Red Hat Security Advisory: OpenShift Container Platform 4.16.70 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
🎯 Affected products194
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:430d1e1a6332cfdf792339390c82fd6790eb07d134b1c56d98be712a1b7f3477_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:903cda0d0046bfc8754eb33db792da295330d9fb6c05e97215d3a9a9c0ab3334_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:d1ba27fcb3a74c76011f0eaeaf23eb784085896f551789bffe47055eee07aa9c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:eaec7b479750b6af442452b932d17d503e2ffb08ca098a7b6273c3854fc07867_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:04d1e91edfc6fda7c2e22714bef6a5fd8cb8296e16a033ea23231c40e79ae359_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:3df47e3603df8d6a818dfec93c7b83decb5240555905f3a77cc5734008cc1fc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:6416cb5de50309c473d531a7721c703a687c1b5184526a9f3e34b8731f8587dc_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:96650478ef08cc116c1998683d400b3c22b11d624e46577369812f979877ae54_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0dc85a335c55ecc4863dee797aa3c07170318f56caa90b290b14462e19f73ea5_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b98b154b7342c77970f6ed1bf052d051d484c0764cae8a2deeecae62d6576f64_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:c1821e1fa6408b9755ff5633a2fc07ff2a4f9c70744a0b5945b6a578506c3028_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:c2748d35adbe8f63f5b387034ed3da330013fc469141e493d675ca03d2a5ed1b_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0364982d11e887d4fb321804cae19a509d6e25a20077119682a3f477aaeeac52_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:6c940f478c2dfa5c340788ffa02e3754b1bc6b58191ea2f54775d372e07d2cee_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:96b1c3545920418652938757ad208fd6393a67efa799352226affdf7a2dc5c57_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:bea5fd1a7663578ed8742ab592c48e80c40f5487defdfd5f34090e789c77a7e4_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:3e8917a857026568bc6a411b3e2162c580576aaed5ddf200577fe464d52a0313_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:64b9b9128fd1210c4ccef573317bc42f464ce47e81bec7eaa14df5aae28f2ba4_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:d1934ee7fa40457337a6ac650c188745ccf2ebb4b96fa127fb9dd7f12dbb683b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:f05c7db147975fcc43452959eed692cf0a5e88522a90c501da06772fae86d212_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:0e304de67bce668a4259a1e5e579f89456990faf21f8dec31e18850aa500c58c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:2fc0993e5cbced7ea742dd95a7edcfa9eb5aa658731e7add07bff35c9d0f0da8_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:4203d0a73125fd8dc782a556944e80f4acf2fd09cfb5abecc9632c435b416108_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:e7b248ad38dd4c67aa7520cfe5a31f819b2431d6b505de3908e22131cec64e04_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:152f7b96e7a237ad7f670c43d66e455551c56aced1f12bd0ec36f786c876cf85_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:77b7431fea225b416400473d97b88b08b43454676aade85ed530c5bf3f59e5f5_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:9ddf08bc13b4b38142573f8a3129352802870805b20109e05cba16e337fb1bf2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:f3be0cd3e843bfba7a36a831c5829f37cc636f40464617d29c6c4d95129025b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:a92eda8fb88285d77b6053a01167697b3edcc551c1740085f522dadee3289eaa_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +164 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.