Red Hat Security Advisory: OpenShift Container Platform 4.22.8 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-44240 — basic-ftp: basic-ftp: Client-side Denial of Service via unterminated multiline FTP responses
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5c02403f585a4e9aee97d282047903e2e53ceedeb4e4827d34cd5dcf014b4d03_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:865bef67ba8ab55bbc5879f07e5478b8d1a5aef526d645639925f10fa011df22_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:86ba489b8c986547d2cb5029e18c2fe53e1b3989000ac75b7a467e0c1f34b71f_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9d0bcf9f382557faa7356721708e51aebccbe4a2f5af36fe16a32672da8e29bd_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0c215a9b6c7bb4153a2ce51c1ae5b62231d6b68bbcd23291bb066d49afa21cd8_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1719282d1ba523b894ac25ba2590f64b82de992b322b8d6d81dad3b6073b0307_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a89c8443e75d509fff769b59d32c3f5d81ae4deac1f6fb95c1636d2148fc83d8_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d75f17d15f90121346ac92d4d257cdebe43f9bc68281aa9a40bb251eac51bdc0_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:74be2c71b826b2d12c61ee26c709609c96aea42bee9714c9cbe5729dbdee2413_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:7df4ce9dd7870923f4db862482d6e128bdadca118de0a7633302a8c95893922e_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:99d0f2ae59b61fb040937dc0f309c762c4b6e04bc7b11d924deb8219d0e00020_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:ed500e4f081f57c69ffe4f0b02fd9f5713a2d48797c3e939a3ae4e8f38c67b19_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0beaad4107cb0d6fb39a13863717f9ccda958da36e6708898b51812d17b2b8b1_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2782952f1ccd511bf3800989a4ef697ab60d59eefd4ecf3cb6031d0576e22072_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8532770ce8d504ac4ed7cd8b888e6559267a590a025c3da5ffc2838be2ccb711_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:956483a7f9c452bc7fee16a36f03d96e9e3b3da9dd288c007b74943df39131d4_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1e28b9a28f7157a6a752bed299f6490b651ff94fc2b5ebae9857f105cde4a4ef_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5e8fa0f7f010004e5f87664c8e8f401986463ff1455e60b5ec33dc0a9553057d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:78777e9ac31f77e67875b1ef6ecd4b44c85dd7a58fce69d298e422aa96697500_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a65f8fa6c32fed51ffc7a138357760b28e9149cb645e4d2d58711c38157bfee5_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3a16c9bfdcbe7a08df39edf85f48c9a9ba23795de661577e4ff423ef43d6c918_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:555ef14fbf9131cf085620191d48472082948aeffe0d27d5194770873999e3a9_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:893dc42bbccf9b97ac244efe1e0c9fb3039c7e00d883bee1c2ed74afe721406c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:96712a7e8097b7561b273131243d04d9d8b72c1ee72f060b701bbf0751644fc2_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4494f866bf2c37d89ae15172acce880ea25fe6f29bffbf56b78c531ec9bdfeb5_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:88e085e8fd36aaf2037c5ea55f00a237efa43f764dc66e36a062835e59007413_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a78ebd2a947cc4126b691e1afa0933acda8f1eca9df7e288980337a926fadde0_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d4c34cd6862f6bcaa256b918c5a07a7d0b580dc906d00274116e33029477aaab_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0cbcf0d191d5c7876a98a35c1f872048d49d82a5a69eeadd4f6e0a59c1a8968b_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7480aa0eac4f9d0b698538c54fa21555f3b6fe91cd23be9879f6264918193364 (For s390x architecture) The image digest is sha256:fd338d11415e37d2e6f4918e1751a4b64fb41ea28ff1315a4c1d67da7543d662 (For ppc64le architecture) The image digest is sha256:2ec94920675f485e42f463cb9978db87a6bf692a90e7d31c709c42818822d0b6 (For aarch64 architecture) The image digest is sha256:a184f7b6d752cea1136a3f3ce8f33130f24e8704fc86ee7faf689e29648fa5d9 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict applications using the `basic-ftp` client to connect only to trusted FTP servers. Implement firewall rules or network access controls to limit outbound connections from affected systems to known, legitimate FTP endpoints. This operational control reduces the exposure to malicious or compromised FTP servers that could exploit this vulnerability. A restart of the affected application may be required for changes to take effect.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:48693
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-16242
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-44240
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48693.json