9bda812995a4110ca85cab02e7a961d1e5ca27794_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/metallb-rhel8-operator@sha256:d8aeeda1be6893d50f871d20e11ae61b163bd44d5db0b4b647d1d7f9a55cfb1d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/metallb-rhel8@sha256:1d176f5b076a791539a95125efb90db89cb4a01c8f5be64096a5d4b17b706d61_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-ansible-operator@sha256:aeb69fd63d309ec5d519400718353bcbf7d8e314fa3440c9b21ce7cefd7f2059_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:0a8448d8eb3b3199e22745c9111bdf45267eaf1ef14294c78dcc4dbf14a71461_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:526eed6484cc47fed57a0a3fb2bdd6819319116a563c7cf6ac0f34a5fe329931_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel8@sha256:3895d8f92a3c7da912bdc84afd1c5a9f917a0438f41f167a777836a8f6efb3f8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:3895d8f92a3c7da912bdc84afd1c5a9f917a0438f41f167a777836a8f6efb3f8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cluster-capacity@sha256:a4f401659e316da5cecb06121a0e56409915b1ec6bb8a6b49e9f299a609eab82_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cluster-nfd-operator@sha256:90b25c93afbd6ad3522656cb11aa5e018a360b4ad7df48d6a3b299d4b6326dfc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:52b2abe04dc3cd21374004c5cc8b54974c91c0542ef84b9e7fb4089e67fdffdb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8@sha256:4a9423dcd9ea99a6bf06fb56a51aea7f754a2d445778a68b3cc8d30e3015186b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-contour-rhel8@sha256:e42e76c70f312b7c0d88903ac1fa002f16934b0fb9a4909d273625df2246dded_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:1946e394a6429376b2ad2f8bb46091994779aa171fb1201d4310d445556d5bcc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-egress-dns-proxy@sha256:948493df70bcb449bac58ec93b562fdad0ce5aa856028d466fa36c2d1df775ea_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-egress-http-proxy@sha256:3addc6c436df611e746a039df654a8f703158ba2a7ec1b45423d39784d1ad02d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-egress-router@sha256:640393ed8db92f380337487f93c061643166185f118d641d62ac9face6db1aa5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:2ae1222d9058e088065b1f161a76d879c72f0ce4d5e792355ee08a9ea04d772e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:cd56147c9bc86e5b7f7f21714a9380f589b985603a43e4f581c03d7e495f1212_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-helm-operator@sha256:25af3d0f0e0d46a0f4d184aac896db3118bcad0a88817d4de5489ab58de7e6f1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:3dd56a4bf5521a954ee3d2d26f42c8d834d0a048588bd53184e6b0b6eff59d82_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:33a2f0c35b8145db73c93e5adcebb22ada4c3a15c2daae752083784e1014b808_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:458a0a66afe92a64c35f3b5694e87072b6781743f1e8e8e5f8c7fc5385ff5365_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:00b21f2da3a2188c501246d293e0d91253bd90884489d897e09e2f526693ebd0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-node-feature-discovery@sha256:4b1f04045082b16982f5b3a7cd4376374b5f84e19d5eaa947db9ff2b4b784967_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel8@sha256:2bf9337c7eaaad6016c89c2e303107e2e0a04c7cd4efaf94fdf934c0735578ff_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-ptp-operator@sha256:76789c94f4b11136b44c327c7fb103b3728f9a4d85158a1b9b77c60e0bf7405f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +11 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (4)