Red Hat Security Advisory: OpenShift Container Platform 4.12.94 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products191
- Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:fe03d49f44b3f8628d367845450c8385dc7db16e71426f5a129de5a3c432a925_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/driver-toolkit-rhel8@sha256:afc81f49af40dbcdbfe56852f4e20deb3350cb4b1133e4d54b525235475af6d6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:d49a1e201dd0a4ff88cddff706a9a2982d5effdf442bf31391389f52959308fa_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:9ba2e7db78de0c76f4a2ab4455c7fdc3ed3b5f2a2c163c6dc43bf0c5d54b373e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:2fe88a989aec30f27e6959d3f97adf608c25a38981bf9e0b8cd6f592337654b5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:3e2834acc551ee63717b7b06f4c7744a9f02ecbed24bc2a48217f2753561e73e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ee4e01a568771e297956dda2186eebdee19e4957317d8a652a00e34203143d9b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:b268c3127595aca0daa9ff80327224f53a662cc56ef86a33b08f2f051cc44b78_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:0008ea302c175496f0a7c245f01c7797c20e681c2894fded701c06bb87c661fa_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:7b4885d188b06523743f16e7d45a64c5a337c86dad10e24a8bc5e47471565a70_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:6366f382f82ae54b8f9fb841f6b52bc5a9c087c80d5ab019d7764116fe3f81cb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:3602f4565ba7d69d3d160787369c4c1b35d1e9a344857cba1750184459019551_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:a4cb13560887d4ca7da6d21a97781cf0e8e58a4cdb9376c5227fd6044edf62f3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:73ceb7283fde23c10578c5c9b5bd27346cc37464798fe41a17844220c7eeed53_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:07896d9668fb163f5df59d84d9a1b4db873ad67726c823785df13bf13035df6c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:edee90ffafcd48402daa9f16b01b83ce5a2fa6349fbfc5ae8787ab31f20d9483_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:786f402280dc9d7ce7ee3b445f9c3d446eafcdb7202949bb1f774705225c1ee4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:315062b74cc58b75b65dac86d86b4e7a13b8bb62f8e78cbd02115ceedcce80d2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:4c6b923ad6c8812c562e64343f1bc2652969fd8fd2c241eb065d3ea9032cdff3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:4e5330fd276d9c18eb2e222ffd7ad5fa90a2d35bf76177d1207aba78ce542b57_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:79b5138fd0345fee0f141d4eb42b27c3ff5e884634538a20631e9320914416e3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:a7b3666523a8984a1b6f603b6dd707462adf9d39ff4dc4ad4f969ce223439866_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:1fe694c96bc95c78004f1dd37f3e8589b83ceb940104929a3e337564c0b5404f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:b54332241f48d211a44a0cce93dc0a1f741dc3eafde9950a16e01689a996cf41_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:c817500f828d281867170c0bb52da1d3891b9869c9670f2420e9c12eb24dc063_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:605b846513b427091b4dc682268575b0e47e51d6efe87318e958e36374fada4f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:169169bd8193f810f797fd9f378df511c315f95d9afaf52fab5e2674b73522d5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:f70817c64ab877c1a47f16f76af911c097055c9c4cbba879361f61c27144d408_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:bf6c4c1623f3da1726048f03a390870dfebd58d132f46a9251484a6558ab1672_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +161 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:7eea337512af15a4b81cb8d5c8005881ac15239c156fc779873e10bd3005b047 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:40030
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40030.json