Red Hat Security Advisory: OpenShift Container Platform 4.17.58 security and extras update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
🎯 Affected products192
- Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:35aa56a2a95f1a16865c01261b9ef810ee6be2693d3556cedb2436e3a79f7365_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:a9b927d1d9f416861245a7f60efe924e9312cd1892a7483c31af2548ea0eeafb_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c64ce8d6ca9e575cdf75d50191b58eda22f1a04edf12378dc90a3062c94acebc_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:fd22f0f24bfdf81baa453cfaf1d64942f076a36dc656cfee8be49f43b56da19b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0e8972601e04f3b593063ab5d66f3810789d596ebe17dbf5a830ce87465cc455_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:6d49dd512b608025865686c4b8dd9d19a9a7e91b7f20077b96b107891abf2f65_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:82e1e240c212dc7f9fc60b1f0f6d09cd480c037731b6f696b896fc5d2a06e13d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9140268ea72dc67d755c783fd068e3cb9c57faa791704d3b8b744a56d7208255_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:24f1bf298c9a517264f2a0c27d3ea857f257edaf7fe5d3f17ca3290c37e68782_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ba591ed93be7c6abd4cc54bf37653ff1490e27b0fb6171f8396cfd97379b843a_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ca4f27c3f797b587fd506641f02b9948479b7ba89d6cc1f4014fce96b3a39bf8_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e44343e9f9c77eea3586c3c27253852a75f86f56c76e478585c0ad452dbbae61_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2d4ea008a3269171b025f0f1f8e00433328e5c33db71dfd291b49266632234ef_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2fe601eac201a0576bbe6269c8ba7df43a16d34e33038b8d0ac359cc0b5f3fa5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9e738a9977296366439883f79b2722fd6ef71227596fc62f2e4a6cc23de833d9_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:af823b5aad55c7962ef5d7fcd29380b6c60c3232988c62ccd7a5faeefdaf76df_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:26162d34050fd8d6edad799f77e83e655047ba2a7883a54f53124758aa1297a2_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d4d8c11674e5577deeafd5142bfa375e638389fdc13b03dcd9b2a0faddc07bcc_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e178193d54e65ef3154595ea718392c06ec26c1ef06888b80f75d47b33df6e42_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e2321a69d5265b4a47b4851d269eb574ed8174e08362f174bdef6225bc9bf70b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:1e2ba6d355f91ad5985234b9a6187955b9436d61ef0a12079dde09326990ae7f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:abccf6ff08457469d9b5bf78f5b3b205abd4ad6fd133203992f9a8a6fcfa9d17_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:bd8ce29a69abfcf5139557505f6c071bbd714da1b18e5c0f79531e2e7d0ec120_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ed80f0be67570bc5fa7f1a224babba042f117083ee4f60ffed24eeacdbfd74c6_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:0d91acff612a6373335c771ebaef4f119b0ddb0b1646f73c35b53a6ef8a1084b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7eb9e3710456f9f9ad8ab5fc3c3c69c766fa63db6118c726eb4dabfedfff21bb_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:bd375fea6b5d1484b65c310dbd3418108f4d3fcb0a4c554320341cf1f6d360de_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ee982b19f3fe24b8667cc4782b435f9988a473a41cdc7eb8828e4a8b099b0d2c_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:4066486a5b755d59b1d136af60cbf8cd521869f72b0e847ebe2ee148a6d9fbf3_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- +162 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:70588
- externalhttps://access.redhat.com/security/cve/CVE-2026-14257
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70588.json