RHSA-2026:70587HighCVSS 9.3

Red Hat Security Advisory: OpenShift Container Platform 4.17.58 bug fix and security update

Published
October 1, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-42965 — openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-66138 — ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75886 — openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:147c595068c03a2434640e42a18e6c9bcb1cbe1626af48d4156491230e2e92a1_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:267b680988ef2c8da5338d87483a2569d90010f724652967a8cb03c4b2c8f7e2_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8318ad4dcae6a211df04b098c3bcd99f553dc52bdc264d3783bf36c7d1ae418b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f286cf12001db8b68ee6da9e354630a82ffbe86aef0107f900adb782e67af995_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3093b6a892b927ba909ac017d547735310f148fce204fb33abd88816a25244af_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4406656e69a610f95f25fa13eae650fefadaa3a03fe13b57bd136994afc181eb_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6c771c8ad28e3678e58270c418893eeb718ab7845616a143ba0357cfc7cbd138_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9ebc19a116c2a7e968e53c18766d316ee36df731819a25a829a9e5b47a24b75e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:26360eebbb5287956498d150242f99b9e4edca4385b93e2b02e5ba0866e9678f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:432360fe914c8d53b315d39883b34dda25115e46c9d58df8879a532190d81064_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:81956952d290c869e154ec44f7708ec52930f2ff121d25678f677deed944f25d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a0e656200ec9a5b3caf9a5a045c52b2d2e98999b69035cd75ae2b6b02b5ecc9c_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:270145dd448aad08e900c5126cb312f39c1d43a0eaa53664248bd2f7df23cd02_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:645f92b4c0cd2278f8bc4c159ac791decf6f29dc72db36824106843737de5bcc_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:cca3449d396faa66a0406474f4ae2de43c8e47891f3f7b0f2acabf3a53ecb83b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dbfcf0e0e651e3ddf8eff7c46967ffbbde58b616102ea12a2edad1de5860d8ca_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2b94d0f13ada40dfae11e266c8b361b59716e86d7f300de93b9c1d00603dcb06_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4dab22c5061606368f5741cd8ea742818d499963fa5aac152d3e0a2a2b9a84da_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:86938399d93741709be2e69a884b9a277b527cd8e72f19ffc77af51e44638913_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ea4681ffb09993a07b0655782c2a6ecbc545788daa2761581bb12a6329bdcbcb_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:01617e470cc4602a0f988399ca53cfdae2be166a77e027762611fa966070c666_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:284e53fabc9492d0fef6df6e94fd4b38ba7cbd6af13e02cdb8273857d79d043c_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:b58a5ec6f4081a92ef10c08b8de5fab4b255b91f6a63448c795851608ee08849_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:e3c60a822f837b2dc2d2377b2ec46f44bb6a544ab2f6232ba415c6568d08a743_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:00e430e0b08c30c0e6a5c59f0b664806ac8243d2e1734c7ff07216342e934718_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:797ac441bd0e38947ff596c45b7fabb4286ecd6c79941aa539cbd19156815f1c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:7e4cdd7c5316320ac4a7ab679eb36aed4677c2859950b8fbe42ffe1bf9dfe72c_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:ecde1e07a3827c26e62e1eb0ef8672d055a55ceaa4e5c97362681297b78c74f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:052e2b9a96ab296c50f4225e36ffd233ceed95095213aba17ae445858592940b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:027c19a0057cf115fdf33dd8a018a9f5195842afcd3a540e8dcd68ec398cbbce (For s390x architecture) The image digest is sha256:f1599fb9c86085b366ddceda999779fb694c0c9442251742c1385e994c4268af (For ppc64le architecture) The image digest is sha256:36544f009e7f95a1d7bc77dc47937abee8c7c4cae1634503b02d5b697b869815 (For aarch64 architecture) The image digest is sha256:79597f64234864ba104ffd99bb4773fed1f6f0797c06f84583a0604119649046 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.

🔗 References (27)