Red Hat Security Advisory: OpenShift Container Platform 4.13.71 bug fix and security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
🎯 Affected products192
- Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:2f8343e2328f9c3666fc3539f8dfe4aa133ecd76124b5e2bc70ca53ceda8babf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7ba1f7c0a89394fd8454b90d841d3e2d74c34a47fd0285dae35e3772b2d45986_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:8f37c92f17f87c41793ee8f5d8fa9cc79d37fb0744418717cc646a439c19c30e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:069e0f1e536ebe9a953d6e69161cee220beb15ad9f65e69e5fc5d128bf1e9a85_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:ee6479ad3ed24f2c1f7850bdf7a9f9939853f64f8872111ca11156cdb659794f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:b14d51200fc95f91e8656dbbecb97c4116cba1de076faf5b1a0e330cebad3d96_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:436d6a422571a1ae5252fb4632b98e062bcfdee03a520076d157f017b2c7c16e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:fd29d7508a80951b5c32cd184cd3e059ace11186cb0dbfd87a3d0f2d703b8622_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:b09aa46195009937c272f26a8c1b4dba224c01c479deca05564e0df776dcbbde_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:2ca8eed4c541702d7ffea93d39c8975dc624f04f7594796f7de189cde58b5db6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:ba43b811d163c10cf8ee10a790f8cb68f510f7cc942fd166d0853060c117285b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:ae6e980d683aaf6f819651a18bb3c3b6aaa9fc9d7f7e2859dfa449b3be15de75_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:f6d44adaaddad0a13413c8075455ed237ff3df329a777ca489cdc43ce2fcd791_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:00365f7f30a025469b823654fe345f2c145de0e641cb5b27a590454e198fe744_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:30bc4c72541b11dcdfa2a91e9e572658986ae2cfa392f667ad3c9c27d3c91f31_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:1a67bb5869082d2b04656d078f648a895cf32338e25f530efa7185c05da214c2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:459b70732d2d6fd1e0f1340d49af3b77593e1a5047d68b61a4f16e8651666275_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:b521f8bd8dcd00f98b5edae63cdf400649e63dee8c7aa7355219995af547ae86_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:a36b09e14af295b1fc7f58ec347e7757e0036a20aaaeaebac1b45c9e8cfc87e0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:ee02570b3f9886494bd90b49a731db51ccc41807f62030cb85794bcb37fb8d82_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:fba2f2bcbbe4986da059965bbd388dd24da55f702f8e919a8f6882096289fdb7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:7545a380208c2e67955b04eba5df7d6fbbc75c280481850cc4822be2fdb60770_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:b9bdbc08e7a71fb352188f73c34f1b0d07d817efdfcfa29344ced6e2ea6b8c93_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:7cc5de7dc549f41d8798ed3650e7aca86e871f0b843acbf53375f1f32096f80c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:30731722b5b66e912761e7f4c391076331cb7fa5f384866a9d66b63b6c4b2573_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:55603b9682b0d33db34a7492e9a34c1841afbb4a9b6a434e54ef163cbc82142f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:2c892f30ee01a171c30bf1d94f0821fada9095d65df8fddbd8c28fa90aed6909_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:542e9b4ada9b64284180de39603b15d21ab50e067b34fdeb8e755b74cd6871dc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:8ed02675b1f93d08ab9b056df952f0eed8f6f26606e4f6a17246a68bc73f7cbf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +162 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:57d3bc54220249ddc77cbcea17171e0240fe2c6d8be3ce83865bea30950862cd All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:65840
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-27143
- externalhttps://access.redhat.com/security/cve/CVE-2026-27144
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65840.json