Red Hat Security Advisory: OpenShift Container Platform 4.21.23 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:449d2692458213ced5240879727028b0b28dc4950396c58ee6f350f2dd2fbe79_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b95f318dacd79041858144e693fdcdd32a0356d27ef60ae221257dac4b0df352_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e1d32af33bcf591191835fd1cd2647bef1a71b605bf78b9f17ca48a4b67a3a57_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e52af42a3f33af11ce952698b33fadf599c74b61161c5215d6a90e6c2a857883_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:180a0991b2e018ec987ec046770a6083f0e64ebe49b689d0c02dd00bf4520ba3_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:64a96109ebb28d5cca17c8f64fc86602debb4fa0c1aeddf4f62ec9df4e580b67_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:689892e73ed03f584c885083a0330273f16e49f666b5d7afff1c4f2948b02fb2_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9825848ab8ade4ef3464eb10fe0832d3c2a58cdc65547d45e3c7749ccfa0b5e4_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:191cfb6e6f24447b1ea29fb6607ec0bccf44c6b88d71c6f8b02857773be4838e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:196c830a26af688bcb22f1875476af9791906e47a0d1c9ac37e091c36818ee2c_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:963acbdbaf3e09cd374264896d8b4bf8877129c6dbce2f918f80c8db2cf784aa_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:dafe2e3cc08645bd15ce23bcc73f431b11005f20efd8db81a78877abb67bd0b6_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1fabf475aad6e15652735226a84bfae9fc0fbc126c1f3cb69365aa06f48ca52d_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:27e4f53e8699c9774c74dfb2683d026b2c239e48a7555c668a4ac82618893abb_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:565902de8d9b1fa2535078a7a177d7eb4385f144eaf858be63ee87aeed40b6c8_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b9b661f8bb3b06cb20c586583fcaff286b8bba04b29a8b655ec9aef56506cb1f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:236aa43dacdec6a05a3936424bfea1b5bb8b0484793f9dee345fd0dfc8fc9330_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:327088278e7597c14dec94cc4a69ce3148d2b51d7bc89acbe8683a9ef9d11827_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:56d1c15bd77b0eec3c6bec49422038f877184ac5bcc44d18790a2715da119664_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7456068fc3e1aac773abeb572ce2ff8848db84e9756845279aa9cecc1679869e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4c3c38e5b80a592c3c5134f5ec024694f0cff2be5e82736b35e8812eadb1974e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:989616fef7274911c5e6b0fba8682ad52b9c9570159a9754e234c2e8e93e960c_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d10135f0b47ec40fd9b950929e890d3059e298e1d747872e8b3314b06746d61a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f5bba1399be0562e5af65a72cef95837465d716dcde272cc047e37434b6d9ebe_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:042254fc9b2a782e155554b445cdbf4689abc822bf11048c99f8d69839b08e91_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:36e2bb50a3206b4508ffdc6972d267a3268e2d0537583d0cf641bd91258b3acb_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9d9ed577c07030ee87051a7196885ae3a1749108522a14b407c31c09b75ab0de_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f8f78eab2bdf2b6e4cd47d9f370300074e221e05586c554726d07cad577030e6_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0983e82af4136fe42a5c213a26b862cd85eedcbd6f587555690c1f675682c0fc_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:c58d65eeaf399b6850e5cc637a199ed44066819ccbc25877a6afd44ff861d841 (For s390x architecture) The image digest is sha256:5c89334e4cf13c60df32762ea475b863c7eeb5bc2cc5dafbbf65fc5351f520c6 (For ppc64le architecture) The image digest is sha256:d723c3c1ca165d75bbef247f412664c36bee48ac9ce26cbddf37553c9bb736f1 (For aarch64 architecture) The image digest is sha256:588cfd15da44d83f3f6375545de8c3e08c4a10f02a6f591a4b5d2e8ffe427497 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:34769
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_34769.json