Red Hat Security Advisory: OpenShift Container Platform 4.21 CNF vRAN extras topology aware lifecycle manager update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
🎯 Affected products6
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-aztp-rhel9@sha256:95690ad16cb4d081d0d0af88a8a33a553f35e8d4dfe1ec2f55bbf0c2c392502e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:4863996cc5f162dbb77a43fad7d5ef8f336b7e3fb04812c8627a6b9afd3d52f4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel9@sha256:8cdfbdec8dee91b2af25912836abcf5a5794310c76da157f3f75c77ed64cd4a7_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel9@sha256:17b0b3bd5afc97514098c89cf11569394c0becfe92036af0db215b0fa7c16c56_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel9-operator@sha256:91e3048be60e8a23c83453e130d2c2522b37bf0644a4f5fe548be4abd99bee52_amd64 as a component of Red Hat OpenShift Container Platform 4.21
✅ Remediation
For OpenShift Container Platform 4.21, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.