Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:17449 - Security Advisory
Issued:
2026-05-20
Updated:
2026-05-20

RHSA-2026:17449 - Security Advisory

  • Overview
  • Updated Images

Synopsis

OpenShift Container Platform 4.18.42 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.18.42 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.18.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.18.42. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2026:17448

Security Fix(es):

  • Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.

Solution

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/

Details on how to access this content are available at
https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.

Affected Products

  • Red Hat OpenShift Container Platform

Fixes

  • BZ - 2457729

CVEs

  • CVE-2026-35469

References

  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:0aa2466ebbaa3d030135fdf5aa377c9e6c1fc023322f7cd2e28299fa875ad74b
registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:c7878001b66d889347d3a87229610d42c1fac2bf7089f4b239dc9bb523f0f764
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:26bdcf0d92b6359c6370b240aef6aa0f6ea5c3daee63b40f9cd156daa206f723
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:b8eb3e481eb73dbd36591becedfa31f732a3de32807af82a840f5cda9416f474
registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:5bbdbae11350d7a5aae8407dd9b9751abd8bdeee0327797b28d6cde9d0549668
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:112b9bfb652715915016d89e87b2e18512f70397a01dd97c7dee842f47406691
registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:a3998bd36675ca4c793448426c7887e95954f667d170fea12c998b850313c127
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d8620fea16a31192af6ec38435ecdd90b5e4f65403812f34f3f3041edc4d2052
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:d169c81e1595b010c2bd59ce31000a3426c0f67909d5556088c41d8b6d665716
registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:d3b3288633257e3e0cb31313c97254c51396518a68cbeab8f34615db5a2aa464

arm64

registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:375400574275e237d2f391a9c6f0bfe3479d18b02c5cebc30b4a20725bc71d19
registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:30bd5a4e67ad96b8efd109118e736ea6c133949e2c6b634f15a8a2c959fbceac
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:63c359be316faaf8fc53a6096767a9db4b167b9dfdd2f3f90d7b682db9ca101a
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:4441cec5cf072fd128cc399aa959d69eca4806468b79d6ac8191934fa3f8e773
registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:4c6615389b809e0c5e97c718180e1cb26114809b40b21f8418f6492ac2ed6cec
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1c26fe2d637af61b0ae3659094002b34638f479ae8ed4b206f8042a72243b743
registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:7cd96e78530cfbfeb787d75c079e26bf6195cc98ecfedefb735dda3f043d8d29
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e7741a8fe04ec6a0f3983a4910732969fb42b5d749099269a08c97384c32507b
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:cd407e20532021ead8d8c05d2ee035e351240b23c11912c25507826326970d6a
registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:e17d381e2b5d4ba7a306d2edf0d74afe78dffb646f1ef54be71146df41458c94

s390x

registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:0154160ced0c0de1c57beab8e82576314e403e9ef811ac444a7bd83705b5bd51
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ce93d9f6e35e585055c6c50791657ed16a515549972a9426833aa26e0518f5d2
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:3303b011dcb878e2165e92b3b71b1839e4ea3af1697250653ddc18bafb2ea039
registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:ea83152d42e616fb7bbf0cdebbce0360c70a4de261d841e0e4ec897266eca77d
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:471d16a66025c08233be6d357cd4dad5fc4ed2dc2a9b44c70cb3d31f2079a775
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9352f6dd61c87088d2cd424d69ee861c77809311b9776142025fc70b5d3e6e6e
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:05f6e52cd67ecb03efe3680d524032d79002da446240f9487eb7c55f80c93444

ppc64le

registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:7bd5bee84c08ce7cc18733e44bcf697c533ebb67eb90a991b0f3dc4fc2af1acc
registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:9f131c386fa2215c14ebfe07295e3d32ba19a0429242d47821c6289b6c601b9b
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eae0748bdf7caf6513a668c0d28d0a8a29bec7d122fa6c2f39ff1c9ab5d05772
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:a43248e0dd8815db87a4ebc56c693d4766ad2afe4b6b37b57bb10659997c3b08
registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:06bbff002a3e1730447b1c039b8b7658c6bd133e64d9e80bee18bc5a13c27465
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:7f2613af9de4ddcfee3e0e2fb2b8ed582a0c76ad9b4bef45fc7f4ba81c959393
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f347fcb1d73cdbe471c057606c966d61b916e88c0beab5d033c4a189eb9c1597
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:cdf1c48fe86d5bd0bd799879f73816c1c2179536330f174237b01dbea87e0c40
registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:04173570c570318c693f9545061be72c39cf6f7b42ba62d0527a9faeb80ae858

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility