Red Hat Security Advisory: OpenShift Container Platform 4.18.55 bug fix and security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-42965 — openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-66138 — ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0ffa56d0b74b1bc7eea5425f5c7aad1cd459f4cb994640db888ad5b70ad17728_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:82a5fd64f40698cd80fe79fe94b886300425f810a17c1fbbf59b1f3f03e2b000_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c0e93fa982d863004865ed70e8d13649c1fe1b4ebafe42ec9ee35952813f7c25_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d589bdb6f344404f9f3dd1d9840c305d5c9979ce84d822cf3a94913aef353073_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:03ae54efcbaba162b3e92834320cb4b252d7170f46d29c850525c5b687675d6a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:57edc2ea3f621ad4c55d1e635e7e28d02437a1caa095a6d3d88473178831fa12_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8861cd755692596e2f15a362c665270ae53413ae4936b479143456dcac604104_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ea123b1b4078291fb5c56f638461f77e356ab6ebbfc1be0da0d41888a3b8b8b3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3f405a17a3e1fca58329235e1e89090f8560bdfdc55b5f5a5fc2cf42ad1637ba_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6d6a37e0c05f8823ab2601b9e0b1497c35990b961de91aaf374d96160638132a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ae1704bd80847bc615747309184c0af1900d987708a4fcf483823faedff40ca9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d2fc2ab086703b6ed89d0fef258964446708059a2e4b7a54d32d4f739dfee266_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:349403f206527f01c0f822ad5390ce5886611f8b0b35356cae06d3dc722c3efb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bb17f4ee945bf8875557628d7da63bd50cc889ba451889d6b780ee01beeb4d61_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:dbe535895f9e84c4d4dff10177951fad95ed1bf6b3e7ae0574e803ea4398a8f8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:dc93c8ee67354e7d7b365e0088cc97bebd04f4bcc2325cc10a14102d5034b1ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b2a4737c5dacb639a424fb5f019b87acb5f57094e7ba6b0641e1571c2e56debe_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b5d17d28cc84f77c232afa8d19ed142c2ea96410b537ac7cab7a55d3fb12a11c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:bc600dfdf5bce285c5280a5dd007587178e700dd0bb242bfb0e3a74f1c5f9aed_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:cb695b942f16be2606d4924c082c3c2a114d6a71c32414cc6645ed610e3a4eec_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a3cdf9193e4bad67950df2fe500bfa021695264c7f82d26d297f629c40af1597_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b1be299d677b1d110530a9b606c6fa8a4cffc9435827fdaf265a6ef9f3eacb92_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ec1eadaae92982738f61d09caadd979f2935483084e6835cc8a63c9bd605e9c5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f371dfc70f855ea2c9d74db7fa58187d371d9e5cb57500d520a7681cfbed6d8a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0cabb8a2f46e6f4091f597bba1805be936a0190a94806dc794dbf43552bccda8_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:718404fe1c32212c9d427c2518e90e293cc4d664b8b32ee39242195193919c28_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:7f31061058fabcb701e8a53c03551de8e136dae29f49e5ba6d2505a85f32fee6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:cb6be740479778c85e2099701a832c9b8f401494331689171c263dcf657a888b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:0f4911d3a7ac2b1e6253c81cd43f5a3a0fb9ee5538a8709d84fcd56a489a22d7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:77724a6074081531299a1f3136ade3f5491d252a5b502a4e26e82f2c65213b95 (For s390x architecture) The image digest is sha256:be975cbbdf062e07034927f71324a11d2df4321af174e7a6f655db0051e3e749 (For ppc64le architecture) The image digest is sha256:c9a14d5097f91a7d01e068a15f6899c53359a3a3e021d96bb68f11eb3e73072c (For aarch64 architecture) The image digest is sha256:d4b9d6050c259b416b19a91f3a5b25c0dd48803c272991a723f1a32866da420a All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:65852
- externalhttps://access.redhat.com/security/cve/CVE-2026-14362
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-42965
- externalhttps://access.redhat.com/security/cve/CVE-2026-43003
- externalhttps://access.redhat.com/security/cve/CVE-2026-44918
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-54284
- externalhttps://access.redhat.com/security/cve/CVE-2026-54423
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-66138
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65852.json