Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:17475 - Security Advisory
Issued:
2026-05-19
Updated:
2026-05-19

RHSA-2026:17475 - Security Advisory

  • Overview
  • Updated Images

Synopsis

OpenShift Container Platform 4.21.16 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.21.16 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.21.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.16. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2026:17474

Security Fix(es):

  • Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469)
  • google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.

Solution

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/

Details on how to access this content are available at
https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.

Affected Products

  • Red Hat OpenShift Container Platform

Fixes

  • BZ - 2449833
  • BZ - 2457729
  • OCPBUGS-85055 - Add Nvidia ConnectX-6 Lx and ConnectX-8 to SR-IOV supported NIC list (4.21 backport)

CVEs

  • CVE-2026-33186
  • CVE-2026-35469

References

  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:ce50c466e22e13cfcdb2fc9669b4b8f80fe09b96ee0a354b8aad522e7dfe1352
registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:f9041e865aa3e0e8bee3b4f49bff0929e815dde98239d381dfa824f2823010a6
registry.redhat.io/openshift4/ose-dpu-intel-ipu-p4sdk-rhel9@sha256:61d37eaaed9e2149311c1b5e6df751ba0bb5b63a6e4a459488a1cf6461a27e2e
registry.redhat.io/openshift4/ose-dpu-intel-ipu-vsp-rhel9@sha256:2065fec82aea506533da4f614cd605712a3d8dab0f1d5d8adb8303384b06e2ab
registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:143d109ff992e7343b667b37ddd174628dfab6f0fb78c55b8a85951010e231b9
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:3dc9b9bb0fa20101ee45f1c64f54f8ae46b481b1a734568da2453a946982b274
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:fc9180aacd01a9893f74b64c0067c40e729fa874388af51c749e88512bf7a6f1
registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:8fd2a36e86e007f3fa99a911f97f2bfb15c1a514640e1c3a05c025a43d2ead9b
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4ab083b5f6807ff483da1da8558808beadb785ab8716fa4c72e1648b8ccc5b08
registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:8d96de0d9faccc93865c46b1ee881d2e0be2d5ead520a0049030b188d7258646
registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9@sha256:ed3f6bec8a5788bbdd2862a748eb366b6eee3a848dc47b43fdd3a3a35108add7
registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9-operator@sha256:6fbe3672e46b57b44125255e6aea13c09421c1753ef46602978e516794def69d
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2fa26ecd87d0bd6df1531db4484eec462704e941d5a39e00d2edc5924ae64b21
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:b1f7e9d88be300bafbfd8f2b09eb538a0bfdc4e7cdeb262cecd09c82aa38c223
registry.redhat.io/openshift4/ose-support-log-gather-rhel9-operator@sha256:c5f1b19e38b1890b936d37b6a1281112cd1aabda6eeb5a20b4bbb01ec00a2692
registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:eb7c7a4917b6bfab7e3668e8c980d4cd9be669d3756569154b5b208390a8b911
registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a59a8ba3808d17f305faa6f4589126a8898afef2a3a70aed836657f1f718d023
registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:fab84896e080fa9c227e3b6a0bb95b600263319278c9fc0af8859f44b4a905fa
registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:aba452f90cd9e1e96ec7c98d56162d0d50e107c0b942c269716f2a6a1702a17b

ppc64le

registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:fbd1cb60808dde27ee424adca3d48f1f345992044082f4cb452b528101769b34
registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:a6bf966202e30907b5083d11cb1ccab1ff54bf17bd478fef3b85d2ca704cff77
registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:1436287f8ff80d5e411e6e8dfccf8d5403fb24bddd5ce9e98cd19517ca802a6a
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b0af149ffe653cd25f0fd05da45a6fd41d55c097b8d607e671bb85ecdb081dae
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:b0279fee56a775c43c07786502cf17b8cbbb0b9b3fd0815bae145eb673b5038c
registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:12068ac89f6d2ebee4c7324782348eeb48e30d94479bd3b6a5971e0bdc330b1b
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a7894d3c00da71769ad80b1c1b7cf118fef354d85dbc80c6a136daf744d03837
registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9@sha256:5cb1f1b03313773b8f27095dc921c10b590a7494fcc2b11726332e92aba810d1
registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9-operator@sha256:8bde0559c1ce222d9405698e3bb93e2ee8592635e22ce375deba8db2fccee436
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:1a3fb3273e15923e10c501450387b1eadcadd020d75a5773bc6932df3b15c3a8
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:3c7a35d4ff51b823b3aeca997e67195bdd0e683f82609654222f1c3c9202acf4
registry.redhat.io/openshift4/ose-support-log-gather-rhel9-operator@sha256:24e50a72226b346bba2492c3c3f6b37823fd05c0d41e4d5b95e8a03cfe2056bb
registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:28274100511ceed52f37414350b5318352a2ce75bb4476a764baffb6ef2fae2e
registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:d65803452768b802ad61ffe25cb49738fcf1d544eae0a160c70b7e8f0e6c25a0
registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:4d2337aec2e7f5bcf48b8c598b5662c0b205018f6339ecb5e9c1bcf228cc55b9
registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:5d5c2c441892da12f0798eb1a8182d2f411fcf568987e5c602bedfd3553d864c

