Red Hat Security Advisory: OpenShift Container Platform 4.16.72 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
🎯 Affected products182
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:3366fd76971a53355fa7a6003b34d007396ca95ad9b69f31d7e47126afce9ed8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:7124cf66c2049c335dfd2cee54ba9d85857451146f23f9df6d19422396e7cba6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:9f4f310973c637addf1f1c6c8ea506371eec91cb20755c0826253e1de5de5e49_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/frr-rhel9@sha256:fcd9c4a09ff5001912303875c104e8eefafa1c88ca0e3a0ac1b11cfa34372613_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:1223a860d43d75ffaed13da21322a19c9005ed8ade107e42de33bbfbbd7df517_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:1da1cd7af52deee913d2292d16581c7110c354a0fb81baa644b4d951c1cf9b74_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:212b21aeda5b729078e15e6531745f4433c2893c13ac60142c0e0a8ae870ac83_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:3b21087ca86884b2eacb6b66fc71638a3384cb97918b079940c5b4bef5fa868c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:149499becee5ab80c843cc4d73d4bacf3339c2e24306ff5f9c949cd5cae08960_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:21ca15f86c4363b55d91762930d4a2c23d5c988f30ecec7bb898b8eccc155b61_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:72d8f668171ffa458aab375b5fb275696dda338e410926f9130511147f5702b6_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:a6c567c25ebbe7913eef6dc05aa3cca8eab917ad59bead3a545c26c832bea858_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:469dc50fd302f25f35b774ce3b145b4c0f66e87c2d64dffef01f413a8429e0ee_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:6aafcaf43db16f1d6e4007917306d846dadc38cd5eead1970b18ab6533685ee4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:be4c095ae2dbc24a342d6669a2176a7c97af1c2129bdb5e875c55bd77787d02a_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:c2bc7189b4afb50867ae36cb060f0de36016717609c1f1c8272bcd12697c563f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:2b25673c880ca5944deedebbdead9dcbdfb061da0ef8a1da313d99932a700700_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:74dc451763403f50eb13a531d944e0a9c3caf5a9709c02e4e84270e4b6273766_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:b1fbc284b4ade6a4e2762b4aef0a6ed20488dfa5448486917a819fb4b1e79ede_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/metallb-rhel9@sha256:c4de1a276333df55879b2e5e462aac2b41d0460a8c3399cc1496764601730b9f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:1dfd2613a1776fbf78a41f7a07ef159d4fb2dc8175a29aeadb79a09e92cb3642_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:4f6b4c53e4a59282102f074a26be70466fe2f1ea906ead17489ae6cec84bf2e7_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:73063fc4c21befdfd5594aa3617dd9cc11d37820d5d7ba3ffbf5184c15a548a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8415b691d888f17ddea2b0da7d10aa27f8cd07526e67a8b1ea1342c6b7d88297_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:2e39dbf768bfb1e1c9bc89f7223b62d4546476fcd6b4d2390c0c13e1341aa36b_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:70f95e505af146aaed3a34cdab48094eecf7bae6ca71eee9b27a76a876bb3d18_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:9007a8dcf4016048c8bfe90a97f4dfff2161f25f8ccbeb4662fe3b01e3264603_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:d25857cc8a334dfbc286791421d50c763a943db2f644521ffea0a9e4cde98afc_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:9a032bdaf2894d79a080760a2a704a000e3323715143c56cb40d775cc9819eaf_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- +152 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:73854
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73854.json