RHSA-2026:67858HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.15.69 bug fix and security update

Published
September 24, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:10e6820f5fac074d68b96feed33957f0fafd2315dc0f45930560d37697fe614f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:1a3697f7cfccdc0f3e86ecf4a471776a80bc8e565f9e0d5e7a5d0dbf17ef6671_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:9689b7d5accf536614b4db1a34472bbf205573cc1511130e7be1ce04b5da8541_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:acbe6afd9921450942039c11aa08612cfe9a31bc453ca60e8c43a863fd89d0af_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:30f3d885c32ee9cb448f661bc8ed2b477fbddb8789b99620ec71f9ff96f8a846_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:46f1f8a2e0bcd8f75c7c2935ae4ad474f864820e33bbcf886beaf7d881c4cd15_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:804ecc1a8f62ed2d1678b4ce7c90abb6e1a9667c887a6fc9a1e5d76f4729383e_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cc7fc667d91e8a88bd1c7aabceffa5c65d0a6994406836e60a6e862db4905ef4_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:0ed841b57b328d98b9d26b56851938674e817f8013dd12694e016ecb4538223f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:a87602d09b9f723d3e948e262a9a71cc16754a915c14ff93bf91936f0af69858_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:f9eede97fe75d33f1325df72e2730491216fc3eb3e95b57a5d8ad1447008c367_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:fa98614846ad08585e6692d57c1cd8766d9d0b33f45b9247f8910ba61205515a_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:2cc6118289cc15488a74f8c1d38c5371ff69672df0b5d89e3804ca2278bc0e73_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:43528a5404c7021147f1b5419dba92b98019e367f76186873f2f21e8e1f63720_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:a8b278c593b04df575c0825011192be01cceb6b0e41b5761cad6beec3ce87c87_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:be05bf456f915f1529641a1085e02b0d6409f8bdd23955c0e2c4eb2a3c5f8679_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:3d86fc9764db409792e34c735c14f43fe12901b18f0ae7e2aaa7e96a6448bddb_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:722771deab912c56d7a2b7d558ffc6f341a0b09f29fd2b676c33bf36d72c9df5_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:723c35f7b13cdba90af09cce85a5631c68d7ea942c12597eaf0c4d27f51e9127_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:c75676cc37393e74aafe18cae85c9fc324e5b1f8113037cc003ac44d1e94c47c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:3e28f74c0521fcf900192f48166f9b0c2776ddbf645d99601352c950efbfa299_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:5ab483fcb28f9713dcf1e2070c8abe9f30b83c7cf6dc16aa1d74701e74a4abe4_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:6a9d997737fa1b25f8e81d4a8c7f54aaa8531dca8b4f2a3ab55fd96086f165d5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:e8449c7c802c56b57df26e755ebf1a2a1a7bf866c12aac0e8633f06e132200ef_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:c4c6cd8051e16290472175e49eeb8ec9c63e054859781401741e34d566eb6f3c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:cdc8148399f22144960a778cb1117346c9ad66e8e7c70e8d5fd5349d6690bc28_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:de448929e359d6714e6ad7ac49fdb3f4150bf186a07d2eaaec922ab294f11b4c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:e83f3c23f96b06ff7f1e5620a7d60a6967016260fb98aa14343d196b037ccbc7_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:57c000f5c483931911f49724bdc7512349608a6fbc2ca2b1d9c55d37327da71c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7d339a1a461033ca021f645a6a0b448808472d7cee184e5fa0a9ccb34a8b156d (For s390x architecture) The image digest is sha256:bc2c70de0cdb11ffd7326b5bf3d514ba6c5e4707f49b0eb78e49621c9f96d318 (For ppc64le architecture) The image digest is sha256:bedbdbf3fd7f532c1e035969707d04271c0b9301d6c781d034608f382a11ba3d (For aarch64 architecture) The image digest is sha256:bcd6c0914a58c724e1c8f2b7f7ecd10cc6bb20ec73cf960700bf3a7faf2f308f All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation.

🔗 References (8)