Red Hat Security Advisory: OpenShift Container Platform 4.22.12 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability
CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:07716873e44d49ad177f8c572fe54cec7ddb819a70492e6bddf36ef2ea5e6449_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:288bb644cbb5e14b00d80e0b409c83644a59cbcb513d19025f8b97de61f2cbea_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a27a41e1a167568dc9bcd1f125ac624897d73bb6dca7be80d256432b35e4c6aa_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fe9b92e8a052208c6eeac2ba816959ee8129cc0f68bc93bb0a1a2f940a49f4d8_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:44ba1190dc20c3a99259ef0723be3c9e1c2d4f339ec4eb4f38a9375cefd60d2f_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:48a700617f0d4ab9dd6b40cc27e9f602892037c10872c19c60f62a2a848e451e_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9319978cb44eb1f26a7d82709c4ba7d9b6b0bdad78c6c6080bafb0933103bda2_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e734fcb9ca41744ac9213327a775aeb0e01ea9974036908721b532ed2dfef923_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:10097712385ddd416b15237d2af20f86a0370f1d97125f1e8a0d25a7215f6751_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:40f8f7e1d72a0e70d96c1ff028cff7125ead621e89cf2f3c1cc5262a3aab65fe_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:50ff72eded21d210ea9c57c9f9b192cb6ca5efe781c5c5a9d2e1129e2eb7a248_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:f77b14655ac6137b53212c8ed526d6baf86d6d6332513416daa73a6dc468c832_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:76042ef2dea9a9316a7bb2a38923d0b670663803c75f5b8351b5e71d344b479c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a645a364226f6768df30645c15ffb8b7feb1932a96c3666cd2d8bbf71786fe88_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:afc4fea57ea3217712f10421cdc7ded66093dfd0d5cdf09120ec1200d696f332_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f70b291b3be37bcef36e4cd282cbd88f917dcc5e61e0ad6228b33b770656b8ca_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4cad4e954d5e9fce7e93ce3a81da34d58e01c38a5d6140cefa7eeeffa13e1431_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5c1598ad56e3f9cf5801a990b2d5d007632cadc69118dd15b771d8104893b722_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d18a7d5884e709f2440b7f85999c2351c0f74ba09b876a7c915a974ccfa3dea0_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ede11c7678a732b9ef9a763632c13e616a95cbabdb36baf0c5c48ca0d476c260_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:208703e1b4c8fd82b6cffc790affc4bb8966f6d95e5b5631d9fc7cd429d82242_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:40be47b6d5dedb587c54ea5f6ee763dc3007284e85cf75d9f48f4de83bff4f0c_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bfe783bcda48a7678e776f99ab08f9d6cdf882432ae03c46593326bf8b57e714_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e43bd0884f4c1993cd516c3ea52d1f878a783f6a998a6dd3fe4a98ab11bd3e87_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0492b621d90ebddbab300b3bcb6979598f11380da79b32531f8978b26fe5edfa_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2f4ffb0abe2bcc7b801658bb46ad9f397d7a3d11e8b2060859f5dee1625d7ea2_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:30b0e4f82db1f3e39379b7aa792514aa726a0c485680b67351c593542c1b1127_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f0f3b27621a9276b1f4f9601b1b399eabbc165d74a4b4a20ebbccf6a36a8f98d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2d56871f80eb82c502cec2b901d3510ab482eea981f50cba4fea729c83f1897c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:c987c0017b86a5aed02d5fa854b4649039e7221e14fca2e824dc37b2937ce7b2 (For s390x architecture) The image digest is sha256:e38f225c850f6fdbdaf6ac3ef1f762b1e7068da19ef3cd57a00f72554e3d0a72 (For ppc64le architecture) The image digest is sha256:ea726e65a0f5f8ae5b5fe4ce31f2aa75943c893c91bd75feb644c4042c88865d (For aarch64 architecture) The image digest is sha256:ab1d1b8e7b22fb2a6b3923e6e8fe77b8f0f774c762836a07542b7ed5ad52d86d All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:60441
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-48801
- externalhttps://access.redhat.com/security/cve/CVE-2026-54423
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-73566
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60441.json