Red Hat Security Advisory: OpenShift Container Platform 4.19.41 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates
🎯 Affected products69
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1a8335bfe17cbcd69f7c136998769020a737e9fa39235ba9614214f3a36f5d84_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:261008b65c77cf112ab9693148611ae5911d5e5e84db4469dfbb8df7c9e4dce0_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9272f571ee2cc27452de9b6f80eb09b5d173eec2e1f9392aa8bd3ca91a04bd38_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9dd451deee4760d1afc1a01ddb72a025c34bc4adbcbb00d55bd2a67f7e9b5a60_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:64c9c46f816e71a12d6e17cb21e298123ed0a6ae4ad4e6cf98f6df8646e8efb7_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a0111b47534282d69f4c6ec98b4a6096e9c84be49f04dba6fab049af0f5f0ad7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:b7921139361b7a405bbde198cd49d97929a238583f9781c3da6f0165a24945c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:c21b52bcc8180437e230d1452d7531cc4e947316744dbb4ae140b9227bc5987b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:26f2aa6700636ac57eb7c58c25999e267ccf4704648b66c9eac30187d5391e74_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:7c1614a03f0ed8c5ea01dcb8cee832c7e1581254b80e812ec4e37d1ace56f661_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:8c3dd397219c0411708b2c8c5e0090148206e7b966a49d2b71514f483a4371ac_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:a300c89d9fd033674fb8a37442edbfdf2c2971acbd0e9c2a10f4851ab5c0ca50_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel9@sha256:6b00466487de8862b2c5ea2da93b0ecc1973bd7ff404aac4fc070255745f3af8_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel9@sha256:bd88c10289025af149f02e09b365efe1d1473ea2aba520876e0a56cbdcf2e6c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel9@sha256:d4ff56d3f57091966e11e7aebdccc38ef520d1c14ce915cdf9cc83efae0fcfc4_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel9@sha256:e810b3299b4ef53d44bd0c8b12b1fd0deb6b7ae7f4d44ad9fbf192a100723f4d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:941f9b681c279aa7997a0f9949256d09c319bf3f0ee4014f813c6e9f23442e1c_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:ce9ba7cad49689571aefcfb8eb8473e39f7babf08a48dd5eb321cd2091d1c519_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d0791e2d15f585a3e8bf35a90e0c0b88022cdd3ad4ec8250c8ff3fa3ba1cd2ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d639fdce416c93081a8aeb7cef8dc3bb5afef9741a5738754c36ec1f7644ad26_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9-operator@sha256:5a5b595b47f9d1a0404dfa74772cd1285d2c34f8826df6273e3d50d3dcf6c5dd_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9-operator@sha256:61a0bbfa7d0eb0ad454030516a331fd869c5da0a6a61870e1ddf0487f36bd80b_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9-operator@sha256:a3691fd437e8135e1727af87308a3df98bf74c4e7b698a18a046e6f6974e0dba_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9-operator@sha256:fe2d3887d6bdc5eddcb3a82a26857aff885e35bf66105b024c4c85d4e6860ba0_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:34c10053f20a7838dda53a4b847076af6e11953b27974e5d183b75e58145affc_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:4d57651415dd7f85a892b8ac54a56dd4c65df2da34b73040235e4464a0f17c02_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:5d68477f715ed6475b5667adbd8ff998c0642c17996f4a6b872e0bdafc40a3aa_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:9e6ee251224a24975c773511d0f1bcbadcd8255e049ad38116314acce6c1e8aa_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-hyperkube-rhel9@sha256:5ded2f9b432c84f1709bef9cd1b4e781f6a51000d7fcda68427bf2bc6028b0ae_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- +39 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e4a2a6aabca1c0a455b1a4eeed0e53eae06b4eb7550388447c49d2916b7cb73a (For s390x architecture) The image digest is sha256:8a5c36b10b981041dc85ca339b131d1aa741e883d6ca6ca28e7f7ce0a370f4d9 (For ppc64le architecture) The image digest is sha256:19d893a0833159efd6bd0918fd1e1779a2bd1867c592c49571ab104eca0c6b76 (For aarch64 architecture) The image digest is sha256:1b20206b1b88dfeb76c0aee2400d1915b86a7c342c91cbf42ba3e2bc4105073a All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication.