Red Hat Security Advisory: OpenShift Container Platform 4.16.71 bug fix and security update
🔗 CVE IDs covered (16)
📋 Description
CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image
CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-66138 — ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:12260e92c0b3611daa54e4fe4c3cb01f0ff7a1f7e5c37be9b9d751abcd56ba35_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:46f30cdcf198483c3d9f1dbd79b426e2081b7bb2658bab395bc0a1692ca9ca42_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4e96851f8b50446bec88435d7aeb14b92465d077b3dc32bbd2047d2596ddc62e_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ab60cdccb286b6291a8940cf6b756898b0f619aa9d9466721548c6e75f214f10_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0c1cea8a388315db184b2f2006060b90971d3b7e5c786eadf2babafdb8fab256_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2063ece867e02052d283f20c23585bcbe480b57b6b255d8499b3130a3430c438_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ac21075371cfccdd4e68267abf760ed53955ae2f12bb30afcc0e8bacbab5fa27_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d296fad352fe00eda534854ac32a6ad2973363271228dea66014145b835ecde9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:281e317e8b913dabca84ee18e182bb11566f30e00561fa5990c67a450d08acdd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:54cdb28de5f15bfba03a5d009db67c9eaa8be2424af57fa886f2c45a91de093d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:76f1552e228d79ad0d4dfac7b769a54f2d8ed752634c6bba70cf079ec891b035_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d571c72f557cb1d88b4fcb53252a34a855c6e2d1ac505f5d90fcc4f1587e436b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a201c2b29a3dfe2f6ba7e9b9ad71660f0883e75e5d533056a7a0009c482fe456_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dab7e1b05ea35b55d382bc99a73f537e6859b0b627a13264f02959573df4ab5e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dfffabdc8a0f04254ee1eca2c889895aaab8ec487aa954f8b69d6b37b355d81d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f93bddfce888b4e67be8227394c792330aee5344198bd2efbf48a93471e0ad92_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:37a8b5f5588f6e44bcc6700f8cfe7f5b5b8f18f4f5d706bc1a2804e1610f2154_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:553ce1f95c82803481c05a1d5d5c25944fc1d723ae6abf26db5476c4fe74bd66_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7768aa3e6ce16fe598323cdd51a3ec9d0c27ce4a005c649cd6853a96cf1e26cc_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e5df78f7eaa3fb995541d702ed9f80ab8b9fdd3594e25adbc3d49a48ddd8fe8a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:4da968f07a3be8c6bb9f2c586bb31a4a6bbd1b35cbbe970620327317dcb8b9b1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5db0d7f616aaddb2c949b745bf7da4719eafcfcff599a9b035f393041ea49ad9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a9a5e7ecbf8dede9ed8d40c49710a3f72519a35ebc58da17a9a9b37aa34e9461_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:cb1b38eccd46a1e2d773c9da00e0c943e5b763353ffd7e7f14e6c340e3607109_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:1540b9ce40dac27265dd9264eb0480c4386c56c8fbfd18a25bbb8e916816bb94_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:6863d7401d1fdfd661bdf878d1e778515aaa2b3736bd1a4ff47c89a6819a1e46_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:8c337a172f08f412bc3750bbcf5355a0c8e8b2ebfb6be07d99056d38c15b3bb9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:d05b1309c997a39f43f33b64df3c0a193662a70216875154d1b532c825894656_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:68fad2ff13ee5201f0d288647e65db13d98584c64e5958c587ee22de5403861e_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e8d2a7b9f0565993f40582cdd56c27672720917d577da9b557ab11a554a71824 (For s390x architecture) The image digest is sha256:ee3eedf869e038de1cf4875f01ea4d62551a7be850fd796af1828d925d1029e2 (For ppc64le architecture) The image digest is sha256:b2d122c178ca0783c1477519ebacbfd745de5a63d3f19a8593132307b3b5a649 (For aarch64 architecture) The image digest is sha256:bf9e95ecba75dc376153b32f6278389d2eab173ac661b47f09241ef3af7d8c31 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes. Workaround: Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2026:67936
- externalhttps://access.redhat.com/security/cve/CVE-2025-30204
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-43003
- externalhttps://access.redhat.com/security/cve/CVE-2026-44918
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-48801
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-66138
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67936.json