Red Hat Security Advisory: Red Hat build of MicroShift 4.19.42 security update
Red Hat build of MicroShift is Red Hat's light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift Container Platform. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments. This advisory contains the RPM packages for Red Hat build of MicroShift 4.19.42. Read the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:51007 Security Fix(es): * Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469) All Red Hat build of MicroShift 4.19 users are advised to use these updated packages and images when they are available in the RPM repository.
AI Analysis
Technical Summary
CVE-2026-35469 is a denial of service vulnerability affecting the SPDY streaming code in Kubelet, CRI-O, and kube-apiserver components of Red Hat OpenShift Container Platform. The flaw allows an attacker possessing specific elevated cluster roles—such as permissions for pod port forwarding, exec, attach, or node proxying—to exploit the vulnerability and cause these critical components to become unresponsive. This impacts resource availability and can disrupt cluster operations. Red Hat has issued a security advisory with updated RPM packages and container images in OpenShift Container Platform 4.18.42 to fix this issue. The advisory also recommends reviewing and restricting cluster role assignments to mitigate risk. The CVSS v4.0 base score is 8.7 (high severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, and high availability impact.
Potential Impact
Exploitation of this vulnerability can cause denial of service by making Kubelet, CRI-O, and kube-apiserver unresponsive. This affects the availability of critical Kubernetes components in OpenShift Container Platform clusters. The attacker must have specific elevated cluster roles related to pod port forwarding, execution, attachment, or node proxying. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released OpenShift Container Platform 4.18.42 containing fixes for this vulnerability. Users should upgrade to this version or later using the OpenShift CLI or web console following Red Hat's documented upgrade procedures. Additionally, it is recommended to review and restrict the assignment of Kubernetes cluster roles 'pods/portforward (create)', 'pods/exec (create)', 'pods/attach (create)', and 'nodes/proxy (get/create)' to only trusted and necessary users or service accounts. Careful testing is advised when modifying RBAC policies to avoid disrupting legitimate functionality. No other mitigations or workarounds are specified.
Red Hat Security Advisory: Red Hat build of MicroShift 4.19.42 security update
Description
Red Hat build of MicroShift is Red Hat's light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift Container Platform. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments. This advisory contains the RPM packages for Red Hat build of MicroShift 4.19.42. Read the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:51007 Security Fix(es): * Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469) All Red Hat build of MicroShift 4.19 users are advised to use these updated packages and images when they are available in the RPM repository.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-35469 is a denial of service vulnerability affecting the SPDY streaming code in Kubelet, CRI-O, and kube-apiserver components of Red Hat OpenShift Container Platform. The flaw allows an attacker possessing specific elevated cluster roles—such as permissions for pod port forwarding, exec, attach, or node proxying—to exploit the vulnerability and cause these critical components to become unresponsive. This impacts resource availability and can disrupt cluster operations. Red Hat has issued a security advisory with updated RPM packages and container images in OpenShift Container Platform 4.18.42 to fix this issue. The advisory also recommends reviewing and restricting cluster role assignments to mitigate risk. The CVSS v4.0 base score is 8.7 (high severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, and high availability impact.
Potential Impact
Exploitation of this vulnerability can cause denial of service by making Kubelet, CRI-O, and kube-apiserver unresponsive. This affects the availability of critical Kubernetes components in OpenShift Container Platform clusters. The attacker must have specific elevated cluster roles related to pod port forwarding, execution, attachment, or node proxying. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released OpenShift Container Platform 4.18.42 containing fixes for this vulnerability. Users should upgrade to this version or later using the OpenShift CLI or web console following Red Hat's documented upgrade procedures. Additionally, it is recommended to review and restrict the assignment of Kubernetes cluster roles 'pods/portforward (create)', 'pods/exec (create)', 'pods/attach (create)', and 'nodes/proxy (get/create)' to only trusted and necessary users or service accounts. Careful testing is advised when modifying RBAC policies to avoid disrupting legitimate functionality. No other mitigations or workarounds are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:17704
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a160979e29bf47b5064587d
Added to database: 05/26/2026, 20:58:33 UTC
Last enriched: 08/10/2026, 19:43:32 UTC
Last updated: 09/14/2026, 22:01:33 UTC
Views: 133
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.