Skip to main content
EPSS 0.3%top 75%

Red Hat Security Advisory: OpenShift Container Platform 4.17.54 security and extras update

0
High
Published: 05/20/2026 (05/20/2026, 12:22:57 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.17.54. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:17598 Security Fix(es): * Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469) * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking (CVE-2026-24049) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Affected software

Affected versions
>=4.17.0 <4.17.54>=0.40.0 <0.46.2Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux CodeReady Linux Builder (v. 10)srcpython-wheel-1:0.41.2-5.el10_1.1.srcRed Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)Red Hat Enterprise Linux AppStream (v. 8)Red Hat Enterprise Linux CRB (v. 8)Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.17s390xregistry.redhat.io/openshift4/metallb-rhel9@sha256:ed3285d796933d9de4e72beed352f4a2f129412d3dd0894c7753fef01cca0cd2_s390xarm64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:e9c35b5737aa94cae47a211c7e8299dc243551b42bbcf892a1754d24d63c6e55_arm64Red Hat Enterprise Linux AppStream EUS (v.9.6)Red Hat CodeReady Linux Builder EUS (v.9.6)Red Hat OpenShift Container Platform 4.2ppc64leregistry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:10079381b6f6f221f79004cf2a5cd808d48a0f0715e295b84f69a8982c2e1394_ppc64leRed Hat DiscoveryDiscovery 2 for RHEL 10Discovery 2 for RHEL 8Discovery 2 for RHEL 9Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)python-wheel-1:0.41.2-5.el10_0.1.srcRed Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:da2a5c623923d1875795eb29b8a5b1dd2cdffc534e33dd7d58ef3c99be66026b_ppc64leRed Hat OpenShift Container Platform 4.18amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:829084afd4886507f9ca81ec66d41112ccb0e1b11362538dc9dee579e8f6c5b4_amd64Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:d4e6814d9cba1eee34529e127ad39d52eef93cab872a610238277d680b48fd0f_amd64registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:ef6b840af348e16329025673ccfe2566202b5d0b28ba49031cdb3def32ebaec9_arm64Red Hat Enterprise Linux AppStream EUS (v.9.4)Red Hat CodeReady Linux Builder EUS (v.9.4)>= 0.40.0, < 0.46.2Red Hat OpenShift Container Platform 4.20

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 18:50:35 UTC

Technical Analysis

CVE-2026-24049 is a path traversal vulnerability in the python wheel tool's unpack function. The vulnerability arises because the unpack logic trusts filenames from the archive header for chmod operations without properly validating the paths after extraction. This can allow an attacker to craft a malicious wheel file that changes permissions on critical system files (e.g., /etc/passwd, SSH keys), enabling privilege escalation or arbitrary code execution. Red Hat OpenShift Container Platform versions prior to 4.17.54 are affected. Red Hat has issued a security advisory and released updated RPM packages and container images in version 4.17.54 to fix this issue.

Potential Impact

An attacker with the ability to supply a malicious wheel file to be unpacked can exploit this vulnerability to modify permissions on critical system files. This can lead to privilege escalation or arbitrary code execution on the affected system. The integrity and availability of the system can be compromised, and security mechanisms may be bypassed. The vulnerability has a high severity rating by Red Hat, with a CVSS base score of 7.1 (Red Hat scoring). No known active exploitation has been reported.

Mitigation Recommendations

Red Hat has released an official fix in OpenShift Container Platform version 4.17.54. Users should upgrade to this version or later to remediate the vulnerability. The advisory recommends applying the updated RPM packages and container images available in the appropriate release channels. No alternative mitigations meeting Red Hat's criteria are currently available. Follow Red Hat's official upgrade instructions to fully apply the update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:17599
Cve Count
3
Additional Cves
["CVE-2026-33186","CVE-2026-35469"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a160955e29bf47b5061a742

Added to database: 05/26/2026, 20:57:57 UTC

Last enriched: 08/14/2026, 18:50:35 UTC

Last updated: 09/15/2026, 01:45:44 UTC

Views: 89

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses