Red Hat Security Advisory: OpenShift Container Platform 4.21.33 bug fix and security update
🔗 CVE IDs covered (22)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0303f6ecbcc98a321470c3e26cfd32d863c3059b4c1233b4a1c2391d25d2fed2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:13f4ac433fcfbad3194b79dea3be47f7a377f875e1c66694ab85c458c40ded44_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2777d18a9c9e3b4fcba6b3831a633361dabc3d402954e55e7df118160fc5e079_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a152c8e9e71a47eb28766ee7ca931bb54fa4407eb489507adcd66040c0ef5c82_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1041ad0d39b39f4cea058a92b08f5ed3e480bc9fbb865a48e5fc74a1d8b85029_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:13801182f6c57041ef58c6a80f863539a96b61ef04eae0dca12b10cfe69a6201_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4d20f45865b534d386bbd5f7032002cd8424a909047c5f0496af633d1bf87cad_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:938fdda6c8f53f2640965fa0e6eafec609fb4ebbcb7e9df906743d69d48b76e0_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:188f7976c5c78c40009864ad87daf46244aa062f97bd083f8f64bc980585b142_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:22b7c1ccbf40ac6eedbdf3c54e7029507181dbd7b20deaed47a83293410db7af_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5ba85c26764f5f7cc27f4a63b4d37158ae022df96765ba0b64c0bc27863e3368_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7fb922bb710f8c276feb4a03af649e8ce3a3f2e7c322ffd765fcddff4d1ff3bf_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:229198d5256e2f994ca51c7abab45a34bf81f28952475ed5d8c0e9cf211a886c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6631d9b1dd41068e06f19b854d8a772fb8d6b455a071401c6e7a3e646c98c907_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:93f1b9c392f0c0fe841be159eed3fe5d3bc03eb0071c06621fa9e4dc116e91e8_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:db8219af7398a18a02ceb9eb4bff0f508bdf045286709e8b0a25b5f43fe534ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:05143113b634fbaae49e4410cb7e19ad037e7904b5fcc3aefa17f4d09c8f9406_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3ae10f5219eedfb1926791dab9e8d2643225fdcd36b9fea778984f522fd84a8d_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3e1cd8752ef24eb29d0f071a075df5305dab40fb03a960a08adeb25225d3443d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a04ac5719d45f685de1b9920ee20f76cf7536af4126867c9eb5b6cea37f00814_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:43b652a21efe093d3029a0527de2062eec4fd156e1abf4b87d09896782d16f1a_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ad424cf35302e5669b7dfa0890abff189ec85f53694742daf208bf34a5e175dc_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d5aff914764c333c65e12df2da3d7e369c9b8ce183a0bbe0132a69f1bb669aaf_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f558e9fec14e18b6d7dd337ec5c93faad774bea47c7fa8d97b242624369b3a34_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0ce5d72793241913165397be46839aab0971faae8bfa005c8070dd32372c26cc_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7d5fa8ebd7c95ad20b0dc83bad06463ae7267b2919aaeaca7e43290eea944b8b_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a200981f9cc4d2abe1bf32b75c497048d8242c439687e6d6cb47d8286ce94ddc_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cb205ce9e405910ab1a00f444067842b6d8ed47c10ac44aeb03b35024613944b_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6945ef04130a624358419c9003134c3e042fd4a6abcd35c505888927c4cf1afc_s390x as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:a9be0bcc315021f011c6e01bc6d8392497688c67e8411b83fce0cddec9315c4d (For s390x architecture) The image digest is sha256:421b349fd83cbcadb1fd144d4f48f2ff602a74460e6f8bec3da9d077d8a474a2 (For ppc64le architecture) The image digest is sha256:719ca0e890560fbe7a913eecae0a09c7b1c9fa9144fd690a58ee0225e34b4b88 (For aarch64 architecture) The image digest is sha256:46c1c59b8dc317e9c3b263bd9a7af6d34bd192c68a6b3eab13281e5ce111124b All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2026:66352
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-44705
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-48801
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-54284
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66352.json