RHSA-2026:34099HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.17.55 bug fix and security update

Published
July 9, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34043 — serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1842cea1adc06eb90eaa2812ae160901bd1a4354d3da8a1c608ab9dc3ba333df_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:37a816ef25c76b836ed14c981e979548d1ce3f1f7ab23f88ae47704dda9dbfea_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7ba4273d1f366c0063604d5fdc7c39e52ab83e97d6d10aa1f35a1227853a5a68_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e70bd56c1de494723b3f92cce396d0339f1d47a538aa626d1827df3d6a57eb52_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:939289cb5bc76239357ae4f4b634a7eecddfc84637350c990f65f22178cf9cce_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c83173c2cc0bbeec8fa5b75f2194a40ee10746048bb3550d72af0dd45351c07e_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d2c4b789e32b8e916ba380000d8f8c308c717fe87db4409ba0f2225b9b35a026_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d97595225635db349a25fd6a6e185dabb621b6622f4f9f834fd5255cd58b9c3f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6404667b6bd1b20fb10cba10818ef52c6785fc9bb06e7269c5feceb6d9142c70_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6824a60265d27c3add115f1f948fd390e7edbc41f3be57023bb36ad98fe1cd63_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bbadc72c62b86f57087735dcd89920869249959f679dd4c458f2564947cc5f21_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:dd2e558eeca9e946b3e36f59f31465f656ec577b93d0d292400a26bdc88a2864_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:92ee152315b548915530d950c59b70663086eaac0f42c6239e3a42710305fa12_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9384a72a08bd4d6b5537ea962bf83637deef2083905892aaed7d1e416d2c0caa_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f4650344966224a3c201bcd9ca469a0203c9b1eaa1081aef7eb1fc0bc45b3b47_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fbacde3c31b0054440b56aa4b14cd056d6a48b145134afaa253c3f0c979e26c9_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:068f088e84b8dbf7484b8e22e389dc8caea2269196d295b8f644cde9eab8bed0_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:442cc010632cc4a89df5a99c4c7ec6dadc82f8767f7aa31197d0e2a6988404fd_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:537a8785e6c413a1a1d8cffd954ab5efbc9ca89d2fbc059ea37fc3e8b9dd0c9f_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cb468d9763add5d5bbd9e7ccadbb6a45c1dbf33af1539f7caca1a8cac6ee9f57_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:04d7c19cc6fd5b2cb2c0093328b1a9c3ed92d5b1d42a6d9a8a8c01ea4c0f709b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:9a1aba95f007e5dc3b34ef230d542a378a474787da98417f7704b35db9423f77_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:b19b40af82d5b36508d9ae9f21032faef6bd61dedf9f699d93a761a7a1c6d2a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:f5f80380adad2c40cb7dcc777f91089629c49993112e60ec593f23be0afca978_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:9c5413e4f1d8b2bab40c7bb12a50a71d36bdae2f7bed1f7f6617a8eb1b2bd558_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:aa8c9b05dd6cf779b976d568e8d6a59cac658b170368d5633abdbb0f4c398610_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:cd78caef81f1a359a71cab04bb06f0a27777bdbb34f87ee2051ef8a6cde517dd_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:d3a66c573dbb137a05fe518e642b56df267b2f42f7ccf44e6a0cabd7ea96d762_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:10155f2c46a9fa56e0f4ae8ce51436d96d2696c30ac509610e0be94870630abb_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6f09cb9bc01cfd9f61f9d8297505f7777217c804fab8f5589b9444b8e1284169 (For s390x architecture) The image digest is sha256:22a38b418eb7f9435f697123bf117662d4d6b725bb4d3e20042ade7bcc616abb (For ppc64le architecture) The image digest is sha256:24fdfdca3a35e1b783f2eae0a46a69cc62a3b89994bb2367f4530a9249ba4765 (For aarch64 architecture) The image digest is sha256:cf3b8c3e3ff5ce4051aaa96edf6d4b471e9ec5312c4378dffc8fc520c8aef66a All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (11)