Red Hat Security Advisory: OpenShift Container Platform 4.22.17 security and extras update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests CVE-2026-87114 — kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
🎯 Affected products171
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:17fe8edabc095952ce5d75f1ccd0462cd5c5a354d747ff1487b9fb99238e2897_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:4597cbaf50210f9fc08ac1590905788da3e0bf88386bee5ed147f99008295f3f_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:9d9da702e2f9b9f692369079fae5adcb44ae803acdf369dea53e2f4b44282bf4_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:efe52f1f811346546235ff509f0185a6c29230caf370224e422bacb2a4b5ff85_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:31355826f45a2585f9cb2301e01b6161ccf33c55ac34795c23abeb587c3b94a3_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:6e0ea1cbefc62d83f302c2af721ebdd5cd8d74fe677d629dca6c9e3bae514a6e_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d7f8cf9c754fb0b59a12ded195631236ed8d10b108589d2bb7cdfb4979e96887_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:fe88c183e40f45e3e95a505338ad0df691673b2b2fc6ae8845183537e63aaa6f_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:0749bc8830f7a58ae86d1009b37a313f62b9da5ca8f3cb1b932c2b8c57533a09_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:75a3a7f6a1721972fca538c4f6f64f21c6baa459f763e3c4679a4bb6e3884430_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:bd8a9572d10300e3e5a0f3953215aae57baf0c1d0306351e37e425bbc641e2d1_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c3410b84a9ea37b79aa68fd3e7a4b2ced17382a20ac3f1ffba564aab9d246d64_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2297ffddbf703f579ed6836d94bf33129d51ae1b75fac00309e4cebcf04742e0_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a525c23f612db02997d5c5e7cee5b501156c448ff705308c69be43ee18ff4f48_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ba2b45f33c7ca7306217214ee9e45b179bbcc767bdc554e85cd733b754761d4b_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:def2cae771d1033ac0be4393d4713740abc3ba351d83da9260c86a138e466935_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:52a9024fe0bb4bbf15f69d00be90a8838d0667907e64b60ed7f96247e08181c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:6cec3bd6d23d5ba72c028a8dea8bf4979c0f461f87a4885686f40061887246d7_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8e6ae4d80583373d3599f320408520134f5d8240357893565e66a56e5f6a193f_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:cfcc5fa8f9d2791fb995f64ee9c931b33f3f0e1499d2cc85177749ce683fb0ee_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:172db7cc356b36b240e489132d6aa8835fed82fe59d633e125a0320e4ca5cb46_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:3855da64515f93aff5f99afe6b7edc2fb19e471071dfa5b663a443a32c4f0041_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:5519a3c15ecfc7ea9212a70a5f2476825f83251fe21ebb144032cc7c77123088_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:bebd523684738d40e4d7a249a3e9f329671c46ebd29f019baaacd05cafa313e3_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8e1f83713f815ace4925ff245ec949aebc153fbd3b0d9e845669eeeb7a823153_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9b8e9b7ea8ddf81e987dfb7195c3d3cd1958fa01c2fb58f4672fc8e95b7a3109_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:bcbd005b26fc861b53bb65599eaa8dc73fd74a8d91abd8b0c1b5b54a32777716_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:cb4c3d76fffb0e4846055e82880b723f6d138a56cc2685aec8b31d9992e70e3c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:4533f792fc06c2d7b04f299f95f525d718f60c54ea7c8dca153a8a9b8ee147be_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- +141 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:74430
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/cve/CVE-2026-87114
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74430.json