Red Hat Security Advisory: OpenShift Container Platform 4.21.34 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-55204 — haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3d67796999ba62d5f88c28d2c89165706339810652be625b426aa43b0c063cb3_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8e5a20e5f26e97a93af5c2860851113f2b647c4f8f84b794e4daa3722272ecb8_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8f9ac5d0f7654276c6393d452c9a4b148fae0425223bdd609352efbf2f460165_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:dfa29c8cadbce514c0eefb4d2d3b8ae07660889ce5210f099ca0ca62f3c70d1d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:16bfb962d795b77c894e7bc9ffc86fcc319731575527accac294d5719cc82c0e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:355e3f522a5fd2226a90fc85b903d7ec66892759392632e074540108d26eb6da_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c83ad83198226ca004c537ac00692359ee6573e4d0fdcbfa9fc7472cdd8bdb42_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fd09951b5bc3c5413da95c53b35d088b0538faa553d7c264d3ec7aaddf3b6123_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:31c0fd1c86a9ef49a79acd92a5ebcb4c6271ef4376d45b22895c828fd753c244_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:540ddfd28e4fdd2e1194b82e8b1c3d4b058f8f05f2e352967f689bf49ebdd0ab_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7f240e7e6f7fb964b0eac3421106a3c7c5ba056c36a9880c9268f98d4720f478_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a00de503326a80cc5eacc566d538e2aead5614a1af78958fc9bd023c4c3ef7aa_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4fc45251006d8764653803c502900a49809ce5f09f2f4fa4870f7060d8ed8f5d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5fd0e35d305337cee9a2b6c1fa1fb1530e1d627dc735a43f3933f77a45225300_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b58ee181d5d0401a8514395d25534954f6a200b08ebcbaa1c23cc2fa93327037_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e001e121e8fbd03d90b4ffba5be7785ea25eee448a8f720e4f987c0c042f2521_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:125e8f528a64d7afd1ed3d4de69da2de74a13433c8ba86e78629eca60724235f_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2f7901e659f3f0418226509761c0f5f1c58a6bd69ce7f44e2db574f23a5c6799_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5f595661a9830dc3bb5308f3c02efacb4d433a383b6a6fdd903649a67b367c70_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ae1d150365cc251d5476b6eb2eaef4fc512861dab9965c07243936715cc6ab5e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0ab8fdefaab5724e3667126f54e5c760924d35740eb28088c2251126d38bc1e0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:337881f288ecdd627218d5b710572ee3cb77fb98022fa6f3061bcf75a218a2d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6b56bf6633c6988d6d58a33695548df52bd8d1916a74b0bdaf7ce15748c4f5d0_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:72b1646a63daa1203b9ba2f0a1ba9d57591294ba2ad938ed1362fd30bc0f05e8_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3954a3756accd3adb4ae905da64b542eb7ee3c1b77922af0074ede911a33aee2_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:62a469916d56ae91cae09dc3a466fa0b9a089838c05bae433be7dff0640a2f79_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6771bb1f19967c69928cf7d47e103aa0546550a4b285d0e6ae047f6ed68609c8_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6847f8f1100dab903faec5225249ee9c4d9b44b69faedebe9c94c3f8092300b6_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2280c49a56fdfeaa2ee78c4f6eedd963796f234e7597093b77bbd74ffce801ac_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:c4d448adf37a2563f777b0f2777a89142b3d8f378e28faedf6c312e2957dc1b9 (For s390x architecture) The image digest is sha256:29c5c8dcd9b771828e58ea470d3fe86077e8f86c741592a6f34b46f1e39fb3fa (For ppc64le architecture) The image digest is sha256:b9656fe5d54b754a70d7803c2014a8d674d380be99592923da51f1acd195b642 (For aarch64 architecture) The image digest is sha256:07ff798da7fe914967e640f567387a7c89d07cbe453a06cb1822b1f9677a0284 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:68546
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-55204
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68546.json