RHSA-2026:73518HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.16 CNF vRAN extras topology aware lifecycle manager update

Published
September 29, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame

🎯 Affected products6

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/topology-aware-lifecycle-manager-aztp-rhel9@sha256:6058b015262d81c72bc03e7019f578655400380f8430f148e3db468b0aa823ea_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:cdf9357ea92aeebff699756ef6f86efccbc711cbc978d47b17162fc9aff0dd9f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel9@sha256:e5bf1a6046bf34d38fffb70c18ecb2f33ccd24d0df6ddc54e1a5870e043466ae_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel9@sha256:f71ca33b9c7fae140a713c45004f78c9b618aa381b0257da15a670839b1a33ce_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel9-operator@sha256:46ad3e89086e605cde315cb75c0e67f16c368263361af18b7276913274ce642f_amd64 as a component of Red Hat OpenShift Container Platform 4.16

✅ Remediation

For OpenShift Container Platform 4.16, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (4)