Red Hat Security Advisory: OpenShift Container Platform 4.19.50 security and extras update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-87114 — kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
🎯 Affected products170
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0e61e4680793e3c2df65ed27dc4eea722bae71d2710d3e35744d8e1e4f0be511_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:124c095184e111dd8237a7690d704deb196d3b0647bdb052279cc02259a3fd25_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:560250615f87c8179dd44909d455603ad90fa2d3bb497c5c3c2dcf13d664e1da_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:903b0313ece5e6200af4daa3954948bab2ff89663ee28d1a03a5d40879ff27fa_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4837912228f53dd229f17645a52028c0e761f8908acdc2451a8e9cff88f44878_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9023622b8da3fc355c74af8f5d17a972b9431dde0795e9eae3198902ce2a3b6a_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9c3dd78697256c68037f82462942b0f17177a5266cfdd67e4e476bb34703c295_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e4f8c44c453dd4ea1171c6d6b6218cb8da1f705b244e9eef65a0fa3f373c412b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:325017fff58f1074d588017c5f0a37832addf1d48d6c9d6bf245152314f170db_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:938ea8820d9482a93dc4f50fafbc367c9285c4e2d7e60feface2e38cfff36431_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:98214a466de2d20c2f1e6beddc072b66c90e219b5805c62145bc55cd584047ef_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:bb587771022637c26c943758796d13abf90e83e907c9af1373d1e792fd736540_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:118392d1eb7e7714b1b48c2f4ddfa8c5e3a330b847dd853ed87e63c6637a1d25_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:6b439f832eaca3a569715ba88b6626c1f24482b6d21b081cc80b8cdc460b0544_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b54798199bbf2a236e680ac946398120a5cdb52acebcbdba1053d78acb7f872d_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:cf967b84505f807364b44d6804ebc508c5dd5bc2105c1fa37e02d489159ec9be_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5eb4347ecff9a8ae6dbc0beec3c3d3b90f27a843d89a50dd7a7918827db975bb_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:6532bb4b2e62e35c548cf87d26cd3fa7f6c3eccaa64e4a7e81239137e1558925_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:cd34be7f278f9c2fb7df041f06767e41f5f42c9cc704f09234fbec0f19ed4de0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:def0e922b99c619e80f07ff083e25a8d878c5114d0468d849322774e46af2c13_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:5820b5aa0a7d188a955c304f852c241dd2b902c97a1dfb04fcf47220b01aa3af_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:a28a22335296983fcc8d3c95883a88f7dcf366d17dd9f0830699971883143206_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:bbafdbb3627b3e9cf20269844b22b0db59c5a57470f14d3b548922e607e9fa09_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:c57d13cff0e2d5197cf286c27f2a026075555b3dd7a62dd0ace702c191b4b404_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:060fb9209b65a1db5822f9a348aa88b6888fa4b7481e698086e2d256f880eb90_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:167a59608d6033a0cbd2e34c370bc9bf5f354a19f0d59609d8d31239f0e8f3c1_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:34c1ae37aa96ba4040fb58d1c99d0a90babe7781c5fcad5e66bf2f334ba9920f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3771faae4956682441bd5787f1cc41c03ba3f17d30f5117a33c76deb3d17995e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:11b0cd1b0427e007e23ea456a2fafc7eaed730c063c31394ca2c0ba347ca6c97_s390x as a component of Red Hat OpenShift Container Platform 4.19
- +140 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:74435
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/cve/CVE-2026-87114
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74435.json