Red Hat Security Advisory: OpenShift Container Platform 4.21 CNF IBU extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
🎯 Affected products6
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/lifecycle-agent-operator-bundle@sha256:c405c11881efe85f77c5d1075f10fadd210bb67f816fbff3b64400ff70bc4bf0_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:735cf4b4fc6e380b33e32e7d7e9b8e8f29c3b08a076b8fb58b98a676ddb981ca_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:74fd5ca457674578f33bed12b6163fa035c46c0c3ea40311a3b8b23929f3ab8a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/recert-rhel9@sha256:74982118038177ee3c1dc9b3448af08aef6869017a6204a9d4e88b2bc34a553d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/recert-rhel9@sha256:8b25bc9b7e0b1cf70b5e031e8722bc682cc1dfede5c2fc7cc84b6ca70de4bafd_arm64 as a component of Red Hat OpenShift Container Platform 4.21
✅ Remediation
For OpenShift Container Platform 4.21, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:74023
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74023.json