Red Hat Security Advisory: OpenShift Container Platform 4.22.15 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3711c44cf9884123e6b04f62eda9e464107ae792608afc7d6e36d09491f73c83_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:48add3d936bf299a64187b723f6ea1b0ef1deed8c01494248233c755c2f7c1ba_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:749a8711aa0bfde758359f40aecb14c6d80fd3323b55ad62c1dee047e4fae083_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fa1ecd8780d2a5d28f0c834cdcc1c03dd0f765eaef69be09817fa31adc475432_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:001a5e2df9e4c88c3071bd603028188dec61dc9c3b8b2911bcc314250b5d4fcd_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:689ee2757c53d3e77c75186cc014cdfe6b4770d39cd4c237e316b646b8537777_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:978ce26278e13f490fe6758ed96b0f8a4ff9f3bb2ea3672cedbf2f82c515c118_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c9c015094d1b338a78b52714d0a63778435bdfb23a3b00b0a60c8f8e9fa15881_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:97f476cad9095c2aeb8a326731bbdb94d068a886c7b59b9d183cce2382db3471_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:b58dcdb3bb4422cce23631d41c937cacaae9c517fe66cbf6e3d8666d536c84f7_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:e16562089da376c2048419bb2142bbf5b0acb73ad6a6177b50331fdbaade5c32_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:f6b710a5514e767030ad364e2d4a77429f14613dab541d4149649a1c679a96ed_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:03c6b19f655bbecbcec4c6ec2220f7295051d1681f661458959c70e673aa95a0_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a8a27439e615c6607f724feea84c500a5ff39f3b3b2c08528465ced82a14c3bf_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:eaef20585c92a01b32244bfc3f0259a87c1df98243224aa4db39a557c3eb051c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:eee9a9b03f714d8db5a907fe84763789c18f602baf621a7909c2c608a3377909_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:511a712493f8be81443112a1b96ecce71a0f1aada975bb6f106c3459f7d7caae_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9c188ae839f6fd118bbf7ccf8142cda860e684429eeda897ec6add04d926f60e_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:cd24b48960be9d4246a720c9605c09095b0bbd1fad2dd8fccc20a2e7f4dce66c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:fc46741d67e6bbe8a713792b6267d8a079181f378ae591cf1fe43e8aec9b303b_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1144f18caf99c50828f721601b595120fa57f0e246fb062725e1cee938882618_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:446651cfebe09e0291d9365827f771991ebd07fa75b1ed4e7e0b1f6c6e72647d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9dc8bf8b4fa507f82a1d6601e4b1561fd1794d7d0ab87f3bb926528f4db6b458_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c466a48c8d2257d2d87e94592d5a33de9f9f7a73cf5aad3ab39b1a6173521fe5_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:467e3859929b4d2ed1211f7463e560f3156488a7728167a708cd3d4e4ca2056d_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6454eccf60a74fcbfd1d47fb6bd0a9fe18b56f65d394daddd6686d7ec3a5b91a_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6858e013c676d1685f45bdfa09113028aade611618dcdd80d3e7ba806094b5ac_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8358734cff41a40b487d51afa1639506112371e9613660e6043dc09c2ec68537_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:280efd317dd31bb8d6d65b82ad6442e7de04f4e541d3688d8b4489d2740311e6_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:fed788eac1c99388dd9b78dda4d6a73e39b70abb00ca918d2bb456a97187f0c1 (For s390x architecture) The image digest is sha256:afe50364c608d041972bf00f942c057ad33a66875972c97b1040660943181ae8 (For ppc64le architecture) The image digest is sha256:e37bd8d2afdaa38c6e5f8684e81dbbe6c718a8a40279e27425a9504e09946884 (For aarch64 architecture) The image digest is sha256:866b1865c19a347186a78bf13e369db4810a9b95c2ad8f6d4d44c29ecd15ae94 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:68552
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68552.json