Red Hat Security Advisory: OpenShift Container Platform 4.14.74 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
🎯 Affected products159
- Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:322b0c6c27d7dda38b89caac051c952d0ff49be350056cfbeaba8b0d64795539_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:a2a02adc0a6e37b08dc36241511276917d4c8bcc7dfb5a4e0b650c437763fa3c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:c403ac26e75c89b51f039802cfacbf577939322c496ac5afb2cc5b45fee97c11_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:142d4659ecd0b83692bd15fe3bda488bb8c889e144b0161d0c9121ba0dae8364_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:2dac34919680a3f11faf6370d22d77098d7a6ee1c9fa05ce51013073974c97b8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:4bb8464282f221c773469eba72490164ce102ccea22eded49d39d10f7326db21_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:b45ddd56a509be0009d43fb0b2398e859ec6954dafbec034a954b4340933cd3b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:585f31468cb06c467c5cad97a0b43109941cde84e2ec4e04056aa7e4617fba61_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:64ff64d8a293d692aefad62d50d568675b8cc4bdacef2471545cfaa6053afa9d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:da30c46cd93cf3f4cb0fad7645f97312206b8fac9f26b88e49cc4c6458054368_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f520a818a0cea89f62ba6440851a54cf7df7b76f088b8c3d9ed271163a82e7b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:579b5ff65e90f28026ac215ef0902eefa07fcb1b432f8984738e97a5ad827024_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:89b834575c58155054dbf7d520bbc46fbf08a92a6cac268586fa5c409f36841e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:afe4985de2a0ef603432e66b0e7da0565d928b1e59a340bcead199618f7043e6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d11dba499c342194d008783c65bc302ea25db4bbec4bf82ccac26adb7125212c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:85481675ed4b36be52c684dad12cca38617e9b7c1fab4ca200a11313f4376edd_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:896ed527d290bf9a62ed4306e886fc5c8638e9c587c9ff2a227ef5a5de03e1e1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9db589cd1d865afb746752d48bdaab429f69a384f59aaa9f6014b62ea5576fdf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:de50cc2f06d67efd8ff7ba83e23d6563d6ab0fe808e901c05898a48d53f31ffb_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:79fa03e4beb61fc095869f02e99323edb9310d9cb557e6462e28c5e3b8833884_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9a9dd3be9dff40b85249ce8f715928efdbd8098fe54238988ba078674fa012b2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b4bb973c58f3259c0ce84f66fc6a55301858bd2ed3d81a94a39b24ca9cb3560d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d6652454fd887042875dee6324fe5e8b5f2e0408ac0151b1751afdd189997bb6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:34dc9e80569da229dfe976d3d8c6705a17b58b952d521ee2ca7e271c9524e223_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:3559684b0e2f4043e406b282e1a37898c9b05975512a42598b0fe6cfdc1a11e9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:c013eaf019b16719d0864094c3e955886d4a1a5b94449faa88ac548f6785418a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:f551a7a0afb881b623f6435b8b0e67a35753f8f17e42cc0ce371154d392abda7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:588799fa51d1ac23b70d3c7a3e43f797c415a2ac36d5b6890afa4209bb9362d2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:72d15d53e199f410876c47cebd2104cd79a296856d2727b489cd4ea5ef71b30e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +129 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.