Red Hat Security Advisory: OpenShift Container Platform 4.18.53 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5c3def943782aab176a88a4f2811eb492408a3c1672bb0f6f47af7d7ff44c6f7_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:65fd0f9d223abf70741baea5633afdf19d8140c8086e45c45b7d5ddb78acf5a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8d203444ece7f4d7ee10ba6441c8f9fb1428ab98e1d7fc9a5c69d10618fbf58b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c4df26df76d0c77b30468bb800ebbf42c2eb9e66dc4dc5878e7e11b65745577c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1eae8eccc10af39fd1b114e5ae1926defde555368c2d64430c21e3dc51cc684a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:44c4a74ea17a483062aa59965b627b5afc9d7216933b70de7f62a560914a66dc_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:ccf8d591dc1f1b014b080ea76dd9c3aaaca5f5ae0e04d63c78b416ccbc0f126d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:eafde78d07859fbcf7bac3fba39ba4bfb442cfa6a14013eb9dc4f1188a02b1ee_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1246df7718963b5a6bda82782989e95aa4702dbe09b219a31565fb4fced99ab7_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1d2a27578189b33cf0275d47f9bf33e385cde5a5400bc99d5f6178efaa669a2f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:3c0c0a5d9a69cb8a5af511a3e467f6ed621a08a2204ebf6f237aa1188af3a910_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ff7da3585aa2cd3044405193ebc9ec640c8f8791783394e9b5f34f4e9b9f88da_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:15c2f52d8c72612feef95eb4c00f70381ee1533d17fc50b277c460b28a7104d1_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4ef72e56797c940ca5c39be977e0631b5f14589d58ca355d8e933ca3ba81d58b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ada2eae1734440ca8add35d0fc3dc0d00bbf24025e9716e928946406b0f0145a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ee0d15c6314e60606c1805a9adaf7737485f719f07b3324023d42dd96e863d29_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2c7bc2b0f7a1e27dfd41cbc40b29de12fecc87cdb53b677add9aa86ea0136af8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3b1f70066da9ae6e192533b89e8fdede81ecde33c83ddce2db6447ea5b722474_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b7adfb8ce1ce054865493b5577648aa754a16fcb9317f30b9cef21848708b2c4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ba0fb133d5f9119dfebdc38d9c6595983b10173d743ab32f30f29698c7c62344_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:44c7e92ef385104e3b863350864f09d177eea19967f4d1e2b5c3d7c9473e9049_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:4de8e8840393ca74edf49e7f69908d658c327d29d5d2d6abbaac017e47ef53f2_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:9fe00b1526e3c64a6ccc1e3ed78bffada694254e04da56f8b1eb345c98da7634_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:d1cda101c0f866b40d12bb45f08106f3bef9b5a7549fc73430af45657651e46c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:418fb600861648ac0cfc2bf3191e927396c48afb1cc28b8ca8629754b8400153_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:57e6a2497a223412fd5278c45fae78ae9717c89d3d50ac0b564909aa5a11473b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a032aa295afb3c16b7c49a706a6280b084519a463877918ee10a9b3547be92bd_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d0ffe3d1c6cd9bad6ea4babb8844b089939a5ff70bcb073de84e229d84285894_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:0abd32fefdc55ce7eba7e3280e00b3d11cfaacf692aa40854353770bf53dafa4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:54547
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54547.json