RHSA-2026:67938HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.16.71 security and extras update

Published
September 24, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame

🎯 Affected products182

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:8ee7b654b346a5ab97d27365491edc08c99cbd1a14d796b4d8cc7143b12ccaa2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:b1875674f49bb063254d5a96fadb6b1ceb59879be6bad3aced290c150fd12e96_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:b1b5e12ca52ad1b20c5ae9f76431445b9539ed98db2f59e54cb36486b8697ae7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:c0325f41e5e0e12db8dcc6b2764f1e2bdc939f5d378ce0a3ef182836d181958c_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:22d14131abfeeaf95b8713eac4d0bef80726c49c21578cc588e3218996598721_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:6288ebd2a4c0080c5ef4999bf6421fe8dce1ba03564b311f29b0b93f2c8f22f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7b4128b62c0e517c6bb166182589961741cff4353d6467b890de7ddbd29f1562_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:852082430422c5fd1da6ee6a58f08b420e57ae58fdb372f461cd0f0548702fd0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3edd0aa0b74c60c6b22602e67baad216bee57d3ed9710767e5e513a953f824b2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:8643c34669cbc04590643852951669a98740f310b734a3121da4185b76c459e2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9ae0aae9d2f4ae10031200274886c98fe412245fb6022f22f81ea13824dd6fb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:dc2e5738cbd9acd4b500e6223e2b16ac14e74a9860b91d8cb2e49c68d94dff58_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:00dedc12004ae2403d6e9a6324df145021c305f87e17e6063f148e03e05f6046_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:101e2ac705a3572e054bfbe12c60a775ff2d8b1a828b4a8b0f76e8ae478f7a67_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:add0b4ee1af498424e4c8ac911af062c04526836c193ee6db49904c4bd53e3ce_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f60c71304a08e2be9b9d52b27452aef2c7b1705d2f0743554ffba1b6c57a6aa4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:01388d620fab1a27f55612dffc6ea2190bf85bf8e807234f87534e52489bfa20_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:6b1e2afc623c02203d486928d100f6659950216d6b5851ad68319b1ec86bb592_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:926c68706caad8c8f9f7f64893778d1cb91769231ce1de2cd34dd99617f44e96_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:c2a704af8275f6d951c33ac97fa028e2f0113177431b8b84066840647b70008d_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3f8c1cf50fd3cea45c24a526683fcc94bbbfe968874fdd6b90e7c5369aa98f78_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:4f94603c4f6dd828474ebb5087c6834d25465e562b20fe6189ae1e70ab28ae3f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5ab17b478ee252c9911a9a25110a3ed5496c15fe641f351841bc398bddd4f50f_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9f6bcc610a858b93777ff633150c152a07900e5a06e50ebb2d24b927ea18a6bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:17a1194271c51fe8d322692908ca1e56efafb82e48bc3bb56f4850574bd46380_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:28f9d6fe72f5679fe9e6f8c55d3f6486e7d798deb296d7bbe6a325197abf9847_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:f09af25a716b7fab8e82191bc4db31c0760a54ed9c7b0221b99eedd16c0b523b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:fd159265ff441ee0bc7aa89f293d7e6f3716f1e79c44a051a4e945c7fbbf05f9_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:590b04bbc806fed5e879734d082723232f1a83f68cc82e424338cfce3e8be3be_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +152 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (4)