Red Hat Security Advisory: OpenShift Container Platform 4.17.56 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:212c20b0c120beb0d52b2b6c2175be76bfe12a5d68b84f2e707e54a2dd50bacb_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:47184748914b63354e8f70dbb6eef7e1d919add6d5d17c53048a3160166910e9_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:949ee169b1b9a70a6893e1dee970b6cdbcad071b9bd1e27e5513e4d401a39114_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d6043b510201c69f3dfa1498134b85dff55560268360180484115b6c8280ddef_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:303f7654daaf263e2e04d3f3d1f42fadbbf3abf2f81d503b4e4d5fc9bbdf4c28_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:659ef9ec39e59fe7a4e4b0800794cd812e1cd8347167acb5ac2b11de567780f9_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:aa5e63cb7469c7f8612204e9ef5247a4257cc51fe617e84330b1db4609a29ac7_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b3ba2ee1866e62190d68937dd3469b2c8f10bde62644cce8b60c44eb4553b3cf_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:030fbfcd9e50e2d58465968d0a02e43dd062f35523f0a2574926c6cd494482fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:5491be4dbb48860465ebb920a118131a3c0add68dccf4cab15f6343764b611d5_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8414f3246dcf417860eb06331dc514d28efd26c7215a1196c93c2d30faf44a5f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a5feea6d9263c51eb80ffb63eae28f9abeb6b3f779d08381d9a3b1c02f94879d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:09067e612169427e344428213cc8ac7af6f30c2ad194701c630eed2967a8b8cc_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:651d748bc3708d0e1e176942c2ffb242ab5a47eb40bf4b14776dec5c5a48e41e_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9ad65d3e66a7c6ab4188ad01c37f774821d86b4bb4adb859081e004f6c3052d8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e30c8054538ac84750a91afb0678a34ae5cbe2a7fd6c374be99e9908991bc5fa_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5bf7ccb915a7d10e8ffc761aa2dff100add16370b02b46ebfbfbe88ddcac08bf_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9060a62cf6d768d75c0cbdb006aa6f41eaaf5a49c419eea0b382ef1db472609c_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:bec506b324ff237dd869f3de26c9730215aa72ae5c7f806c6a3177913212956a_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:bf328c5c1596b93a638d85875e7773132ebff0c1b99505e813feefda27ad64c8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:3e1ce2eb35206d75c6d7f4537a4f5c0c026e90d46e6cec799d5629403bb3e1d1_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ba13c580930f3928f07e954f563e7ea8f956c46e0b0eda5098a0b5445d82c8d3_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ec5cbc5d763f300cba825afebeeb571a9c6338b255196b192a20ec82ba8986a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:f5a5af01be61cefec6b22eb8fd8f68bf944e6a70bc5827d36b279542846969f1_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:05e862d33f90d632583e2cfa62cabcab876a6fe652e1f07751e12a4b7e955662_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:0aaf7c22a4bf786ed292e73fd38f031c67994607a7668cd779e441724e313ee3_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5f195f1ec227b5e82772fd66e485e650bb3a0b5b84a4b5d7ec98accbd20a5e7f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:99aeacb417b4a0d7abca6f01b8194319838facdbc7dc17bb4601db091008db8d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:3c2891751d40931f4d4bed2263d956de1207cd20c9b2a80c9931720651e03a3c_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.