RHSA-2026:37187HighCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.21.24 security and extras update

Published
July 14, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products191

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:6dffd33dd0808c4e115e89df38f96c853b8263781b3ce117cda38be935ac9433_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:82560fa42cecc160ff1e9c6bb5d485b9ea2aafbb26ee0fc2e8c6401c23cf8c2b_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:a64a7eb9be8916ff3db7ab3d01147d852e374c7af16dc819f2bed44f4d174284_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b60f3740130424747d4174ff0981c7b394641f9c1ff5b31058c5cc531ca0f09b_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:602bc9864c9b6e37998545c567cfd70c4064a11c67892594790b580e1bf38ecb_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9a76d098394cbefbbd64ca4fb563883620bff6e83e40fd5e0a7cecf01adff06f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:bc1a02d3e8805e272770c4fb0a893019dcf676cf15f5f4ddf0e08f228156173d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e9e0180cf066e0c3f384fc7640c98c94ed830ca9248f17a5573df85d1d8f47c0_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:327574737a2103a9974ca5602c68831bed0a832e59c11c743971030762f2486d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a7acefc77cfa72acaeb12e17df398b983ff65cfd6ae33b5727fb7708885f7e2e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:aab6eaf09357f4cb043f034883bd0abc8c1ac1637ce49ef9925f66418763036d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:feb290ca127fe28d931b022267d8939d0a622d990955565aacb59a199a4353c8_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4bf68ddb418cc5f10838d3190b9929aafa4380d7878bd6542c264f92234473a4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:952a32bcb38036a418068adfc36454f9326fa9791ea67e704e58d25e4a79ae76_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e3c4573e1a87c1229b2ee0cc10dc1b64d7c9476bf81da5d346af19db74455186_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f17d581c32e498968c1b00ea80ddabfb1480678b7e085b01693e0c7e8524d9e7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:411f066c93e58f3335435f97c9dc6ebd1ecbfd130774b4194e4b725c7a923729_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:66c5b0139b8453d5c5cc9942460a9e36286f4bf048532a799a41b7e72fe3365c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7b589475e20d2ce18aa2b83d77e53a1f8fff89b9946cab4c3fb52860dca9ffbb_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b2f1c08794282cfbd24fcf29e8efc181865b6a8b3e81f5bc1cb61f1ac2a5c0a4_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:199305934abebe05d0bd53eb79189b65f0b8eb0e5cb98624b87a097540965746_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:c631521c79a9bb3c4d6f7a9f68e777872bb5bb592a7118182b9b4dc05944495a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:d4aefbaccb6410771ddb7fb84134e9713d5fb9a48385d8d2999114de7c78818c_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:f77f2deef5c6f8a27f75bc617a7560538b8765ac151af2857aac41e65ac5c4a7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:56887812c4b7e546d90cacc3774973045bac8c71be27d7cd3290416774b8c2e9_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:78c98c64d35ba6cf9dec5b969af3295349d1dd504a77ff5880af0870e2b221f6_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a503663ed5383c0cb1825355e584e41e54a12f36674708f1d620f45aad8bb7a9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eabf926032b95bf7fffaff401ea38d9cdcb35058749863a9420bb73f20da9a76_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:28754629d5ba8075fef095a05d9c50fcb3b8383e0de787815344b0cf3c2d9ea9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • +161 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (4)