RHSA-2026:54556HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.19.43 security and extras update

Published
August 19, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products186

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:400e2a9cccd150602959e9d19022ac75bddc0f5fa44bf94b526886c77607c101_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:6722cd8e173da7fcaaab6224de1cb5456ccf439ef48f6475619f3d8dd3731af7_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:72618d25411961a0fea94669840abbac7d5ac258d2a6cd4bd7647d8c5459a2e8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d0453a02ae44f284e9be2b0a20ee21bb143808915ccf7beb60393c29deec5c6f_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:231ba684a82f6cfefb601bf8a79e91243c5f51f8a04fc83a7e0dba8da2e469db_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:54a4728a8ba7b11dba130352d05af5c05b2c2ad5725cb1a69ec12a6f4536715d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:72cd0a11ea91d18d3a223f4ff7e91d769703c0e216ab3744018e6ec67f4019e0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:92b39d71994c9581ced53d63c336acd593f1ae98c1a7be7f3d9a5f94f9264220_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:4e1b1e995816372cb30efcb57bf09ffb4f14c80d8fdf209bbccf4644e59aa98a_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:74fcd5e270631cbb3f5e1205f40a5f02f6f305df88e81644cca2c1303598b835_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8025030d8268337584cdf33adf1a9d3d08a5c468b1d4261722d79cf5a44b3580_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:89866193f6f9ca71458326811ac66b93c3b2c718a4f723a1a03493bf51032492_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:0eb9b5d105f10e76d857f9aca8e21c618290cd4d5af2ea01ed5dedd8059e21d8_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2c5127ffa86fbb4b3b6b8085557906a5b5d8aa48780a0f17e1eb9ba76fdf7fcd_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:7a6acdf3d22bd71bb4fd23eee8069734bd74db8677963eba114bf661a5a09a62_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:eb86896a2438f37a31c365e1a794b53cea0b2dfbf6f9e8ff9fd6f6bb95910b3a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:db1e5dc297d136cb80b319aae13a720315586b1e94b45430e937184bc60c6c9f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ea12ded16e5ba754726aeae7b29fdf180a74cab9bd4288520606705c144ccae6_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f561b52660e3af697a37af0ab917360d9cab58371ff8f614fe563a0615332fdd_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f57ea8641ca9d70ea5f0c2b958f9896bed4c4a3e765365ed2b6367ffe9a3a383_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:0c342fa11989e22aeff46f7fc1962c5872d716df1ccdf126e0ed28e57661202d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:2f20f63b23ebc27ab9492e5f2098f2a2f540214f8677bc7f26020a6402f4ad89_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:486d04876b498e0331ceffc1f8b008e80b13d179da80c3365b22ccc52595d1c9_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:78f622d03b111765b434f39b111f609cbb90037e79ec1b0d10fa5373a6af7e23_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:1175934bf125dfb3900aad69fdb7ab049987cc7d0e46511fcbb24a8bde26516e_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d64ec2908a14f416c11a365124bc0352973fb9b38c107c939f36258ed2e901af_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d9be79ca975fbc55a876bb096cf40bf41cc2e27ec94506670084772959cd7c64_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f3a42bb39939ed1d220eadaa137acc5c383caa8d4426e99f6bcf23a2c036ce8c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:1a7d3e71f10da89798dab7edcfbfda046b11b8f54e6428c2bd256f0677438b7e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • +156 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (6)