Red Hat Security Advisory: OpenShift Container Platform 4.22 CNF IBU extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
🎯 Affected products6
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/lifecycle-agent-operator-bundle@sha256:5173c676811cc0986a619000092cc1209fc2bffc43def17d5fc52e6ff86055ab_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:1f0f3310ba9f39479ce297031ba872bc3061b3fb8cbcb82b72767b6475f880e7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:f14f6d96e219538080b9532212b078f9dc2023097064da0ef71afce222b87d2b_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/recert-rhel9@sha256:7a80cb96de1d30af5604f1da5d436621bce45f8743d3dc8015fa92d79acf68b7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/recert-rhel9@sha256:e3ce3b47f0aecfda12aed87c581a183c111c1e747620faa92801bbf73b5d5d82_amd64 as a component of Red Hat OpenShift Container Platform 4.22
✅ Remediation
For OpenShift Container Platform 4.22, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:69922
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69922.json