Red Hat Security Advisory: OpenShift Container Platform 4.21.9 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking
🎯 Affected products182
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0cf6190ab6237f900f12542ff3b2b3246e2dbf0ddce7a2e976d281a241884c08_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:510be5fe92853f661a3e9fb4f873274f41e266b2471576c2b2bd82b3bc231539_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:845444ba5846416a42cd44cc89fa5c866e91da2dc117e2e478cd424b0c24cb13_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f613d742e04fcab1fc2144acadf82c2e80c53dcb7132d621c68f5cce9b19fd81_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:20153ce4892dd2ccc3633d67acc5736c576e65a05b4c60bdc3dc3ed4ea23402c_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:64dac7cbebc17d8149d7c6aead7c956a4fce90f318b093a5a23d0eba1471c643_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:75363f7cf52ba29de47b3a93e15dda7e2f8c81c0d115193ae9bda3ce384d650f_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:da29b879f9c388c3e80505cfb6a7807efa39d4e44a40e5312d8c4b320370c59b_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:6b83d5c66b5a687a4ea5424b7e0ba4a5c6103ca0aa3e3a92b64fa66c4702ad30_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:91b7a8be897d55e9934beaea43232254c76263bdfecc887649566eccf63eddf7_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:bb539b330e4b0bddbaae919da4312c58af94d35eeba1f82d494e7bdbf1fd50f3_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e840b195d184766308b5355351120865ae3de0c04dcb7c65f844f7c676fb10d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:3fe30786202d31c639e48200dabd6e880f2ec478d4eb638a854f764a78ea61ad_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:6174d8b3b01f7ddf994389066dd8f88fc2c95ff987896ebd6eba9cc0944aab13_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:cf434d1e0afe482c7758c6f16f28fcf0aa022d5cf144a7ac7706762630895ba9_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f06f6617ac70687955bd157a23fbd3e121dc45fd9a83883d5bf341a3ff07d385_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2c45dc46833b6966145884a7f98886af205abce59c13e12abbcdc85ae3e77626_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:564d6081ae8a4571cba271c015e5f1fc1436fbd9f1a03f72dcd2689ebf880b69_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e99f6c3551f7b6d6cd1069ec8df85a4e56a3e3c44e7950de535f785b08644806_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ee19c93c8113d620af1815efc28c11534dd68343c4f6b892b80ecd7694c42e1d_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:77c613959e8d7a202df764c22623271eaef0c8902a5b5fa9d40a9dfd43efe9d2_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:7b812efa52c2831d8ff907c5b70ee00f728d700f1585616896e43fd39eec520e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ab64ae161deca672967b58e5c3273050a6c54d50d44b19164971fadddff74ca5_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:cf9ec24020a453d9027f548c0237008a1bc5e45ccaf1c5cc5a513987de809cd6_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5f92e87b3985991ef4712227c309a955b0b0f13bbbd680331c5447561871b35a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:820af97d9909a9cddfb0d29c0bdb40b8248fc4849d97a84cf05c6a1710d30c0f_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a2c3a87b4012c7d345c8c094e050b279eb374a296d97f67891420aa981abbdae_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:e0f47eb915c27c4df68cec1b70bf1c15640af6d467ce9d40920625a299033f81_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:237c8ac5d46a4a736bafabc1d08f0409e29584784228239cf9ad7c66ade83cc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- +152 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.