RHSA-2026:62410HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.14.73 bug fix and security update

Published
September 11, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:035f861fb44bf663d80f9997376f6059419c331be0783c27e36f47a08453e513_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:a661792f53d1cf22cc230adcb749ef41cdcfa2c6f37562f58d7299fb4fa7c0f9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:bf6c68ab419c62f8f507700c00d748c9e2db111d0148a0560c1a10bfe5233187_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:dfc1666d554a5167745b5cde28917f2dfdfc60d95c7258b860ea23746e752f56_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ac1db57051a58496ae8336238eba75452066d3ddda5aa34ae9adda3d98a94c36_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c5dcdc1ec193a9449a91070e829d2029ae359bc6cb70a6e00055f09e568cdda6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ca7bef7243ca819294c2b8882b65eb12da6316d267bd9cb2ad13b401ea12d90c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d6424f78e75079f6eb4b6e6f6257dd50c0bba9d13930053570507781bce4756b_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:45a66ab59f933633a2d4c577907347ca285b0b1ea4b4348df0e92e03b1ea9e1b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:c09ca64139ad9a0883ae0a45cac67b951853d035077642998299229356154e60_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:d4ad89f6a68ba4615c908b2ea3153db0b262d7dd8902da1d2641ef28f3fa1a52_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:ddc760e65c8297fc02727f461e57a632e6439da991d9311d90f02095ec2432d5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:770bb312182a37feef7bf105336b0c661ff338f6f2594fc7800fd63a6ea3418c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:831295260321417a5a2610f8ed26c62febd2f57bcb3cb814d60186272e62f3ee_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:ae3498afbd3afcea8c79cbd3543713d61c4b62bc57118781583e6e51e08d3f6d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:d9490792d8c58beedfdd5588402fa311e2967b9796f33c1bf8790c21600dfbf8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:272fae18049c39f8870050dfee117842c3352f07677a91ed18937d41371909e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:335f78e74ffc37565166139daec8ea5f786d8ddf17e5bf6894b4ff4d452ce385_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:60a61fce4d7faad05848d6fa6909c229fba363d7d9c3d9adbeeb5436be9ca5de_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:ef97205bba04dd150a190cfb7d26568b5e53a5322454d8c35c07363097aee492_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:91fbca8d1d99f95fe0d061d61ffa834f8d4c6b238520b8b22e76f4c76bd85863_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:99dbb5a07820124aa7cd415479477a14c050ce6232f015604a064dc9a98b3ff9_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:9bf107999e1d0a95e1fd1e31b3f8baf2a74f81e829698561e7bf0ea70173ffe2_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:da65cb21d93ca1ba277cdf8b7e18cdc6dd4b71bdb5571756502610fd02bc7961_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:3c651118246b3cce6ec0133b8171204febc371e7952b18c51592ae638179e27d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:7c15ab5c9271e110b3ea2298375f832ac980431cbe406c048eae33eef48cdea6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:b56a690fb6e25803b98ef05014b4b9d6d6fa33e82029ef7e6b52ba45a52a13a1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ffa2dd1f68a72c1b76f4036cbd170a5fb7ea6f57573f52270f752232839d9187_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:327aab738b7c4221b1a8a17fe058b6747b2f522683fb22f0a85ccb7b0a7b4229_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7f1b9c23113bc7bdb125576cd84817bcca701055b76452149676770a301c8b32 (For s390x architecture) The image digest is sha256:31179cd8edb0e05a0e297b2e2a4d47b4beab9c6d1e9753a1cbda1bd8e33d8cbd (For ppc64le architecture) The image digest is sha256:6dbedd53d65b4d9cc7973f6d28a9eb905cda5af6c1ebea7a28670c1351977107 (For aarch64 architecture) The image digest is sha256:590c3eaa971d87b59542a8b3f65e20382bf4a140d139e0a6028f7295fcedf194 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation.

🔗 References (6)