Red Hat Security Advisory: OpenShift Container Platform 4.18.52 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4a8c808de93cfcd940348e67b0b9b0545a892370373bf8d8d372c4252320c137_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ea45e9fb37bf6514fff298df203dd16c82b1aa21a53cf01def2ee1d25a49d4e8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f614a4dd16fd9be05a572d0a81edb037912d0cae0ee23a9c8a63b9e730e02dde_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fe5b0072664d15be4bbbdf1e2df75211ae22a581880757e6e46608c1950c6add_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1dd19cc3685f846e9e4c865c244460156ba915e79c38b4630e809dda50d94a4c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:28283401d400f70ab0bf6cd9b0b9a3ed7bbd60a041bf72a11a866f7407c76ed8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:83bb8f477bfcb4a54a171a5677780c306bf2900e3ba173fcee9324aff55f0330_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ae813cdfb5cfcfc39f8769d0a6082d0cb9b02b8b239554a26286e39781479e62_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2c1603c88460e864a10cae67a5651f9b7f5a3686bf595b7de6ad9de0a3fd9bc4_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a75d434e0767452e7e593f3d0489fac027aec40261ac6268cff85aa3f347381b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c7cd4baa71514737cfe2ccd4b085a35fed146b00d932cdf249de1a200196f13f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d267ed7ea1f44be25aa43c92bb5ec7d7833011b9fe857415cc3decad2250b4ce_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:318498f33279a845b5666012aba93d415e41820c247c2f7a1a43aa4ebbad68b6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b7aea81157e3621300f685ad511aceb4cd113a3ac649bb5eeb45f0f62f2d1c46_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c19f3e3d64f6133beac9dd94043209d009d1e185e60eb4bfd627b9f456f3944e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:fc111213c82df8626116fd4502d5b76a78d31d584465918a5a09eeffc282984a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5be25f03409970cd649035d8ab9f4d179ff8748767e5f042c2542dc48c813cc5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:820ce6be26ed01f922eab5e4215ec1f1ddf680241f4eb4239cf0f2485d0011ba_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c7fb19392ca35554a67ed39fb57146ff08ba83b9540fa9b580e3564f9c26f541_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:da7f46266aa3ae199209359bf161038deb85a7e1e03f0e6860e0a80b008c81f3_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0e807e009ab1b6446265ab8e46dc348ca2518bcc276ebb817fb9772e7081a5da_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5c696a84f098ced16c371e760c2efed06446ba10f00825e3982516cb07e3e03a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:88cad44e76380cc13889814844ab3f07ff2035ecf1dfa66e7ea170139b163d70_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:def24f4e818dd3ee78bbbb28d0fbbefe1933ec775df5768925c6d1ca0a620b27_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1a4ed53d624189cd94061801e063499da9f4591016ab340bb820221edb1a0807_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:8fa47e026242af9e892d7d7635af2a1a4fea8c474a3020d42ffdb04707b9b962_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:befd295e9cb17fc196b6203e37b00386caafd8d98153d28e8ccdd1ba72ae17b8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:cda89bafc9b74fe130d3883a32e04e1cd82ceba2e9a0008cfd036d131f8889c0_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:672a7d6d41cb077c0ec8ce216d4b92acb0dbe6d3f9b81aa256497503c4e821db_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:dddcb2c76b40454aac441daa388ae91c76d90b1a058adce58f3ce4e0ec957b3f (For s390x architecture) The image digest is sha256:cc9705596bdec4e35bb1b1844a7b0bc90d947bcfe4e9e64b78b243016599f820 (For ppc64le architecture) The image digest is sha256:5812c3370e9858c1258719b911113439752277b8f932341f054116858297b363 (For aarch64 architecture) The image digest is sha256:ec15a66aeacad7c22c6c84ff3a5b8026bbb9df2963643f31afad44e93155a876 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:51013
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-49332
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_51013.json