Red Hat Security Advisory: OpenShift Container Platform 4.22 CNF vRAN extras topology aware lifecycle manager update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
🎯 Affected products6
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-aztp-rhel9@sha256:7f11ad48e6abcd95ea358fb71495e3089d13de98d2b019fe5ef8faab57b46410_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:f3360742b2908ae2235f37825a953a9225d044a57e17098e1dfa9996a3a9948c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel9@sha256:211acee7beb4678f08d5bd1b66e2fb4c194f272e3bb1fa43c75f0ce9b61f948d_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel9@sha256:128f9922ec17660e00030388c56922893e1160a53b1ddb16123bb69bcf5e6919_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel9-operator@sha256:7169944c3af3e9fd9bedb7a6d3289f85d16b72e5e10b1e07a45d4d5cb581c279_amd64 as a component of Red Hat OpenShift Container Platform 4.22
✅ Remediation
For OpenShift Container Platform 4.22, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.