arm64

registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:5826a835b7506abd9863c2860b14cf2da3975bccc82c20e8dd379d19a0899f38
registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:55af6d0b6f04aae9227108d33af2589ec2b08def27b0a96bbd8cf5dcd96a0b34
registry.redhat.io/openshift4/ose-dpu-intel-ipu-p4sdk-rhel9@sha256:c9e74a81597d2877abda1a30bcbb81da7a28bf2601f2dbbfc7a747c0abcea57c
registry.redhat.io/openshift4/ose-dpu-intel-ipu-vsp-rhel9@sha256:30467acbef1e5354694a2dde7c16835eb206ac6b61f39c7700b4504b70de18ae
registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:96a1a8a4ba30ca355abf8a7f4ada3f11f920566d01db795dd2f46d02a820ef36
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f78a36784ea6369b3f8a20d7e114f26fbcf261a9d03e0b26ac0e00b5a2d68b6c
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:34730751aa38c5964d1729b3076da7d70e7f399b19a7622b344a240d48b2e416
registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:b7037e3dbbb1d9a038395af84764459e4d1ea707367fb7df85e1d552e50050ff
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4b5be0fe4c266d9cb9fec524f080b4e943eaaab975a75932bdf057cfa351e7ec
registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:2a223da7f2e09d76f048ef74ba9e18d29ada46ad43d676af32a6e32c02efa867
registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9@sha256:d0d2ba740a31e0b695bb87efe7d20b3c5a9eea5f22a4a58ef432425fa52a654b
registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9-operator@sha256:2554a48a29aec9384c3c3c6ddb7745f1adb6d0aae04f3afdcd011faa2178963d
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0dcec8ef82fdb64117b817a7e61ff01d9a39dc3c67783aed266d4a466ff84d81
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:ccb2c35d60002645d38c0ba97cc181d0edfce4d1dd960a6378bd3e4a03f56086
registry.redhat.io/openshift4/ose-support-log-gather-rhel9-operator@sha256:0b12e0fa93fcc8fe20b23d776bff77593027f91f0819667bed8451eec30d60d7
registry.redhat.io/openshift4/ose-ptp-rhel9-operator@sha256:6ae92094a60df319b42192c8eaeb0d47822626a0e0d6ac235e4de19a405b170d
registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:fd3885f566e67e28d3997c72e4f7587914925c415dbb78152dd8004788ad1172
registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:c293cc71af91c226517964ed114c81f4344e26512d5719652f85289a4ea163bd
registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:aff6f79b34d1024b2bd988deee16cfd6c62414edf69ac757b952fa1b4702ad32

s390x

registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:e8dcdd83456aad01d1c0fee3faf4ab2ac18e3372181d0fa0998e49bf365200d4
registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:52d4e5b09f1558e8a9fa05397ef1ac7ab97eee0348db25774f4bb7e02257db8b
registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:da8107458da0064021a4784a8435f9a8d9aa9a8926fec2144c0960b7d0ef5360
registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:d042d76a54588563b61b2e2500ad6c6f355f2841072723dfcd85fcab19bb88bb
registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e8e1512345c3190b39f4ee2b696069174bfe68e1ab29846666f7d9af49b4b0c8
registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:523f22a66224ba7c8cef228bef27d636e69cc946360a9d752147b07ec993b3c3
registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:851c4d4b903a0f8ac5dc255ee27c704eb7e1f79acafa02bb5cd64e74d0618a49
registry.redhat.io/openshift4/ose-support-log-gather-rhel9-operator@sha256:fc891e692b5db631805fa57d0853437352b2fab9260b13e3b910a91c9e379353
registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:29f76b09bd632e87dce73c72667ad8a0fc591c160f746830fb495da7e1268105
registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:8e3f8454e069cf2c941ba94748f13b8b11305ccaed0b0ab713ae5723bc1e7c57
registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:f6d1fe72f88d8f9064d5760423eca6ab20c26916742c676709da3ef15a5183e1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility