RHSA-2026:60446HighCVSS 8.8

Red Hat Security Advisory: OpenShift Container Platform 4.20.36 bug fix and security update

Published
September 1, 2026
Last Modified
September 7, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-66138 — ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0c95fbbcfd5c54e6b2934a8efb4f8523d1536ec1deef78249f4daebaa9d327d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:1b84b2a1cecab16e75947d29572008547922714207272a5dad8169d1ca5beab5_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:466597e63e82ac365414c803f5ecb8f06a72374885eedc5daf9532aad16ac148_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:de9cac5c7ebcf3d43cad87758dd2eb0f4d6480f59bfb4112c224a4497aad9ba7_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4ae516b98be8fbdb9b783345fe680c1d6ef57b5dc06b2ec3bbd20bfdb7c9b2c4_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8f242ba3e0b9c57ecbd85f0d4c1bd67306357c92b53968a42419736c3dbe04d8_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b717614ee549be99c17ceef3d755c66abc983e821e04808df347962858e0da81_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:bd0f90ccaaaa74683b9bb17db0651dfbdfdf8f49adf0ecbaf8e83756d270b590_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:040115466e4f525e9f2386d6f8838c51f8e1638eb06cd64f071d4ae027a8fb9c_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1a677b9d28655390d007acaa656997b12a32e9093c1c228778ef96cc6f4ca875_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:39c68aae39089d044ce992b949d4e9961105711501daf3d4f0ba7e9981920729_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4e814640d65f77818c180a706940337f8ddec8ebe4cf22c51a58a8b69e0f4099_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2831d7dc9f3cad92219addd21b93959900ee2f71e2d988fffe913a6f88dc7e1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:50f602354dcb223759d781cb057b4081a424d6a509178b10674358cc8dba41e8_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6925001d8a798896438ef1388f54bc29825c37d41f2f09a59e3f8bf60b2ec6af_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e01a83cb76fca294a011e022ed86f1da8cde36928096422a440bce8e42fbc8b6_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:757ad9e0c37b861340a7b2269b068d5b0c6355322eb5f5898a856fd9c4495b16_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7f68ff8059ae68d15041b8f38ad5ee5278289e1370d276cf7e78fc7e9fc3bb10_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:816787cc8c95a4a2df1416f09af6228559333e1bb1421ede0c9e2093444260e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f9bb9a184319c9fef278d3c6705f56cfc592c844f5c458bd20bcdc07c4230982_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:198f39ed50bbd835f4789057f9d7fd8de0962f1641a7f453dd90d68b5b2a4e7b_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:633ce875ee7bb08d9bf00cf79738e3e63cd6bf4de2d40fa6860142a301c0968c_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e169d65b86f23d6424af5e7cf9e1d0ced58382128092821676196c0a05f91da6_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ec2586358c34d0130b00a3714b50c8b7bc33ce915aef6aa79eb214d38202f37e_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:13e81e4c25d8c789ca15eb4e84f3fc531a50b4dc0d95fa3573e002e3b54cad61_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:17637f8455e0e17bb3dca34545a26e881cff3e1444af45b9f45c3e282a252bb9_amd64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d2dde1514fcf3308d1469a0af6727835121c4d6a1a1775a675a7ffabba8e3bed_s390x as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d6376055835ac40728181d6f354398a0e60ca131d2fd8f41471ed87e974ea4cb_arm64 as a component of Red Hat OpenShift Container Platform 4.2
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6f86d997faaf61c874def5a78cded319a188c1babbc4dfefb91a29f7e0d7f0fb_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8fcb7da94ab599d7aa92adfcffdcda19cef1f3c2903bc9d38006b7522847c458 (For s390x architecture) The image digest is sha256:7d2df00be06a79cd70639c116c4998f8540b3e379cef1e2cf0f3ddff5188c00c (For ppc64le architecture) The image digest is sha256:e41c3fa52e30b8c9d0c3a5ea531f082c08c7f8832123b76d597b198726a0f6f1 (For aarch64 architecture) The image digest is sha256:2d6b342b1c77355a7c02d990ebf3e28d31aebe9c78a4bccd8ea07fbebc5a0c49 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes.

🔗 References (14)