RHSA-2026:63047HighCVSS 8.8

Red Hat Security Advisory: OpenShift Container Platform 4.19.46 bug fix and security update

Published
September 9, 2026
Last Modified
September 14, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step CVE-2026-66138 — ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5a2c82aac7ace73ca65a5e6c053b5e0dd765556d8c629d280331ea89eec0f335_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:87405eb48b1f464c0f36870d6a28b1ca117e3382da06d064ff4068fb93f5407d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a3bdb243ba7d5590bfb497e7471d764d37ce38c4156c27265784e3394192326b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f8463d596418865808757a01ab2930c4d3011bd75b9cd304927c32f5d77abffb_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1b62925adc612536b359423137e639804124691d8ddb67f85a1a5f3b6fc86241_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2da8541e511b859abdcbae3416faae970cb700e9bcd56d9e8f081905f8ba2c19_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:dbe8ba416e5571d91e798b455a48f7c2dd9419a79f776674f0bc5cb298ce9c0e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e07de0b946ff9197883d30853e05756430f6d4cce935a700244fa3d469a722db_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:015ecd0bb145048755b5031e0441b9740e2d609bd2114b6b12349607ea5588ab_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:214d0c9b8133cc79142d760362135ba61117979214914b4f8d6d4b116a507a18_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:580b9652f31e25ecfcc5ceed25221cc75deda5468828ab44e2bff76aeca0579c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f2af713b18b164a606ae97ad24573e15901458f1b73a95c71e8800a6524fa159_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:18b592463f848152ec7cf0e0f819b65178116589a0e2470a5e1a824691bdf196_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:79df1eea7a791296e3b11a2a08e35c906aec3c79e621bbd5b59988950488fe28_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:831c4f332066e64f31b6baed78d04c181b6f34e4cc83ef0beda4920f6a4c0b56_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9f8b3c4ed6279864a5c4760d617b8119d469b61eabc96897fec920cb1d657686_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6acaad9e96fd3a800164af40a926123e55de92655e0352e9c0385bceb568edc3_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:83428532f5e6b59d7596df15e4c43c6c56aef380f358442d98500250c524c9e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b299c4f301ee41f4fd4a493f7a295761f888ecc798fcaa8c49d04f633ebcda4e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d53e8359c71aa391e1d685cff71bab653042c1b9d6223782fc7acad74a5060ae_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4dbf64722b197afd77dad10ed467b6cd12e85ebab3f9328bef8666c36507308e_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9b072453c7b8ea73587961b78bdefd836b4ab27be96caec7be1abd1a8ab781ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b40bc638df72e624c8afee098bc81f91b13bd5bf3c35a2b3ae3abbedbe4a85d2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:cec32a2719110aef9d10a675764c9aebd286c57cffe0eddb8fda6044e7e54d34_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:432da8b8bdf1c3a8ddda6a45cb21a6038080d15b866f962ab9ae8107ece42665_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8d95965ca6efbbb533897aa60a22d8d00a6e8496994e14132eb9de9b507fee15_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cb2dbd69dca74411eb3e88b725fcaac2f9be369a1fded57579443a1f9f34df58_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e37fbb71f1d144305c15394ba15115ec7efd81b0560718fea7e7f762a01674d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:943beb2dc6998ec9f52feda635aa83419ca34c7df9a6eb6cc917a772ab318af0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7c2a7b3f4b11fb7b217f196d8f4e6a3385beb7c15275b941a27249263c60a3bc (For s390x architecture) The image digest is sha256:689909e6a2fc8eac872a9ceeabf4f9ebf1d77551617151a54561fb10f776e010 (For ppc64le architecture) The image digest is sha256:b5bfa7d60cfca5fbf544d025e18b27fe1d98b7425a9fa22808eaa0b483c505a4 (For aarch64 architecture) The image digest is sha256:dfbf625ebb1addd1234392fad233b882ff5e683b2f037ab3a50bf1aabf1541cd All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation. Workaround: Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.

🔗 References (10)