Red Hat Security Advisory: OpenShift Container Platform 4.21.35 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
🎯 Affected products171
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:4cc4e8ce3beac0050469e7c49d2788e642e18e9fcdddefd909a4b7a00133f973_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:79cd1d33f6d7600b6e31aa40525662f185e7a09b55b5a46c311e451cb4dc00e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c4719ea66a6e6d84b3dbe5fd7233ea1759279f612cf66b3be70777357c0eb411_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d29b57a6f6a782ed06c2dc9a35062b36ed24c9f73378dd20d4e7de2a059278a6_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:2e3f5872db6290d714e6777c1d31079508727b7818831dad0141f3f9bfd55a0d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4a472156ce7ffb192231fe8b42b136e4bc8d37383aa3b399b3df7a57bbafa775_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:a7c1c829b2eec56e777c9aaca5d3712021c50408974b6e4d4cca857cc632eef0_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f2e982677ba7afe1aa6d8d495dc2f113ac8b06f664e2d4d4755a56a662a9673a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1ebfcfe36431ef0424b3f64c318f5ce0878551b728ff505f2a56d1b36f491184_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:90d438e253da4ff51aa9234c11d529d5af79ac57fce76ea5198b8fe5f4ad0cbd_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:93abbcaee222704b060b894bf613c9b733e3a67e6768b04a18a8eb2e29f84204_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a841726f17f4259b042aee2d326cb7c5b0d38676828f4a880fba3e1c3635e7e2_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1721d78dc1f1f0182a70e9e4bd9d0db1ab614be157f6f7096fea1e5445599a03_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:48e401a931c82b743a4647345a7a3aff95c825f1075b19de2c2782eb729bdbba_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:669f662e10f0d16adadd6df4a493afaa0c9be4b8ee853af59e3736bf131aef66_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:94e71df64c93872f45f0a578f2dab950157c97f54d501cb35d0811e4c9ddc13b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:1a5bcf0c5d6893de32bb9482949b56795d8f970aeb91c0d650951f0538cdf27f_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2dd5a7834c4140888f918ee1f1589d8a4841826df37b03fb19ab52a553fdabd6_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:90005d2785f53603e2c1550a4947d5a336f71f0888ae6ddf722d45a915352e49_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9b6bbef1e99e31045d1688b39ff52a705d04aaff2d7d10467de52af45521610a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:2850f605d68bfad5dc71e4da5de0ba0a7f9f28d6bd87ade5251353bc1db5d432_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:a03d31487c606e7919d8fd7846f214ee5edeec29da8126a2251971991f6658a4_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ae7188fc3f36c269b017e0f18879fe7fc366a488f093d0084bf0dfa0a719c36e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:e1e5b38127e49ff8683d9d94e0a5177cfe94b83301878dceb03dabcbcbf1d765_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:2624da656d0dc8b41af6cd04c92af95ff368beb726e37a15caaf352b24ad1940_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:323badcd653b6e207e5a25c003653f681f71d5ab090e7ef7514b530c2fd5e700_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:503fdab12f110904bc596de9b09f126ac8bc6b2dbe00db255894c853d89b691e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8dc2e4f98dd0de7d01a8f0ca4ea4cb8d0e573852ccd33bfc8af6b0b33e395a3e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:7cf67c95a913aea1e657772ce38a5b89239b21c1cda171658047452236527588_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- +141 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.