RHSA-2026:60025HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.17.57 security and extras update

Published
September 3, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:328a3fe353542541f8d9a4898a95d2df86d38425ec08dab606e5211cc67f9c07_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:52f5c032325142a2a05682e39b6aa40a75eb6a200b0a4e39affd566f7188ff68_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5768c8ddfad6d560c1401ec298aca90c3a2fff84730b54cdc238cfcb89cbc25a_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b4c8abc3f51059b721ad779e69330f29245b592ec9a245b99576acd0f8156b7b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:31b6da6795acff2441bc2d93b028f34e5b1ed5483c278162ab5f3900f2b57dda_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:493ffec38b7abd755365b68111c5fb4c4008a10ec2c8af0a076d09768469f198_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:596b2eed712951db3a28898ec77fcfadc5a43c8e1cc94003c9f21dd3172eccc3_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f2cfefe46da83c7b271d840c2005af41c2e826bc2a5085ca68aebfc2c74227ec_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:6c0041de19ec0defdd48a529df940dac32c2b882afcbfcad6cc8cb83d7fd61c5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:9c12d8aa69bfadc98d4694ab399123c8564f1efcd9ff014f7b02d6ca5cdbc30f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:9f5f22ee3f56bfbf0bbf751c2ba96cd6ee5699bd8f31dd923c6f1ad2863c4293_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a8e953377dbc412dd5be9e459e57080532139e1781f9a8dc2cf230db52e038d2_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:3a25da2760edc9572506f8dd7379d2981b3c69c24b9a465da0a8671ed78c8dae_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4d47b7779c23a634cb5b915d3f98e76e23ad365ed65df845d1057745868dd9dd_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:8c743196801239651f58552a4886421b39cd03aa29e5fe48eae7b2550c4cf9cf_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:8f26026d665cf37cff6f2a64d7860b9b36a59211ff2477252fb923ad79b26830_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5331a2f64101c9e83323fdfc791d70911f69b1e821b28dd4bcb156441ea41676_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7e90dcf4252d53b313cde3b537832e66ff576e1d52bef8b75a49f4fb6bb0b101_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8cb4456347e27d369370c3a7b8d1589c93aa92ce3c1ab71728f737caae9017a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:feb9393ba298eb61d3585a10c730f5fc17fe08fb38fec4d44a96d0943e977b5b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:3ea645d85d613f24b7873b97415150d6d38b2190e56b89f5f5d48a4f0c82386f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:894be56b2f3cb422d408c5e7f6256caddcf9454555a38abafc35a646c2d25f60_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:b64aa95af56bcb2fe8bbb034b86fd2804e457343f4849c750a3c4e26ed60f6ac_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:f0d0d799fe813497b0a0bc2d54d9cfc8c1847ad4211b5554ea7d387df684d807_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:62392f909d9ce5bbfdfbb78e43384d4b288f5c6800e474844fecd02bbfc0536a_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ac6f60af6e19aac5608a6081bf9c01c786dfe1e0ab0c3a731220d23ea4092281_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:e05a648393b03369d0f9ec0fbd2f65d31cb3fa689f2cdd9758d3a8b1e80a5fe3_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ec691e5f094c2b89138ae54e67d9ea97a7e6a8c85c33a2eeae18625661bb2d9d_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:3eafd395ad333a9886c4a3678f25433dce84c7b20e1053b518682ab6b14d97d5_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (10)