Red Hat Security Advisory: OpenShift Container Platform 4.18.48 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:1580dfeb7b27ee56f1c825993f6a5fc214f5e8216aa5dc7a714efc865f5bec9a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ab1cfd52294ef065e7c0ca8561f883c4fbda64e05f3f2428a5e7ca2e4168ea6d_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c8ee36961191a6451c0d67eee11f0f91207c330cfed2aef5c4907bed30a5c801_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ecebf811dd07f5573f485e3ff94c4b33e3a599da5f4e52d29705330eec582477_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0233b647330de5b06c9521413e06a6e7ae52cc302a361d3dc9a752553070fc91_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:428c1c89af684962fc9b3b1c62ce1899babab1bd3912786a4f39da738d1f0e2b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:66e946a1fd861976d46f2573639de284a8da54b344cb4b8444bcf8270dc81645_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f9dcb0b1c5f6a4e7b6cbee21b6227f5f2376c85913ebd2c8182d50749cfe0fb2_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:0a7fe35cc229f0eead22e7de74c90768de55f75c8f5b7adc7bca818552882da3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:781b7838d714f3d3bd5e96663933d4848254a601e6d75431efd5645689ce7aba_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:7c5d0320d7b2292a9158e2db6ae4190b83da05042b2727fb1c1609b57aaf95a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d11dbb54c638e7fd9a79d4e183cc5369a3727b46e9c5848162b87740767e5a02_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:0d6060f0fb1d059d595a124e1be4117fbaea6f7a6770b8f1e27e6c93981fe67f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:6297fdbcf64ceebe1d002e127ef0bb86adb668433597870a71bfcc8df72bb76f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9b373fdf924b3b0cc0c6218aedfed86400761ada5ad7e3e8a3410851ea0f6db9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b5192566b4a5a5491fcdda31d1f3f0ec61dfdb40b6613b035cda9f7ccc2745f7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:6c23dd26bbbdff91d4ad822bca54f49e322c96b798a69eb89cc6eeaf41f26862_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7c542e3f98354ffbd73ea6e589374ca37d1245283d0e118f66c305b964080b6b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:92a4741a0a5e0fe3129898185dae4941d3d1aa4889462ee952ec5241b92d36cf_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f987e9e38acf76daefc5999490ffad0ae4af6f838deb89fd51f09d4251c3abc7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:0089000d89a51fb59b34ba938aeee0deaa4c4b15104c37b7158ae151e5caccf6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:02b0a83947d0e7016023dae14980b35a3d8a18b97ba8e4e8ff88e22bf41ebf8d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:16bbc430a05b9ce9227ee8afc0f93b55cf522119dacc8d4957bf3a18bea0e51e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:47489af9b1b6fc00ffebad401e112c73f7f1c09617aac36ac0dfba815c5dba81_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:4f71ae61089aa2f68a4a4193a0caf23972813e69644f0277f833fb5b3d30f425_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:860f680b6bc12636aaf6a19176fd14a8444f3ae73a64de3a134f44e2e633c7ca_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ca259e295c155c69ed47f1ba344043bc349722b2a4fa0e840218ac9c5fac8d5d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ed3e97a38eecfb4e61632b794ca8ee10d1d268f256eea566fd7187f56360aaf5_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:0a9689f472c322f5f79a46975ec03e0719d277a4e1ef984b19c5dfb24dbf7b17_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.