RHSA-2026:37581HighCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.19.38 security and extras update

Published
July 15, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products186

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:51adbbc3b16b910a9c7d92aab3ef45aa56dc228581dfab9ecefbe56c0b6a6b01_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:62b131e1327a24a93f97a8fc39c53a06ad70d2eeeaf0654791734d2e585a6898_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:66693d23984dbe3788b2dac772b24d2483fd1277e460f3c715bc4bbc9eeb3992_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f73313d220b60ea18570e32bbfc2475c81c6c815ff6b474c7e9e58f569a3bed7_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1df24a680dd829edf0659384e7aaf51144140c4859f021a9dde03a92c89256cd_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:466fa4f18395713d46a83b3ed69ff77249c9b41112594071fa7c6fb6c1849ae9_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:70dc9a2e666448ad330469cd51a5803660db0579d9ffcdb7a9ec06bc364318b0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:be86baa43be20580f7a51154cd731eb6d6c81078f86a771241ef95d5964124e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:22ea3579b35ee61052d1540fcf503b7df804058cedf0335af74c530e57cdb42b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:2afd4478749aaaedbbaa3027d6d0da82f34eeb078719a98fbd192d788d8f3663_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:3595c4fd4e7fd321e6df1004b3d6896d379eb21a1f460fbfc314172cddb9dd0e_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:7db412eec00e2aa4ae3bc907a38ee0d8fe8b42a4c4236fef0813521a0c78711a_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:12f3e46a5c18a083a957418146923b22d38514a40654f6e00dcc27681bfc05a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:3a788c3584e7eb4bd548a2df1d2c7e13070aefcd1669667bec0843ab98ca7b50_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:42e611d4c8f21bd73c8b7eb0bfd893595a3b4847b864844852e386a339aba1f9_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9695991f20184647594d752528e451523c24343e2a375d9c684520842ee7fc1c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5723a72689d4a13aeaa96f400588ff03374328d96d0e736bd5f1ab94b1e4d4df_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:61d917452192053ec8fbae5b5eeb3760a45601aa2110e33bcb3ae87a1d6b623e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9c8259a996b1b620025a28d455bb3aa94335b3edbf1fcd421cb7c677705fe552_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d6fa218a1ea51165b38044956951e127671acf1f74c454fc8bb56cdf79985b93_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:2e5613c8379fcfd90aa444ef4713729a24bf682217faf770bb718af3c98213d5_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:56b1c3bbc17f09138cb8ba547377467fdf6e771e081bf2b50d295bc9fdbae480_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:816a26dea53d22ced3e9b2c28d3526e6d7cf5fc9c1f75ce3d8156ad106737a13_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:c65df715329642357213f5596d62c0cd779e0551da72aa32c9d9d7ebe8fc89ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:209be58c61a1165339492c5834f85d7d0172c7c9244accea5a04e47ce748f95c_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9131199e2b45a0878bf0e70a3add2888f1203ed751154a0e57fbe642e3dbb122_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9582c7beb302f9bf1ecda0251d880f112f16ee4fed46328cb8ca5ddf6e5da1ac_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ced3a28728e9e754cf0c5b2f4f1244c9738ff77c478280c07b6e03fd04b985c7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:022a18c85f1addb8e232ad5b492442a4a2dcaf90b5d33330b297efa52b3261c9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • +156 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (4)