Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:66385 - Security Advisory
Issued:
2026-09-17
Updated:
2026-09-17

RHSA-2026:66385 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: OpenShift Container Platform 4.18.55 packages and security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat OpenShift Container Platform release 4.18.55 is now available with
updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container
Platform 4.18.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container
Platform 4.18.55. See the following advisory for the container images for
this release:

https://access.redhat.com/errata/RHSA-2026:65852

Security Fix(es):

  • github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd

Injection via HOME env (CVE-2026-15809)

  • github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE:

Denial of Service via crafted JSON Web Encryption (JWE) object
(CVE-2026-34986)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

All OpenShift Container Platform 4.18 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift CLI (oc)
or web console. Instructions for upgrading a cluster are available at
https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.

Solution

For OpenShift Container Platform 4.18 see the following documentation,
which will be updated shortly for this release, for important instructions
on how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/

Affected Products

  • Red Hat OpenShift Container Platform 4.18 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.18 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.18 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.18 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.18 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.18 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.18 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.18 for RHEL 8 aarch64

Fixes

  • BZ - 2455470 - CVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
  • BZ - 2500846 - CVE-2026-15809 github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 ? /etc/passwd Injection via HOME env

CVEs

  • CVE-2026-15809
  • CVE-2026-34986

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 4.18 for RHEL 9

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.src.rpm SHA-256: d1e495723c6c80214a2d74063c975db5883a0e4f309c192cd80a0697c79d5ac7
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.src.rpm SHA-256: 37543040ce0a42c087fd6c404f9a54dec5668719e9b6fe4ea9e2f2ff7e174b7a
x86_64
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.x86_64.rpm SHA-256: 403778e6b3cc7b58ef2509f21ea559ad13bb1695d34987de4982384760c0deff
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el9.x86_64.rpm SHA-256: 80e792f9d28dc5e0248acbdbbbca3779c8c3ab07b922892a6f756cdac24703a4
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el9.x86_64.rpm SHA-256: 9902a57a08e7fce9aa2a53da4a9122fc74dcdc5781aa7cdb426ef15fe5a775a5
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.x86_64.rpm SHA-256: 23267caafa58709a33c323ec69c9583c41787cc4a50f2a2804c2468a341d24e0
openshift-clients-redistributable-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.x86_64.rpm SHA-256: dd106c36940cc27849ac7fcea5dfc9b6dd480ee8f6637055f4ab4f2b2b93be31

Red Hat OpenShift Container Platform 4.18 for RHEL 8

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.src.rpm SHA-256: 430342e4ee6e1d0eb8dff4479bc1527a528d572b5a755f4e77354e6c8afbafd6
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.src.rpm SHA-256: 305a5d7fb03441b5b2a630678f12a9c7a3557c3551a6146f99b9654551054c94
x86_64
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.x86_64.rpm SHA-256: fef592d25aa4e8fd04df29f0d116b7e3e0b3a873da14d4569e5f140ec5496282
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el8.x86_64.rpm SHA-256: b75331695265abbf385a1876edccd9833bd6f9d16b88c0ecb754b4c647ddb18e
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el8.x86_64.rpm SHA-256: 662e3518f95270f39ec2400e44dc2057b8688e55f073843e6eeaf1f30aac0fa7
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.x86_64.rpm SHA-256: a79a2376f197fffd7b2b15115c9b2e6410c27ec3948e302e888b54df73dab1df
openshift-clients-redistributable-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.x86_64.rpm SHA-256: 80a395c31406977fb896036dfda0bed9664584f4f40dc54b5f045da8b077d6b3

Red Hat OpenShift Container Platform for Power 4.18 for RHEL 9

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.src.rpm SHA-256: d1e495723c6c80214a2d74063c975db5883a0e4f309c192cd80a0697c79d5ac7
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.src.rpm SHA-256: 37543040ce0a42c087fd6c404f9a54dec5668719e9b6fe4ea9e2f2ff7e174b7a
ppc64le
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.ppc64le.rpm SHA-256: 7651b9c03ba2690df68b2c01c88b1fa71873fb0437a17ea412f2e2452c247063
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el9.ppc64le.rpm SHA-256: b3cac77adb1d55c295863aa6e8d302112b87d888557e5275ca886ea3bd0c56c3
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el9.ppc64le.rpm SHA-256: de91e720af2b4c387d4980f5a565fbfb25d2f522503793411758803678197ee6
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.ppc64le.rpm SHA-256: 3e07ecf9637748392b17f167f32ff9ffb902aafae505d47699c9861a2809bcbe

