Red Hat Security Advisory: OpenShift Container Platform 4.14.74 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:3db659b9a7d3b1331d0416efe0ad8aefa1fd772bbdf99a6b651f000bde785fbe_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:3ec8af5c530e9d9a3c43ea2e5812ab96cb5c4f78ab355739097a597cc5343eaf_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:9cdaac47cae974b3b8976e07bf12541647a9dd3b53f2602fd8ae5cb0e9565558_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:ed02f10bb5cca3c79bc5cab2f061dc76e1bfe3e395dfe3eec83e1e0b8996bd3a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:71404e0ba600a1d933915b3878111a5d780335646fabcd4fc30fa85f147e3778_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7ddda0f3d367587d8214806b0fc19e0477c95384c6d7694a9fc12ea25905f44b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ccc8a26a9da268834038389f1d94cd88494dd98894aaeb95a1b3132955907695_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fe0628d392f270562585e98c940310c348b8d412bf86d420ada4622db56a1f54_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:1d0ae685889dace1614912376fc1ae304a51a92671fe2181c6a3b8061d5cbccd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:5381f6e8c93e733d0560c91ec1187feace60b0bf571c76733b49f0d1b9bd1f36_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:8633df40f5df4734380f37a640b89795f329422ea8ecba2737fc89ffa76c803c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:a75dc62473a3ed8067fb6e15e745eaa3f167e9a88df9b270675996955bcf33bc_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:0e299492621b61aef302de9ae9c2d2e0e9f24ed64700a2fd4108e57febded420_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:79328b818a478aaca064e5370cc110bc6125fe8114f319a098e261611b565c60_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:a70d54fbb44eb2880bd3cf5d841934dab3bcd3161329fc3ff5e5a5613b07cc3d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:e148d8849acbf080e7dcb4597b25f3b4444513f848a625ee3de4246d3211c20e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:1397fe69fefec25b4756699784d5c496e2c1c39d34a1a170341e4e725b85a922_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:296bf9fb57a219258e6cb8154d747a30bcbf3581942908dd68a612f2bf27475d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:b2b4d76e1ed1b270bcd29154fda188a021dbad1ed3d151a1020581f6bf05d414_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:f608f560602a218d22d74831f46dce1ee8e21a2904bab668ca41976473a452fb_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:1d17fe1432a157e2c768e3bec5bd7a7094b3a0e82789a8fd6e55caed668eb515_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:92406d71ff6098b0ed315d63523afc1e322b9095210edb3c338410e2ad9c0d3c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:9c3c5e6f17611af51c66a37a544b42ad0015ca92e6216d01e46f0afc276cf525_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:f98aefff3d5eb4af27814f779c228ba11714f24b2885165ae3b8d4184da9dd60_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:02558c66710c5670039481ac5822c61b6d3d1631ea6387ad8d320370bfe105c7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:1db049bb87113126d262677b1d04578f083405efa0054962d99969461f8be4bc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:37288fb475ff0653ff641025de6ea3e98096b938d2b20991c7e7302d82d01940_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:cb705bc1a52e0d957e617498ad801de4939ddfd8b3493ef876018a67c990114a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:4441792ee68aa3c1e0424d5ff50152e0bb6eacc552fc420e991c3a5f1d952571_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:b2feecdc0ab865bd24a3cc74b3ce18af33f73b41a13dea29a794ad08d99e4320 (For s390x architecture) The image digest is sha256:d628d30f1a484dcc4abd233e100605c0aadd7b0a78d020ce518884a9c3f3ec4c (For ppc64le architecture) The image digest is sha256:e22855f7368879aafe35c9c4be9810475769d40a1cb5bfcd927d96b1cf496a56 (For aarch64 architecture) The image digest is sha256:1c5d2db4adac2b414a898efc13dc8d6e4d2ea8fbf32c63b4a40e2939a50f5d1c All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:67838
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67838.json