Red Hat Security Advisory: OpenShift Container Platform 4.20.34 security and extras update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products178
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0433533c8d39110e37a99cca92fefe578f7a3e0498d9e7c3878ebc6b1ff3f5f9_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:85320606ea1de014a9776cc316c1a3fc0cfa3930a6b1db59f731eca9c3e4c659_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:bc83a7d9f5257846c5e74f6cbd0f25461d01372b1183c81a04cd67c484d51ceb_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:e60c0970708bde3826db4e9412c516199f048a8a5b9a31cff0c1a2b0b83617bc_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3f45e84e75a7959bcea076132b079f882d9155ebccf0a74ce8b67406ebe06dd2_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:7b6a50e32198ce8be63a001ae246c028f58ed4b7c3c6c302fb22d51f8b15b3a8_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:94bb55579b67dac0314393f1203da8ed11a1cc1efdb8fce947df3380fd55882c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e956490ae07bf92a637b9518da555fc07b6dbff0787e2d3dcd82b37ba6e3517b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:22e138099200e2ddf9427bd1594313c094aa7c4fcc0b3726bbd7184c15135e20_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:56f207e065a9d8b8b032c035f005dcdd5f4de0d2b5e79e29e61c62f13043031d_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:80be65e89a6931f55c2667c8e399f1509d3a2c8665cda88d45c42209c1413908_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c453bbda94e1367a60bf91a3865580da31706445f438f5968dad7289af29a18a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2b89c71ce561b77761ee6d50d58600b5566a79e0e8ddcf550c9c8ed989baf228_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:59036ec9784fa0e9761a63cdbc40a4d54d09dafb0999c60943fc491fa8c9db3f_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:8d87cb3ce01589703a7cb502b82204dc33f8aae9f261bed8bd9b90557606ea5c_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c7c6c703bccb82bde3039f9001d893894857fff9af54a7619e3e7ad1f6bc9a0f_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:176d0312c4aa776fbebaa006aa7ee68ce20e82f2380ce3d44dbcc674c98cb521_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:70a2aa7ab4312c45d7e526ad59da5b3b888f7a597a0dfa9ab0da91ecf2b1eea6_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d56c14c67103d049f5cd3a9ffedad7667b0846b53f5959d6357a774d3bf844ee_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f9450bd84b878aa047a3bafe25f0304c9f4ce6efc658cfcdf26f3bf8ae43d755_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:3478fd4fe8c235e1e2897aa5cd86fda3f9be5d0b00a3271221b20d1080728423_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:948cc137bbd6c1bfc36878c1384c4f369efc3ecbb161c51dac308d981f3e11e1_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:a7969670ebc1e7943cdc2a8b33567c203414391cfd179ad0caabd44a6997e753_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:d3d2023b8651248258470563340edbacfdb1c41b4926df6ad284eb0c9a52e7e9_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:1c91de1bcd122f3ea3956c57191c634a85e81d49ff25bb6d2d1eaf82dc44906d_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:27e43d151a498e603dd627bbcda279e47e2fb07851dac099aec326a0659f3578_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d6401531f91d6800f9493d1389b8b4696fc97c39e490f0dad97a1a7fc4876b81_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f0f30db8ecdea772559894e876e8103ab3b794f8b4fb33a2c0e732671ec6d167_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:43e769b150e9e9bcf5faecbfe7b2d006a2c5e6af23af1f1a03662b05afe4ea10_s390x as a component of Red Hat OpenShift Container Platform 4.20
- +148 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:54584
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54584.json