Red Hat OpenShift Container Platform for Power 4.18 for RHEL 8

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.src.rpm SHA-256: 430342e4ee6e1d0eb8dff4479bc1527a528d572b5a755f4e77354e6c8afbafd6
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.src.rpm SHA-256: 305a5d7fb03441b5b2a630678f12a9c7a3557c3551a6146f99b9654551054c94
ppc64le
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.ppc64le.rpm SHA-256: 94935c9dd4c782f656bfaa991aec5235d483e2cec5df9608bb8ef6272ff24cff
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el8.ppc64le.rpm SHA-256: 38f48cb8cef96d2bc2c4901babcc9996752b7b43a589dc8cb72829589e4cf83f
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el8.ppc64le.rpm SHA-256: 8b487b7f34551dfa95fb61d7c5a4b707808fd751442129e5f83235e6b8abc4c3
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.ppc64le.rpm SHA-256: 93e3bdd29e5a5f19253377384ae3fac324e7cf3a8f3d1d1ca55c1db7449a4eb8

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.18 for RHEL 9

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.src.rpm SHA-256: d1e495723c6c80214a2d74063c975db5883a0e4f309c192cd80a0697c79d5ac7
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.src.rpm SHA-256: 37543040ce0a42c087fd6c404f9a54dec5668719e9b6fe4ea9e2f2ff7e174b7a
s390x
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.s390x.rpm SHA-256: 23e9b44640fb25aae3920bf3a80c8453fbebc38f6bea7b5904a2721647d91a4a
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el9.s390x.rpm SHA-256: 6a8f326d05953bf991d3afeb575152038e3c8c40b97868019d88a22e9619bfa5
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el9.s390x.rpm SHA-256: 51c072e9a00135ae08d62e5c8d93c3edf19b92ab329d37c647be0e39223f8bec
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.s390x.rpm SHA-256: 4a93383ad38de54e4b77302405240af4ad0a6e72c596ed19343e866500fa1f4d

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.18 for RHEL 8

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.src.rpm SHA-256: 430342e4ee6e1d0eb8dff4479bc1527a528d572b5a755f4e77354e6c8afbafd6
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.src.rpm SHA-256: 305a5d7fb03441b5b2a630678f12a9c7a3557c3551a6146f99b9654551054c94
s390x
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.s390x.rpm SHA-256: 6821ab94e1c3377c15a65743dcdd354592f9a10737b0c5dc1852c2e4039fa85e
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el8.s390x.rpm SHA-256: c07c0ef910b6325e153ce3f898482e629dae506c7d48020665a567dda80ad27b
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el8.s390x.rpm SHA-256: d05eb688c553b38a0b8a09d1791af19c0d0a213b80aa5638aa6d2f2a433641bd
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.s390x.rpm SHA-256: 9c383e152685472e4411240dfe9ba07ab7031b80238e1807f44e786b66767afa

Red Hat OpenShift Container Platform for ARM 64 4.18 for RHEL 9

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.src.rpm SHA-256: d1e495723c6c80214a2d74063c975db5883a0e4f309c192cd80a0697c79d5ac7
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.src.rpm SHA-256: 37543040ce0a42c087fd6c404f9a54dec5668719e9b6fe4ea9e2f2ff7e174b7a
aarch64
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el9.aarch64.rpm SHA-256: 4ffd33e53ec1b7f5e3d9ddc860b6c55d6dbb8d81d4daf042055ae65f8c3bd725
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el9.aarch64.rpm SHA-256: 672b9a98f390d8ca6fcbb1fcf64d81e44d3e2cbb0c5a5a22a4c6bab676dc0993
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el9.aarch64.rpm SHA-256: d66a470ad4b1768dab3fe072c7430ff7dfcc88e5ccc7365dce1568b24288cd84
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el9.aarch64.rpm SHA-256: 2a570601c89b46c4415175ce51770129ea2fb3f9a153bca71d84dd1e8ccfb8e8

Red Hat OpenShift Container Platform for ARM 64 4.18 for RHEL 8

SRPM
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.src.rpm SHA-256: 430342e4ee6e1d0eb8dff4479bc1527a528d572b5a755f4e77354e6c8afbafd6
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.src.rpm SHA-256: 305a5d7fb03441b5b2a630678f12a9c7a3557c3551a6146f99b9654551054c94
aarch64
cri-o-1.31.13-14.rhaos4.18.gitf2de9ac.el8.aarch64.rpm SHA-256: 00513cbb40ac63f03d319e6c5b9011e5e354bc117f75ed50a20363208397ddd3
cri-o-debuginfo-1.31.13-14.rhaos4.18.gitf2de9ac.el8.aarch64.rpm SHA-256: 6a1ba564e47106945523d966a38d6b50d60beb2d0441fe9fdf2003a7944839b0
cri-o-debugsource-1.31.13-14.rhaos4.18.gitf2de9ac.el8.aarch64.rpm SHA-256: 0e490113cd18870650ce66c12a7b40501088e40af98e380e86c57949dd6bda27
openshift-clients-4.18.0-202608191253.p2.g3da7a06.assembly.stream.el8.aarch64.rpm SHA-256: b30e8d8fd2cb35d9ae1054bae3c7287d3bff9da726fdecdf57b6af9cb11e7d1a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility