Red Hat Security Advisory: OpenShift Container Platform 4.15.67 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:48b6e162d2dcb01c870485c89bbb769e74c92a2eb74e171530e4a8d15a25fbe0_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:536da0880d7ebab32cb931e6842a7955563ecb3aaae4ac3760433625ac2a75f2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:83963f7d2be216fb17e0b21fc1e2eac11a81f9102d93323366b6f6b4e396b8c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:afb1ba5c20a3feafebb1f81ac84ebf4cb490e321455c00d081c24d88ec3d2bc4_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4629d200a6cc65571017820a610c64eab6e8f65be5ff5570443d1e4769997b2c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a059a059fdd0522697a9f6e92fc8fee920cd6a2be82adc592f78ee77aed7b408_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d4c99856d276a8382dd1f0cde046a5b5cdcf8b6dd3d4f126f5b2980f8dbe1d75_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d6e37fc46ff8f99554cd8b79f29a675f28f36d24b73702f4bbb652e840835af1_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:0b76c5d1666395255bd56082d5b18ea9bbfd0591f94fe29ea98bf48f067dcaf8_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:3e178eecdd63bc96f489999805e0d2ce5ab8f1d73415f118f98865b40b7b2884_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:c04205e7fb5351b1758eca172c7da690a454823fac6cac77a921a16cc3eaa7e6_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:c258bcdc6936eb981f50c9ed4bfaee4b2c4ee4dd502e742daeddd6f81e54b71f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:096dcdebd499a7a24876fcb9b36aa4a8f4438ca13062f205f226f09107acb27a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:23a1a906676caf6700d55d544dc26d2808a5813d2f288273d9c5e65663fca69f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:4a2be30dc0a1ebe61274ffe6a6729ffc7560f4943370deb26cc16d0e7e050254_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:74449df48351f2b132b6f32b1bd47df61d2ef16abb921be315478e1b01bb8365_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:3e5caeb15919d1f0afeefb531765cc7f1d491e5b94e4e0b13ad130608c2dbedb_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:6569a2a87f8ec4f19271b47af90edb2da75ea0cada22bc14e8481ba1f703d9ff_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:76bf4d629090510cafe96b199f455e202a9df32c07f9529cb70cfda5e080c3b1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:a0e89dd33d07786bc9413088a8dd00a48bea12c840f1d19686d45377011afb38_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:182409749ef9e643963e444ee25ff1d1652432eb63120c9b647e9ddd46b137ed_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:308b9411588750c64014e65d43631790062868fc649526907743345a8d841634_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:41f30f355f83fd38b6a81d30a8bdef70b626cb8be5dbd46d3341149b36146c68_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:42a62e7f05167ff27480b25f81cd224befe3e514eb1c71e38389b36d09929ddd_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:3107556e866b9626d0cd5a2a28152e99253150f51a34af508d3ef8e512845d73_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:bc626da0bce654dc35f0ce2c5da5387f23560c9132131bf607caa4fbbd70cb97_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:df669a7517c0c3c753212a39ae0852335319f6ad1a2de55bdc9e746f5f9ca4ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:f98b2561613325732a30ddb2aede2d34ccd667989781f220e00d32c7b27dc02a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:02f21fe59cdbbc54a590204ba32ac5939946ebd7f335484c033a5cd359cf9141_s390x as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2f76605ac71fd30ffe0f017cbff0c01a24dd2649002b397ba17b010f49c77884 (For s390x architecture) The image digest is sha256:a3c80c9086377af739bb96dc18739d34adde8594eb216b293bfa5b8370be05e5 (For ppc64le architecture) The image digest is sha256:f68d6c7055217da39e79072b58bacff19133f4af31b32b8c529be6c2a87458c1 (For aarch64 architecture) The image digest is sha256:a9b3c83d6d295cfe71a46fa917e32aaabed01ecf4eb54e464428a9b92769b333 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:43227
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-46579
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43227.json