RHSA-2026:40023HighCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.69 security and extras update

Published
July 23, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products39

  • Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/frr-rhel8@sha256:f6e767af32b6d0108e86fd913f5b0170bc3ed9fa6d1802356bdd237067dc989a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:e8e0e7c2c2a1630f14cd705b09fb5bc1c710dfc3ccf1cab906d3c7ad18a2a1a5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/metallb-rhel8-operator@sha256:b2d56a41ede50396c35644d98af9a9095db783757470f540652bff21b8a83813_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/metallb-rhel8@sha256:c125a175766b608d902bf9f22a9de254a448697b75806d5f365eb72520089cbb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-ansible-operator@sha256:c2728e43a9aaa126b57bea95a3edddbad10bfecb122464243cdf8144469aeee3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:53af5ae87626d7f9bc70af1e4a112a605c8cb00ac60016248aa476a176f4a769_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:f4110a975d6d9e7e00bf8feede9d2ec6b5ef49a43501eab544c2830c82b34113_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel8@sha256:4f0404fffd61d7bb08717d915c5cfde74ee84b3653fcd8002297e3bd0b9b4620_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:4f0404fffd61d7bb08717d915c5cfde74ee84b3653fcd8002297e3bd0b9b4620_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-cluster-capacity@sha256:cd093dcf93efedce2d16cd392baf0e3b5f1bc36f342c81e6e054f1e92a01d9d6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-cluster-nfd-operator@sha256:5bac5a5b6555fcf90f67bd3f663433121da459ee765213c09d22112eaa618d81_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:58ab0833517a94d01b5453a0d78c00df31a5155cfa3410217c9992cacec7cc5a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8@sha256:c5905aeeade584721db5c99e5426f2cb54fc7c25d5a5c2df4b8fb535ffbd67d6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:bc351e89ffa52bdc1d2b20e1fd65675f297b651f2ea539e1a9d32f3ec506de39_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-egress-dns-proxy@sha256:dd1e9bac0534f2886cba07b4e875f2b3745112bb71dcdff8293fd3ea473aaf75_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-egress-http-proxy@sha256:ba9218bd2759c524a96fa6eaa8fd47bbdf8b8430f2fd41b4e3c45db280615f4a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-egress-router@sha256:37e0cc01c959c65c3c1bd0e54bd75293dc5a174c4d20e1084a49656ec5d06eeb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:da4d7dfb7d36698f2504abe3dd83d20e1d4cbf7b695dae2138c7d34a9a945426_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:f3b5f77cb36bd419cccce37b12e9dab4e6bc6caf0be2af5467b25bd4991cebf3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-helm-operator@sha256:3c48781258ecde9265ddc5e0b9fe1a1083444040767b744179ecf162675ceb3a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:7d40bd42bd805132ee15dd319fb2083ea3432d516763fc2cd315677f23f9093e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:3be70f3a7d828028b3158cb2ec1cd369e36e7cc650ac9f795b24a58ba7f568a5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:c10362c7131e2d73c6e94c5ce3b3562501475cf5ccbdf66c6b42103d50b08619_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:e56b026b1e7c7e023ed39422a612761bdc69d3452a270c05e325783559516e30_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-node-feature-discovery@sha256:2dba76281f91dd9d3363c33d74f075b829414f589fb77a9da27c67c9b6b56e0e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel8@sha256:e1b319267d0254b7fd625c2344d87993d80110caa71b31895df3399a42bafd5d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-ptp-operator@sha256:17fe9be845164b1134baf8db44912241656a543ca72f4cc5a7dfea61401f5118_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-ptp@sha256:2455116c543e2f6982a7ed9724cbfa938a2af6414d3a53feb5084c8c63cbb1a7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-sriov-dp-admission-controller@sha256:24fefff1b6bccdea62590d1c30ee966da411e5be6d8441c54d3c2daeb982ddcc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +9 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (4)