Red Hat Security Advisory: OpenShift Container Platform 4.22.10 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products195
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:05348c34eeee33d9f38b55af2baddaa52d486aca026755316b1a5c7cad2abbee_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:163776dcca04f4b41bd1da371cfc80c063d232ce8e723a8bfd325894c79643dd_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:2f6e1f74135212ac9873fea7c39bef75981200edd86e566b516d0e794c71df66_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b523fa6b05f151fe5799534e9251cb85815c014ca0b3fe01aea449fea3b230b8_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:07764751d8538b33b50fc7142e89db51abfb5a4361651f56643984094b5a6e10_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0f47320012500eec81fd7556924eea3fcf3dd843eef253a9bf342e5bb41ba4e3_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:30b3cbb369068fa1c4dd36d199a21fee50ed7fe382b090464155efed7ee9231d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:52df1f2fe7495237631e9a49f5c3514a874262f9162a14119a8a885aee2a4041_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:155d717978189f9dbc6e77143d4aec7bb59c8d3c56232a9b3b5004e6e530f001_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:392237202c1aac33ed50c9f32dd9a924673438b538311b0175b44df38ccb507b_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:63025d8aedf467f78c3f873024fc61df050e0c230c5669e0d7a05df9df198c4c_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c097dafe2dde6ce30ed4a6f335e3075fa30f823ed6d2e96329ef206adb22695e_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:046e802e3074c7b4b0789ddde0c0bd5c1aa229e1142b89a8404b3f51c86baf9b_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:331bb9daaa15d3bdf109048a49445008ab90a22bf0fe63f7ad811ac35f8e9695_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:801aef00afafe4c737d042a474cdddf341c18c0f08cc54a910408ed0e0323653_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e320768d36c984fc672dd2e208031acf9304c9de930df5c60f18c614a6744d99_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0588dbcd0620be65ad20378128472b9f841f9248a1b4436440a5d1b0dcc78571_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:181edb7f2abc83bd6bf724303443f713608a23b41ef02cc4c514012e1799f6b7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3abf1f7c705ec9f4f60dff92f6cc0bc4d639cdbafcb6f620d52516a19447a86b_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7ba38601e217404545a9f9cf64e768b6385bb013219e9eb130acf0f8043f502d_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:32f9621940bbf2b79e2dfc487d26bd4416b2635e7fbee1548b5411311b5d512a_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:440ad20b0891de5e7eb79185e5f4baa74661b926bf4a184fee12ed0fb7f0e30a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:8a5c6cb2d89a53502c5a3bd8de2715302de584eea293d4da1eeac6707240b3f9_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:8c7b22555711e5f47c041512a5bbb3f528a4d803244cb822a76022edede33b3b_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5c0209fe1d9d0098e78931befbd0edd8ec6817caedb14542e47a287bbdd0a235_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:6c1ca1f9656d025c3f95490c7002945cab66187951ba633a71b8dd554a83d706_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:6e0e4a745e29266960029494dabc5fc72f53d4362a3b10f6f88d06bed8adba70_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f4de4a42d5ed65de5df5ee7618b7e71d30491aa6f3371e714fb1a872682c063e_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:32ef81f85c5e02c6cd9d300147e86df94e423fc4c3b48970e2f855a242fab0dd_s390x as a component of Red Hat OpenShift Container Platform 4.22
- +165 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:54771
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54771.json