Red Hat Security Advisory: OpenShift Container Platform 4.20.41 security and extras update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-87114 — kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
🎯 Affected products162
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:230c0652a5e0b67976785ddcc85a7b57591ed0b80a602dead1dc81ac83c504d7_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:59e04c0f161178406c690f8529c6c15ff7ae264906ffafccf5237aec3b7a3c1f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:aeb963c95a2820a893cd3711fc802a544a877122a63d7e0bb244e9685949446b_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d50551455e17a49aa6db6537b7f0d16e9399575706a94fce729a4cc8bd917d9e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:7224654076398c5387f50a572b74411690f334ab6b73034b3eb5a297cb179d05_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:82f77e9fae37964fe758d2253befdb0692665486bc69bb2735bf736bfc6af556_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9cf6d4a9e03063508410cef90371830827357952080bdc6660eb085a1ac4da96_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:dae456f119cc8df21a80bbf66131c9e94c75aff7aafb7d6eed169e8382cf5a49_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b5e4b4994ea8b703e6a3829e2857a33dc68c149e6700a8a0f80973b49cbc3d5b_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c0079729d7b9d5848e59f9997500f4f0ba002cd84f4d2e94fed425b59152ccb4_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c560b7b8c647f1634a6ca0173a8a16190ce35561981ad96079d8aa8c5082d08c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e1013f786aa65bef93919697e8ed0f3d22470bdf9e74226fa857c2c6571deab0_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:0235a9e2213b505795d4a3eba7864007800e4e57f3e9bcecf1821aef71b6a578_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2e850e8951e2d36e03179cc5de0e7e6ff893c2fff6725cb7d707e6f4a7d9393d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:8aafd09604b3c08280619885b82551383f3e7172a58034c7497125509a5feae6_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:eaa37c85d615a62fd93e1080e0d680a64e90f45e750d21029171b596649e036f_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:05ed1394a60bce12d512e6e695a45a1a710ddfd7df7d24d8596093d90f99b79a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:39e3b384157190326460f619013456ffae49d4a903fb579e1c3a4bcae111af19_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:465999e0a3df45f870065a78ccdb265623204fa40cf4f41b3195b3ea0497589c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e8c033d88ea684fa7949248c231e6c7fe0c5e3d6e52b060a62a902ea2342b34f_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:198c8b86e8746a57b45a778a8a48c02561989a26414e6aeed0eb49e154fc8667_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:33b8d4fcbda4aeb3b9e90868b7ef5cbdc43b680392395290e0f2614752cf8831_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:6fdbb9937d5ee36b6ced746223a373ff07345857814dc9971cde769838e48999_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:afbec74286d22aeffcddd49ddc86e43b1fb2f23efa948ae40501266dc63dd230_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7a9b17ec751815a6f50b58f797b76839fa60f1e361857e9b979eb5c7f6c47a21_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d4370618805d53eed4682d6a673aee90a3956523f4580713f2b35afa273f3c7f_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d46c9abce224d950552f5d842f4ee94917b068846af630658ca038d29ea79557_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:e8eb88909ddf1907af82fddf4639c39b9f4ec7ddf6e6a456d4b65ce2dc4a95c9_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:190e5c29895aa1793aa58d7f454ff15d2b551f712c5d835b09bcaa9ea655c4ee_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- +132 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:74381
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-87114
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74381.json