Skip to main content
EPSS 0.7%top 51%

Red Hat Security Advisory: Red Hat build of MicroShift 4.19.42 security update

0
High
Published: 08/12/2026 (08/12/2026, 00:24:02 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat build of MicroShift is Red Hat's light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift Container Platform. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments. This advisory contains the RPM packages for Red Hat build of MicroShift 4.19.42. Read the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:51007 Security Fix(es): * Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469) All Red Hat build of MicroShift 4.19 users are advised to use these updated packages and images when they are available in the RPM repository.

Affected software

Affected versions
<0.5.1>=4.18.0 <4.18.42Red HatRed Hat Container Native VirtualizationRed Hat Container Native Virtualization 4.15amd64registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:6f00dbe92e456e3456d19240a2d9cf4b7388d5d4b728a08763796f18103bf16d_amd64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.19arm64registry.redhat.io/openshift4/ose-cluster-version-rhel9-operator@sha256:982008ca7abbef3ab654e3c0e35acede52ecffbb838174a46d39bb5a50454253_arm64< 0.5.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:0aa2466ebbaa3d030135fdf5aa377c9e6c1fc023322f7cd2e28299fa875ad74b_amd64Red Hat Advanced Cluster Management for KubernetesRed Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:043fdd995b92bb8de99305c0706c8c30ea505617838fc256573e1dadc58ab1c7_amd64Red Hat Container Native Virtualization 4.17registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:fc8c4b85db018114dc16f4e7393424202f0662c1a21999d52392b367eea72f02_amd64registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:26b556903b77449b01b1a1afbd3cd5e0b819a096110117ae9aefe170f99d1a0b_amd64Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-operator-sdk-rhel9@sha256:2dca55c529e8a92ca4d6bc73de6caf4e5f78ac7c2b3a59f698a5c1e46431af85_arm64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:c6ab036b18b656f8e6f95167a22a76f248375f1ea5e4c1acbfd6011e66956268_arm64Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:b9141160dce8628b7a65d1e756b07c8220e8bb3f74288edfdd4956836b956361_amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:dee47230347404c6fc39f2250724824881cd9e69273888225847f92859dc9540_arm64s390xregistry.redhat.io/openshift4/ose-operator-registry-rhel9@sha256:03edfdda71d7ed916e67a95e58438b44a99b011e3256ca68a6b89ea67ae02c25_s390xRed Hat Container Native Virtualization 4.16registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:44ea9bd018b945ac5af9e68d1c9b053fca263188a7ef540f6f66e8a5e00e7f6f_amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:b43d741116229996169c7dab94dddb3d6a4a5af8be04cd067cec43ed85e11355_arm64Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:9352d0869fc2ec1db70e385a572696e4097fe95c8e91adf8ad22f47766b84036_arm64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:722222e48148ee206861bede432f914c200f67f289fe722f0c85556af72d603a_amd64Red Hat Container Native Virtualization 4.22registry.redhat.io/container-native-virtualization/iommufd-device-plugin-rhel9@sha256:a4b3cc14792e7ca66f2bc090cfaf616a2cbb39039266990f1fc1e900b4f435ad_amd64Red Hat OpenShift Container Platform 4.20ppc64leregistry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:43e0b9da0aaabb0f52bc3a248692ab1f2c4170c2cf10aae98af86f2ef95df674_ppc64leRed Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:3895d8f92a3c7da912bdc84afd1c5a9f917a0438f41f167a777836a8f6efb3f8_amd64Red Hat OpenShift Enterprisesrcopenshift-0:4.19.0-202606301915.p2.g63adf01.assembly.stream.el9.srcregistry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:36d22f5519bb82d4b7176fc2d6be72306e9ae9c04fc4afb109e37fadb9a66012_amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:21bad60731311e59aa071c51f5a1fed550a825db5869f2bcbe8901280df3f7f3_amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:35b705331b65c712174357f008fb9ea2e53b4af03b1b4c5ad1eec14bb3379a1b_arm64Red Hat OpenShift Container Platform 4.2registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:8d81d68f4dd8fa0254f073305be3747c3e51f3bf1b992d196253195135188a00_ppc64leRed Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:4f0404fffd61d7bb08717d915c5cfde74ee84b3653fcd8002297e3bd0b9b4620_amd64registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:63934f421a8c4e798384196b0eb5e03e16392b5a951be5e1febe9ce254846314_amd64registry.redhat.io/openshift4/ose-cluster-config-rhel9-operator@sha256:d9adcb9f987459e19e7af0d9bdce5f0f6d5fdf88e5e8ffb52501f089d817b781_s390x<26.4.2microshift-0:4.19.42-202608062155.p0.g46c9d67.assembly.4.19.42.el9.src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 19:43:32 UTC

