Red Hat Security Advisory: OpenShift Container Platform 4.22.7 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:205b1f1c747c2d881b6b950d31e37b3e6c9e8114b33db0d4de8c5a07c1f04d33_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:236aacbf85b66166975b33a99a3394cf7d8d8fa72408c41f9dcd9dd1fb79dc42_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3f134d7b6513ca7f523daa7b9dfdfa10c63f6a8f96646d5f0e941b9812200d11_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:81c2841defa78a29b33751b80b0b138b17fc1e6daeff8fe42c917bbc298d21b4_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3584888cffdfa11bf766b980b63b0eb3c2b7cea0bd96474952fb9f596427497f_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3b17db1d303154a63f226f5dd930e77f25d14f99fd47061ec469a7ae65111a52_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:63a04a2c57ebd46287380186bae075404a887c67f53a4fb7d68e01f3d1897fde_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8e4efcf585062119d2e2a5b9a0636f8d35c9bd61d344d37d8a1c1414e6382fef_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:299a07d35ef5524bacc488d9792608042955a0b59576b23830d91bd4268091ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:7635312d8b4980d6c654e8282194e524df90ceefaed06f4c1538f1253d27a140_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:b645963af7080ba54e56374af3636b5275d21e042e1f0d320e77b60d929578da_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:b91426170aae22c8e7cf52add115336c0aaf5c0cc416b8495767e4ace836ae51_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1886291edce491810724be260f7f6e7e91eb9e38e248babf434b16cac34d8c54_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:73c3bdee0efd0bee31e4b65798e0a61dcfdc0ad0c06795bd9d968b0c8b89b814_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cee0add2b115ebe2c9ceaa7bea2bf52d4d7f94a0cb93ce841b271a96cb673167_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fb6ff0bc594800acee96b832008be936edd2968b0386b6369e12e83b96c7667e_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:05dff6f5efdbfc540288f5894c14e405d7e1284f6ccfa8428a8bfd792e89f616_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:33c7e7c2f16cf785615fd06d6e5b231cdcd88e18e3c68df9969af85971854dcc_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:55c8448f3bc9033571d44e7ad4bba353beee605bb7b1ecf8dc5992050f249592_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:dc3216cd9501a3da1cd8298c7f4d2bdd1f902b7ef5f6f634e0d0c8d2752642d7_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0fcc57e6ab7e759a56790f90c447f2ec4ed8457f87723e89f27dba72d44c6e58_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:201cab32510d9d698843daf9f05e795952b51fef914d02412f63c9b775ff8d67_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5487647d0f11080fbd79e0128bf5a4a1f5e7342f1d42a860c97560bde97a91e5_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:66d61fed83f4e2df97e34003ba992c3e0cc40c899362a41e5f1627cf80812ac7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:349c3798d7d67e136560f6b632febfc924fbe36883e235e7599643f4224f138d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:676b83413576bc58048b9ac16ef3f387d78345bfe6dc571caebd57452d82749c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b9b923bd7eb6f773e5c97bed56282d0a08516df4f97171b4484b9dbfaf6690c9_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c8d7226472b67c94809974911da393717ca055a97d8cf8d2fee6ff49dbfd6715_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:28a74bdd6b26363af3c17176f16243ba8e0365dfc2e596516eabe7a12096b22e_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:1a50a7c21acc0b113aa74c187bec8798cb58481c065a4c5a0e25df6bc46b8815 (For s390x architecture) The image digest is sha256:fab0fdcd43074c37a41da78a0fa072dedee74e50bbaca089fadaf0aea9dbbe01 (For ppc64le architecture) The image digest is sha256:d3ba0098621b34090d062040dd7bd6a75ab98c0aa50a69ea25cc02cd38743771 (For aarch64 architecture) The image digest is sha256:24ee7f1deedf24b43ccc30c85c14233f1543076db3c2a7acb1c368c9afd7bd23 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:44237
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44237.json