Red Hat Security Advisory: OpenShift Container Platform 4.19.39 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:279817b52a17e012b4ede04b686df810ea22376005ef7765d47582ef1c3342e4_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:314d4447feeedd809a0de66abafa6b9e5cfe89aeb967226691c131faf8d8e922_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:464aa371343f9a50106e061e07c5d8eae3c656a3f3e7530b37985caa84ed7765_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ecee9360ba8687f6e9195d02105f2095c2320fcf6b5fe89f17c5861811441183_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0371b277d0f6a9a72d998c521aa74b60dcabcfa70faf9e83504f5dc2e0ab5623_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ab4e33afb116dc30f3ceb07135a7a344c2740d7b8654954696bf5602e4a42f8b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b90b3571bc6808da9dc89bac4d40048fefccdc873eb7a6fdc47c1c32469862b6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e038f5ed22c8db00f3ad74c5cad9bced078edb5820335deac37140486b35f55d_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:33601cb02cfd198d711d819594e15804cd9a691ea8d46ab1cfc2063acf359a3a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:68bfe33409ebf81f020811a83aaeb21aceecafc940c89d6c0a5f6216aa794a6b_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:98e6bfd592fba5088fe40f95f5d443c109c38d18d9b08ef2898cb565a44584ab_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cfdb7d395fc448cf22b8f09da93a04379c12c5e80e2e89ff8b6f87014e5687b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:609ccca9976d348eb08ff4a9aef160fc38791ff0a3b245140b51472659ae96ce_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ce27ad2cea8198c8bcb1f90b9eb8cb0b22c35068025cabb75e90ae3c9d00905d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ef41e869362946ce70d282059a6eeadcc17393df5bb008e9ba4fc120a316db7b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f36c2beb65b20687e92b04f3fffa9234ead2276f5208cd75600549ca761515a8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1657b0c05f0167b41528096e8566e64ba22d4078f66d49f1a65b30fdaa252bba_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3cb2949bbc3c6a3e530021aa4e738fcc678106094e8b86c937854bedb6bb894b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:556b9e251b0e9de553e55458b56f242dde2128b784f1519c07832b1c8b6a78d8_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f3f9c3ec4d704f692890e91c725d726d339f937f3475e43bb87d0a5ccfe543a3_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:79f1dd6eaaf33380ec4ba84d55cce4b0204aaed07a70d7619e256f326ecade28_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9b39f0f7095514426c40b27e847f42950f2dd7fc0bed2c5a7edc6944af6f3e38_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ecc2af42f80af393543bec75202cfcfcac67e90b8d7207f502624878e9c3d2e3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fea31c9b7ecc0a8000497df7b320074c03c4a353cef1ac24de8dc9238fc5a1bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:414d00dff436a586c766dd91298d2c58fec73c8ec3ad459e778453f95e672339_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:752b11b491340569e5b389cb8aefab559c302c52e2fd93e15fa99d29f8abd000_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b07c211f257236f514cb87f641d6a82a270b75078b2c9ec7d625d53866c18861_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cec209c04991ec761dcdbc989e20df9c071fbe2ad1ab6eb87b4933938669fb5a_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:388279eecfde3baed285ff768df2235fe10b336e32eccefb9046318d200940d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8367df5ccbec71bfd55d827da81c659e301e17073b8a1a47e43d3e201adb4fd1 (For s390x architecture) The image digest is sha256:8eb5fa80e5e92443a0870c876e82b03971051c4285d9f71ef025eea098448dff (For ppc64le architecture) The image digest is sha256:5d7790ac52e357afe0a15363f4eefd505029cc49a3fc147787cc5b96d8bbc666 (For aarch64 architecture) The image digest is sha256:ed4761bb6a0bb26e5250aa36776dbe48d9ccab7fb1a05a253aa6ef2d59d32fde All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:40765
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40765.json