Red Hat Security Advisory: OpenShift Container Platform 4.21.29 security and extras update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products191
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0fd7f0d73d6b64c39099234d93c7f9f51dfbcd31f3b91598f74759857ca9a6db_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:32d3377fd582ed8cca0abc5e45822586c89e337626ef19b1bc1c6e40914b9aeb_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ddd1a6474300278dac787d5e4e3c3d039bb2da4ccece1d004c96527e1dde666d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:edc937b4de4b12567d0e5d7ea0be6884d7f78e523688810f14bfc0b57d5f26c3_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:216a37561cff18f8bd5fe083fb894e8c125885af8fef3bfc4f2b3ddfb4d8557e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:374306e1b481da6c9047c0f0858f130a751d7dbcc90186f3ce67b6a3ed4fbeb6_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:396fa8858583a78e8e4bfbb86796222887ee1940c4d19a42fd5a050e34fe4c25_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e43d84cbb58aaa6e8b0257d613bcb2cb99f5603abc3286a7b9ca931b2837b6d8_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:00c1899142a0a9154c96a974402ed90cb69d9af43c4df5a926d26e32ac7dce9e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1be6df2d9b98155589b98f39a87c8ddb7b93d4f689a66d9dcc298d7f13c464f9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ada2d5058e8c966d207bc51163a26f9178e658b9cb91162eeca78fc3c80e7e7c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e34fab907da7d5544abfa221fe81e84f0cb8357f1a3cf8f9f44ec646cdc3fcf8_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2986be053fbeec6370bf4d3907fb1552e487b2fdd40f7f77a13de05b7738b85b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:6dccfbf75155a6e66bdd3964442d38054f9d06b7bc15d3cdfad849273ca5a9bb_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:93e150cd31f0d3cc1d81f09e5cd8c17a8b48760c5898dc53a2eaff4d8b1301ea_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b395c24205a39409a775300161e69a42008f480782313287a206018d9d9a4c1b_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:20bb64be019c65f9219d1382138204b7b38dc2e1812c5f644917df3ebca8c32a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2d72686181aebb898c519976817deb8498ed4c471e06aabe469600f3d48e7319_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:68e2c6dc33d52ef407e05ee066bb7c15f8f9e377055ef51385af7a7734a7abf2_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:c7b6cf03c610fa94e7fe88f45840521b59f38271ba594595be7da5eb7846a7a0_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:0b63c950ef3da3ff1c2e07e78b218040991abace6b3513220116c85fd4543cd1_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:1468dbfae99bdb415b7b05ecffb38945c62f6a306b9be53226ed305eb0974069_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:287cc54647195536203e3ab55f1a04188fbc6edfefa2e733d6cddbf58c967e3a_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:65de516013af4ebd5feb0f0e8933f639c40f086c536de7ced44e642f523ddaad_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:50d1e6041912e98b6ccdd8c58f84e97932ede3611660d2e51bc4d8a7619a2fc1_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8a9d82d6ed529aee3b72fce932fb3d3c77d4c3f196ec5164c25ad11d5ba7690b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9584037d9eb2fbe1cb4654b0eb2ce3d549eed0893b18886428cdcfd6d2223f48_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:fa91ec0d482855cb0600223c761b76bf4584504b092e84989b0cbe761a52b730_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:35f03eba8dbac5e9f9459a6ae392ba21d8934d045fced2446a0eecb57d3a9e19_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- +161 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:54603
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54603.json