RHSA-2026:57801HighCVSS 8.5

Red Hat Security Advisory: OpenShift Container Platform 4.21.30 bug fix and security update

Published
August 25, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:277cbed8cfee892f07b9d0b90cd0051244a4dabbbe1b15373a9812b795a799b0_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3cee5aefdccad2e3d4d78744396a3fbc831342c03978d4c88aa56571b4459e46_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d0fd19e6b08597ed9fa720d031c81b9ca28d4f269e74a764bbd9235428184e48_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d4c325e01d0ddecec71ceb90c4d5cf6c785c4dca4cf5ee92525af7ecc7177b19_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:478268d3720d186effc354b10c8d375b760700669cc7af59258f244d27b9d0bb_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:57fef7f41be76346a8ed768fa21a65a4f73862895e8ca349134c8941a06641ce_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8b6a4201945fea04c15299e08fb2e86c5ff204075489fc10752d2eb16b5f3dc2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e0f4f28dc1156db5bba44a7c278eae0bf9a33501a23393f72a4d45d94fd40741_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:497484ea4ef9ee807e186dee49b72bf9b5af14edb25a2cb8d8043fb45ec3614f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8bbb1a796e3faf733bad1e9091962b2750c048afcee8b5b5de3d9657411a6e21_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:db8d0d93612477cdc694ed69048ec6037fec9c3e1c767e7b280e69ab209c2237_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e11015b83d5dad6b7ce82968cc228ff4ac2f80af42f9cad36640b33ad078630e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3f773316b42732378cb2c163835ec36b767b4397761d963dc99a6c260538f3eb_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7a6a967ad3beb5b5f7236bfaa277997fc38ddfbf391700ce1d6c50c86acb65a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b66942ca45460e23f3d472503547f9cd9d2eb40918dfdaf7d57323344cf813e8_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d5179fec9030f8d16ca5d64ca00929968415968c2336ccd38c00a2eb8b79bb71_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:251d51029d451a9b333e24bbc14bcc00b3289a4ad85794bb4ee0d860291c349a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2813815d2304ab8938a586cdeb1bbddc3ad60e0b29e084b8e1c254dcd6da1bf2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4cba4634c41c3474b94f5f615c32de8ca7d3c5819a54e7730a0942abf341cda7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e0623d4fb7e84c4e2854a5271962a9c39f72fcd4545777bfafeff0cdb945598c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4283e5a74a19670e2df309bb81b6175b5b6d8f88a6d3b92b8f36d1c0a1c58e96_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4be4a7c488a283f7d9fbe954be14e3a2da9e1f4ba5ab80900338998fe07743b8_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4eb743030244ca568507c3c67934c58755bfd88e6a1dbfa2ae4dd6e6e5a70711_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fffca33d8e3ba21f2a90cc52d6ef1d58fa68cd97007a85aaf7aeed0c7e42f4ee_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:083b594bd331ba2fec7d5cc42433add53039ffc7fbd09ffe934442b14d0d3772_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6bd6c7091e26263587d25561ad9bd98fe1f5dd0cccb35af8d4e325a5e65697db_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:73912adad11e83491be0198fb6f182ece83183ae7fd699033e74ef64e45f6937_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:943b93d915cba7566ece8ed27c2606df643945a578f7e11d29148eb3ffca2e4a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:400f19adc78d97c1d412105972e336eb486a29d199b9f5fbaee75206cfb4bc28_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:249ceebaa2b02ce15ab132d36db4c0babffa8b783fcbb7e328bec5301742e904 (For s390x architecture) The image digest is sha256:9a4dbf0b6b633404ebd59da5a1d8d646f2693c0aae16ea9d69acf96b4e8494f9 (For ppc64le architecture) The image digest is sha256:bd47f591cf8e997beb46d29c5bbdec946ca96c44ad4fb87b904a1794d03627fa (For aarch64 architecture) The image digest is sha256:ffe299bf20746f9b40431e5edb66ddcfb77effe9389a966c8edb20388b10223a All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively.

🔗 References (11)