Red Hat Security Advisory: OpenShift Container Platform 4.16.72 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:02a94f2e4ca380b9f14af861f441e9df8f7a855db56a231ab44037a5c04373d5_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3be5faebd096af5c05cc0f9d4a92ff0677c71435da61c22915926c12aaa490e6_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6c044b78722528cbfa47bb330e278e77270905476cb742462e67c1078c2f48c4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d1771611e7be18860a1747f7a6a0d45135665019d967c4920981558b0a5ccc9f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1474aa69d8b5bd765fb7a176cc23708524a800fc6c26c9335bce041619575d5a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:aae022c4a763634d1e3329f59a18c845890e2180f9075a3189ceaa30556bbe5b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d96e3dbbf07bf38a7cb7ee52da0d47cd949ae552ce38514ac0e6b27be0e7aaa0_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:deb602ed4b7994fd87275ba32da2485ac763fbf8b3a06133992ef4e04cd18353_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:20dab4e73c38fc87230516176f7959dfd7b2bdd619ce4a0e62b146a5cb69a105_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:733f3fd57b7ecfac2608d9e912861f47f06bb10f2a0e81831faddef98fe8ca73_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b321fba5ff91a756f517755b2331701be676be7df25b2f74c26022b91e748ec2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:deca1076e241a9d68e712fb3e3d32d043f8a04fa7c87b269b3e069038de9255c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:26d49beb3a10973235208ae2c4f0136830444e417e27fa327d2f450b07005c95_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ccaa79ab55b30525980b1eff347b27682b5b603c9b37fd6fde31ce990763aff0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d5cf091ccdf5966fcfcbab67321f670f99753548ed174888a35557db07340749_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ea6e0c25fb9431196a6f1dbf4f02496622169d9fd8ac2bb44c678e1d51eb593f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:35a702f77ba988e07d2ff223cff26832728fb918d3eb367430e756d2c1ffaedd_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8dd2e2e37deb64e3d83380fa43a35d86d051b61bd61e0e5138bd37680e4150e5_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:97aec152db609afdcf84fdb8c52dcb11cf4c930a4107ee96b74dea8f9eded480_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c83b562256615e0b9fab7e6ae2b6fadd163f0980ed70273956da5cdd807e8543_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:05a0d089aa725671f74f9b73b002c8d924acb029312c0325315e5d1e32516492_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6436676177bc21fab5387f76c65ffceb77dfd8f985b0a11964292c288797a948_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:9123810ebf75406d473d30d30581f54e0c07c3bb3eda6cc29948e3d7898093af_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:e37b4787be72feb35b213537ce3e2a56732bbe145f1f96dd3afb4aa5413b60e1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:94438db108184685df8f4174b8fc44a011979932e434fb99637b6ea806085b0a_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:a053e142d31f943e57dd534a63b02e93749e37ecf39ed463730cab589ec0409d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:dd8d1437473a1148aec3204d109627b8f06ac15dd28bf022aacf0f980ef32785_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:f49e23a2cdf0d0248cfa123b2285d9793f4bf49cbc23e9b34fab228b4f49bffe_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:2e531bf100ce11bc723cfafb4b8699c8a23efd8dea70cf0aed1af5df41f15320_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9cf7596b1c295a65f4b38d96f231690661869f496bc30dd002f07e31aac87f89 (For s390x architecture) The image digest is sha256:90ac5292f633ef445d838bf363b0b93328a7e371e4e14762764b71a868b2bc6b (For ppc64le architecture) The image digest is sha256:a2326dc17aa9a3eb441e509fba8485e3f7e28a9c2515f5c85b5b9fcf226ef5cc (For aarch64 architecture) The image digest is sha256:71f6c76d872323fca9ca822a86b3bcba426b13c5c7cd1b02fbb4c7bd0d389610 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: https://access.redhat.com/solutions/7148487
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:73853
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-75885
- externalhttps://access.redhat.com/security/cve/CVE-2026-75887
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73853.json