Red Hat Security Advisory: OpenShift Container Platform 4.20 CNF IBU extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
🎯 Affected products6
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/lifecycle-agent-operator-bundle@sha256:d47c3cc13acbe6b986b8f0a8526d64d7061675d1884edf37d56d4a2b87acc06e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:a57f2924b69f731d0751e6d3c9fe77612ac79fcc19cc1de05c1c88ce862d2fd3_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:f7a3d8725d9e31ee93f9450177b94abe33b6b18fecf5ecb0fb541117b219c4f7_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/recert-rhel9@sha256:19418b31b820a1820d5d7a99cbe42e9cfeb98db9d344492fc6765b794c6c6ed9_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/recert-rhel9@sha256:2d76b8085c2de21b134c042f91432b820c0c2853776d84bca90a98fe512779dc_arm64 as a component of Red Hat OpenShift Container Platform 4.20
✅ Remediation
For OpenShift Container Platform 4.20, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:72508
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72508.json