RHSA-2026:37629HighCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.20.29 security and extras update

Published
July 14, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products178

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:23019231520861c0dd8a270fa4bd8834920528a42533a9e6a286598c4e9be6b2_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:542d3d9bf3b38f3f6e6e2dca3dd8d527213e1c43910ddd7a81b5c8c0c99a94da_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5f59aebaf3cd980004b0a3be479be8e24859b648712610d3dd6e320e5797bf10_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d941de2102cc86c5791bdce5341a783fdf4209643dad7b06cbd09265bf7c1f16_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:69f24675665bc2ce33e3482a264d9c4c5fbed90aad9491d8e84dcbd6be91419d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:6ae77e01a59139a5e338b28c9b0a862619d1961f3b10dac1334d81289baaab05_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b9337c9b15fca53536e77215aeb779d1521eee51c9ab1c3cbcea421150be2b5b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d0c8063e8907a843c2af6c58cc2a22f2689d19c26f9c050fd29a479734394100_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:407278e1f5e3e5e2fa1f6522ed098dfe17b33831d9f219d5451f95dcfd96b4ed_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:5eb66fd3373606cfd5e71a2954568b1ac8225b3468177ffde78aa041da1342ee_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:9c181d5ee822a2de1d4fccae444f46f8bfa8562d75f629b37886d75523e3905d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:dab16171e5669664a27e479cbb92f3432193b495e92a49a7543eab58ede56915_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:3b2f06dd0732d7cb0ff58d57e84ae34f462359db94baea0882c1b9d39f13a0ef_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:75fc75ac445a226f67e42c37dbf779f13d4c927726918efaa148f3bece27c3c7_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9cb8a785bbf806d4dfd8b16acc639286cef9c64f8de498f0657b7142a7809a0a_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e71a3111f659d25c72eeb08795b588047ce34661d88c72531ff119a046e07714_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5208a5e56e9e412f4d76e052529c568c5f335c6370c6f65573f390c1938d514c_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:93624da41efa7d00250f7559b95918f06753052ccbd1952461eaf1f8643e022e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a63601c67d5740d94abef4eb7ffc7d9bff9f7a2aa891159fa050f35713af7dd2_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b4132c003eddbb5659cd444458924e73ab2ef53d3a564e81a1fcf5735da35d0f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:2d4d6b2ce81f25aa03e926fcb7e077d84472868822aa6bc42ceacc308e7f7def_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:5505d9acf32e369eeddfa381af914ef98314d203adcaa7dbe1860e9ee81f9a34_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:80d186feef9a38ac17a65a0e9d2e60062f9bc20e5c1fd92f783c743271eea530_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:9ea4ee319cddccce1b6a1b9e0324452d0a4314625c8b9834af8837e8f2272194_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:16650fa440ee8571ef0372380e51c6ceadbec89ca9f4338e5510a0d2b5b35feb_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5ed9d56add6c3516812afdde46554c158592e25181903a849c5b886405fc358d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d89bca72c37926c0a0d68f2729eece4fd9a0aca9b08db162cf550edb0afe0068_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:e02779c5282c905aa7b6f50c17879eda285ef456470332306f7b27229508181d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:183756f55242a55917e79c4df4153084bbdae74fd11336612d2d85e614962750_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • +148 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (4)