RHSA-2026:34791HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.20.28 bug fix and security update

Published
July 7, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:19c9d31481f6b823c02e0960eb54a187856910a9ad9b57bf6bae19db49ef5c80_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:26c1ef5f515892575f5631892029da82b58221081dfe2142a456a869c5761e8d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c38f1b846eb87f4f45d3b6ba9ba0e33e5a220c34204bccb1da169dc65a57686c_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c7fdd3bb4eb4411f58f48f5f24d4dd5a53aab1389e85ece11b988fed669df4e9_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6d2e61fae4b3e9c21185b2b0a5c5db3982825fcbe5bbab43cef36f5806d818f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:76b941738f75312e43f56f26b6df288a8ff73e7c00009d6e9f864cab97152da4_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d1ae669216f2ffa33d80f5d71661d0b8c95b0f424a56ed2e9eaab7d5454654f9_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e0af52aefc600fdbcf8ffb12c7061918314356681d72def0b8dcd55a41d13d48_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2d0f6bbc85c7a84719564e6d52ae16df0029f5f07bf2b143592f97ca90df84db_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6fc8db4407a5515a3d7b9c4cc28cca3fab598ba661cd440ac785129409476932_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:815d4581de4e003d2cc056f6ac619261bdafcbeffedcf1ac61323c055bc7c739_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:aff61dbbed872dcf48ddde3ccd3b0c2c5a03d199cf7fbe6720d677c565d6fa04_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2200ed53ca7914666cc3aadfe1821a444d3f8ef7bfa456c915b1ddc9c70c4974_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:42c52f16a212e07e602abc3c6599bd0392bfee644d6f12e30fdc8c332cf5eb39_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4c1b95e288195b8226d4352a90cb497289fe2c04ff1aa9c096eb661454f092cd_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:8aa4ca3b613f93d4da95e58784e0ce1a978066e6c2e8e331813f7ae9db295f13_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1c69d5c9e5a3aacb6a1dda50f16bf46fff933dbee285ff0f6f0397eecba861b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:87ac78f1f8fd2286ccfcdc885e1b02354472627187757a5d33a09c4d89520946_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:91cdee85a9a2872d9e07e978ae656aaeac03b00d61e2a599ad45593156b6b307_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ff93aef92e133bba3efd47e3976019635a6c6557724c5f2988b439f19575e16e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2d22c104c2585b77a12bc4f16cbb1e497aaa7aeaccfa77f0bf2ba311fd50feab_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5d5c7331ba256d154fc68051504795f0077639a157a7e78a03ab582cd75971e0_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7d7ec4eff87370c1df7810f4f74b0c396016f4b8f20380ea38789465b645af2a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:924fb1e23353bbe92763b58304c2ed36abc8dc07ebf4b0e5c21a9d2c5676e83e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:70c35fb7ecbcdbc73d9cfac51dc5616c5f175a517697bb427abd51fdd7aaf749_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a3999925f43ce55756cf631aa64196af04c1810989df99a5533e3805b6a1106a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a4c582f90e045c3c71333bdea241c20578a43e3c15cdca6a242905ca992ca95f_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c1e3b1e051ed539b8e59d66e3ce52c69d6281ee44d37ac1bd75de7486cec9936_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:952b671d4cacb6debf06aff03d19cf0e50775651ad6a8162e0a89000d7e43053_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0f9e0109b320c8c93c58cc06f54defa90d9462b150ef9a9fb407db6630850a14 (For s390x architecture) The image digest is sha256:35a85e19eb7c68ecd9b3bcce8aeb27c9a4b7878a99ffb211611f31eda7bb8e54 (For ppc64le architecture) The image digest is sha256:55770cf362a7ff3313b0edcb6a58d76dd524980a54a563709336baea78d72933 (For aarch64 architecture) The image digest is sha256:b093e33964d723a21591d37093002532ba32057377d415a93093931b1fb1b63c All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (5)