Red Hat Security Advisory: OpenShift Container Platform 4.12.97 bug fix and security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
🎯 Affected products191
- Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:ccbfc8f6066c1c18da33d8eafdeda759accac31b42bcabc83e7e7a94362ffb7a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/driver-toolkit-rhel8@sha256:21e454752c187a30c0934339d87c38b4ccba557b33eaa9ed591fb38afb5a61a9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:21fcfa5f8116fe83aae757f5a7f89065fa2fb0b5f6f434afdb4319e30806bebc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:6e25c8bd01ac3068ac5d8e2b5970ec41f176e3b750f422073e0144412ef8b87d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:1614d81ed149dde2ff2ec60a73a49aa0c5c462fe381ca7e0dbf54f4a667e2f24_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:2e2b2a5666d40ffbefa26d4ca2aaed2755eec3deec64543c751a659084cc2930_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:285cd6d488a60610505c25ae3ad06738dccb2296e5a6b22f5d901b96b63dce65_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:9efea34c31f39c7682df25f4a253b9170d1eec59b034ec3140645c3c390a4b1f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:63e989dbce15f54c9a511af48207ed87a3cee2537046f487715ab14595988ad5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:0b7471f6c99a087e4d6914409fea35c46fb2b003780f85ad2359ecee9c8b9d1a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:f0c8653e68d215d116f7d09bc1952d63f5408e1e04232baf09756a3a81047ef1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:7fcc8538f83a93bb4e7a88a8e417435c76defcf431b8184414f56cc506b723d0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:2ea886a42cdfe61bf90a7e70b608472d56aa0e127a221b0bf3ba05fe8c610cf3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:3ba866c72305abe78dcbef9609bff4cb9d09e19e761a6256f21bbc6d01627502_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:056eb5f8136fbb724059282c3ac54ec05f966e5d1129e795cd2aab8723c48efd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:7dc368342a1f019716340c9a7ce5a72330b0f03a3e0bfb874787cf33b8b9ec2e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:3c601dcd2409d1a066fa3eb780464da1ed4a778ffab694602b0679a411d66690_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:4647f7b37066fa3072d83dac6a0e2e87b826fe964eb2f0d75578dadaa16b0ea3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:49a415483a8056c4ebd87432b0732db69af934d1599183dcef58a9398b417d46_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:6b455ffeaa1e29cfc0b898f1d73d737eac2464b5469a0ddb6d915c17890a9870_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:b874a66872add67b0210323db60e8c4125f6ec21c19c23f1b0fe30560353443e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:4d26d0a4783e57034b74ea1d125ef6bf3474e7849ec8c275f824f4a6fd07dbc1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:da73c0e57102e37ad2855ccac0ac5fd625cd72f446bfa02bbfb17cd998083603_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:cc04ade746946b9f3a532c92499b5e04b69c948f0a7df01514c727b73b3952f5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:1e4e00c6c61ac784173107b6c7b616a62bd2c6d686973251727ef8d5d41989fd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:74433130f20ba2ae437010e1c7ee180bd538a7f94bbd9c4e74594f97c41915e6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:5e1c08930032be1e5505e03225b7da9ae042f4ac13d92864c80ab428723ca2c6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:7291486331cf88c22eeba81fd6989fee963fc6800283a4f7bcee6fdac74d9e91_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:67fe1d9a3326b71aedd655a5e4d9b3225498d6ea7e8101a5fcf7914aee9b304e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +161 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:610f344ba2a621c2205f79032b10cf06865ee89d2ad8250e96a8d83b4d49f310 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:59833
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-27143
- externalhttps://access.redhat.com/security/cve/CVE-2026-27144
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59833.json