Red Hat Security Advisory: OpenShift Container Platform 4.19.48 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:777c8cba98e8ccf3053fa5c072442bae70232020705ca184863365e87dd4b81f_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e46877770eecca2c75ccb141a4e3bae9f0fb2dffba6b51a69c5cf5d8b476e6a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:edacb660e1147047194785ab3d5f3a74bd11ce2ef19c664b873b22a52e753eff_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:efc1fb8d5b8a269e549ff138db8b0fdcdece362940ade1922535a1c3dcee065c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:18c53b55342d14edb6b6e27ee4ed5d26c9b660ec4e12e386627b36873f7653c7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2e2c98858e52fe3ad60ec962e06b8cb2bf9ef10362df2be07a3c02124536ec4e_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:870f4460438fcac3af00f395aa76e1d8097e33abfff3211e764c23c72d028cdb_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c0d8e052525b955292933d93006e7b2415eca73c219a51dd5cd762679d2a470d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:11193fad6c34f579070640197c9cd171f7abee55ccbcae13887dcffec08c114b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3746344777993196b702215104e10e8a2591aefdc9526406d703f87c52bc64a0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a6831db4d9516512e69b8326c92e59808417bf41b095efdbd154a998ca6be66b_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d8b3f83aca85dc26f6d21a4122507dab6ac07d573392b56b31d65268ae310e39_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:29502f7dafd06851e3d04de834a6c482addd54e06dfaf18dc3ce5b0b90415dd0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:34c0f1f0b85c0897730386b2ddfa380808cddc4aa20f4b6d996b8f720dd2ada5_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9188272b499f5da9a02c8019d15164ea60c491dfe4bd61e9628a0dcc70cc1b80_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f85879706636aa8c6d4b3335f07a1b2be446f93f2f5d071d7424cc1fed8c3715_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:01a83d6acfc0b8c7158871f7985b2feb478b0171d6dbed2e76753ead74fd8340_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0a2242601531b4f4cb818c4e90fa6ca0372e922d23c88f956b65180928872f17_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8d5bbf8f1366e2d0ecdf425dc5c85372e3dd428632ff1405e7eab81148868ca7_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ec9af76a8705b998e412a0ae04e1318d2c2545f1dd9f29691172e170f0464a36_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0cecabe346ea2e38857fb1963d990522e378a03d86bc98ec5a618ba5a1e54966_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:971533d7df6935d2f6b1283c65e6b42f0c5f99dc77a400cbdac63c1b09f174b7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a03cb6932d918f730461905f3ad63764e5fd8c53a3932ec58266f0552de2b46e_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:aabb3ba86abda636a6817f3b1e07adeefa905bb5a8a03263552f848f0f244f1a_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:61f703f80f37e8ce144ce4454de59d0e478f5c5ad1d3aca14b46a88861e4cac9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:64cae2e30ab1b5005648a808526340fb373acdf2389bf076279bc4cd219c3515_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9ee424ec383ba8836149c0a944f3b0d29820707494fc4348d583fe34b69bb8e9_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fdae295ab8b2321f998f94804317a02c9ab653fa7a894ad30f14a2450881e4f2_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1bd0237f0b46e155da193a0a650850bc08001722107471083d257e23ebff0b1a_s390x as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:3d5589a4eaeba9882efb93c31110387e755910105f4838ff6c109accd62f28c8 (For s390x architecture) The image digest is sha256:2ca7c9a56b74c80a2f9a50319f331148baf75988a110d0ac426f9415adbc8251 (For ppc64le architecture) The image digest is sha256:45a93008b78247cb4994604e8e92c08b5716a5d3d7dfa1fc036175a79d365f8c (For aarch64 architecture) The image digest is sha256:3b9a364d495a5355e6bb5698e3e9384dfb388ff1ab9100da2de8a08e4202cbe2 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:68540
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68540.json