Red Hat Security Advisory: OpenShift Container Platform 4.21.36 security and extras update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-87114 — kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
🎯 Affected products171
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0c9521ab81cd8e7d6f4422b3d30085b6f2579e2efccfc5b5f7e18ac73dea3bc4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5706671200de29d08f27b25c138f28271e398d290ecb7e83c4625b5ae9fb8bd0_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:806544a03a0b066cdca2980e376e26014b555ea2d68e951053e2134f51fbe950_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:a50cac65ecb71e5ffeccf759b43b1a8e2f5ea1047cb25e90f4c994cfc41596ce_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:15a63e59d25550e41d2e3453b38ea90961432fca91d6d91878504a7e8361cc0f_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:169a6794efa23af9742118e59fb5cf5037ee62efd4875349224e0cf25e9749eb_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:57e1f1a7355c763089e25857f09be8969cc4771de4a22293f80aebf82483df36_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:c268680992020c90c98b2c2bb306b8fad06b8f0484adaf683b1d921b540cc5fd_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:6b4314f0f6c3a9a3336e5cd7a592b10cacfb1f06ab6f19d64a838a1a29cd1ad8_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:7e682ffc35de4b583d0cec6fba22f1d3aef31d26a7e29e701a7020bcf6c7429e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b7a79f33b75e39be2d145e87c7388e5208d4553eab9f29f9b7855ad5a5458f84_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d2439932f1683dae65bc50ed6d2e601f92b2d2c5c32f0fcb442235650c4c9f04_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:17ea68c7efca05e38236876b8a2646f70d81ff2e0d718b9c0ea068735ccf9924_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2e5c4552a6b4cb609ac820112d6bf6b101cdd4d202921fa916eeeac62c17bd36_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9d155914193085331e3d82c2258f3881b571132d9e927aaacc89d0977d923a33_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b870042a6f888872de991c1c97094577b33548bd5121d7d206d68c1441089004_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:78855a537e314414142070f5432e4d9157984e5147baa3873109f0b9e89a1a7a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9a010aaf4c4319a9296c78d676afad002674ba3fdcdb0b0002c29f441bdb306e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b65e6bfd7cb79fd05880d4b9824bfaaf075bcfa1dd5933e594d7136c0c439ce4_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:c198e4368a147b4c688a49ef6828926534d45ab9d52a3ae1e67ab45f378fd2da_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:7c811b94ca9931a3a2a1965942972aec1f8687eb7ef3efee1e7dde856ce61bd6_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:81ad7914ce0806d7120ab2f207f3716ca58004b541197348111d15c2ec6f66e2_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:c52f0813e06f82b2fdd96f8fa6f36fbca0d0bcfb6b5ee744a0f240c1fc0ffe9f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:edcf6c7e39580a1efb480a95a198d7e8f880a098e8e8065f555f163d2e00757e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3fd2d65170b59511aadccbea19eaedde2f32468c495b169ad21eb11a9861b13a_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:53aacf42c92883eedea57013e35e697f1a62f692d9edb50ca2fedc488e5a41a7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:71b098bb7ffbfbb0f7df0268ab9d2a077c17d89367b222370ff11cf2a96a2222_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7b362c01d00246e49cfdc0d17ef693b109df866a0ed79dc950d5386c7397bb4e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:14ef1480d6806c9514fb030b5ec67af3467eda2f0cb505ac50a025a0a01e23a6_s390x as a component of Red Hat OpenShift Container Platform 4.21
- +141 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:74384
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-87114
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74384.json