Technical Analysis

CVE-2026-35469 is a denial of service vulnerability affecting the SPDY streaming code in Kubelet, CRI-O, and kube-apiserver components of Red Hat OpenShift Container Platform. The flaw allows an attacker possessing specific elevated cluster roles—such as permissions for pod port forwarding, exec, attach, or node proxying—to exploit the vulnerability and cause these critical components to become unresponsive. This impacts resource availability and can disrupt cluster operations. Red Hat has issued a security advisory with updated RPM packages and container images in OpenShift Container Platform 4.18.42 to fix this issue. The advisory also recommends reviewing and restricting cluster role assignments to mitigate risk. The CVSS v4.0 base score is 8.7 (high severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, and high availability impact.

Potential Impact

Exploitation of this vulnerability can cause denial of service by making Kubelet, CRI-O, and kube-apiserver unresponsive. This affects the availability of critical Kubernetes components in OpenShift Container Platform clusters. The attacker must have specific elevated cluster roles related to pod port forwarding, execution, attachment, or node proxying. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released OpenShift Container Platform 4.18.42 containing fixes for this vulnerability. Users should upgrade to this version or later using the OpenShift CLI or web console following Red Hat's documented upgrade procedures. Additionally, it is recommended to review and restrict the assignment of Kubernetes cluster roles 'pods/portforward (create)', 'pods/exec (create)', 'pods/attach (create)', and 'nodes/proxy (get/create)' to only trusted and necessary users or service accounts. Careful testing is advised when modifying RBAC policies to avoid disrupting legitimate functionality. No other mitigations or workarounds are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:17704
Cve Count
1
State
PUBLISHED

Threat ID: 6a160979e29bf47b5064587d

Added to database: 05/26/2026, 20:58:33 UTC

Last enriched: 08/10/2026, 19:43:32 UTC

Last updated: 09/14/2026, 22:01:33 UTC

Views: 133

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:17449https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/updates/classification/Canonical URLReference 5Reference 6Reference 7Reference 8Reference 9Reference 10Reference 11Reference 12Reference 13Reference 14Reference 15Reference 16Reference 17Reference 18Reference 19Reference 20Reference 21Reference 22Reference 23Reference 24Reference 25Reference 26Reference 27Reference 28Reference 29Reference 30Reference 31Reference 32Reference 33Reference 34Reference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47Reference 48Reference 49Reference 50Reference 51Reference 52Reference 53Reference 54Reference 55Reference 56Reference 57Reference 58Reference 59Reference 60Reference 61Reference 62Reference 63Reference 64Reference 65Reference 66Reference 67Reference 68Reference 69Reference 70Reference 71Reference 72Reference 73Reference 74Reference 75Reference 76Reference 77Reference 78Canonical URLhttps://access.redhat.com/security/updates/classification/#importantCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLhttps://access.redhat.com/errata/RHSA-2026:51007https://access.redhat.com/security/cve/CVE-2026-49332https://access.redhat.com/security/cve/CVE-2026-49978Canonical URLReference 97Reference 98Reference 99Reference 100Reference 101Reference 102Canonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLhttps://access.redhat.com/security/cve/CVE-2026-46579Canonical URLReference 111Canonical URLCanonical URLCanonical URLCanonical URLReference 116Reference 117Reference 118Reference 119Reference 120Reference 121Reference 122Reference 123Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses