Red Hat released security updates for OpenShift Container Platform (OCP) release streams 4.13 through 4.22, including 4.19.43, 4.20.34, 4.21.29, and 4.22.10. The Important-rated updates deliver refreshed packages and container images for x86_64, s390x, ppc64le, and aarch64 deployments, including supported RHEL 8 and RHEL 9 variants. OCP 4.13.70 was rated Low, although its advisory lists fixes affecting the Linux kernel, OpenSSL, and SSSD.
The fixes address vulnerabilities in the Linux kernel, Samba, SSSD, ICU, dnsmasq, OpenSSH, libarchive, rsync, Unbound, Vim, and other bundled components. Notable SSSD issues include CVE-2026-14474, which can enable privilege escalation through the sudo LDAP provider's directory-wide sudoRole search, and CVE-2026-14476, a GPO-cache path traversal flaw that can permit Kerberos authentication bypass. Red Hat advised administrators to upgrade affected clusters through their appropriate OpenShift release channels using the web console or OpenShift CLI.

See real exploitation activity before you spend the cycle.
18 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:46990 for SSSD on RHEL 8, fixing CVE-2026-14474, a sudo LDAP-provider privilege-escalation issue, and CVE-2026-14476, a GPO cache path-traversal flaw enabling Kerberos authentication bypass.
OSIDB Bzimport recorded CVE-2025-61662, in which GRUB2's gettext command remains registered after its module unloads and can access freed memory.
Red Hat released a Low-rated OpenShift 4.13.70 security and bug-fix update addressing vulnerabilities in the kernel, OpenSSL, and SSSD.
Red Hat issued an Important-rated OpenShift 4.19.43 update fixing six vulnerabilities in the kernel, SSSD, ICU, and dnsmasq, including SSSD privilege escalation and Kerberos authentication bypass flaws.
Red Hat released an Important-rated OpenShift 4.20.34 update addressing vulnerabilities in the kernel, Samba, SSSD, and ICU, including privilege escalation and Kerberos authentication-bypass issues.
Red Hat issued an Important-rated OpenShift 4.22.10 update fixing numerous vulnerabilities in the kernel, Samba, SSSD, sg3_utils, rsync, Unbound, Vim, OpenSSH, libarchive, and acl.
Red Hat released an Important-rated OpenShift 4.21.29 update addressing kernel, Samba, and SSSD vulnerabilities, including CVE-2026-1933 and the two SSSD flaws CVE-2026-14474 and CVE-2026-14476.
Red Hat issued an Important-rated OpenShift 4.17.56 update addressing CVE-2026-43329 in netfilter flowtable, CVE-2026-46243 in the SMB client, and CVE-2026-46323 in net/gro.
Red Hat released an Important-rated OpenShift 4.14.70 update fixing kernel netfilter CVE-2026-43329, glibc heap overflow CVE-2026-5450, and OpenSSL information disclosure CVE-2026-31790.
Red Hat issued an Important-rated OpenShift 4.15.67 update remediating a BIND DNSSEC denial-of-service flaw, a glibc scanf heap overflow, and OpenSSL information disclosure CVE-2026-31790.
Red Hat issued an Important-rated OpenShift 4.18.50 update fixing CVE-2026-43329 in netfilter flowtable, CVE-2026-46323 in net/gro, and CVE-2026-53359 in KVM x86 shadow paging.
Red Hat released an Important-rated OpenShift 4.19.40 update addressing kernel netfilter, eventpoll, KVM, and net/gro flaws, plus OpenSSL information disclosure CVE-2026-31790.
Red Hat released an Important-rated OpenShift 4.21.26 update with fixes for CVE-2026-43329 in kernel netfilter flowtable and CVE-2026-46323 in net/gro.
Red Hat issued an Important-rated OpenShift 4.20.31 update that fixes kernel netfilter flowtable flaw CVE-2026-43329 and net/gro use-after-free CVE-2026-46323.
Red Hat issued a Low-rated OpenShift 4.13.67 security update addressing vulnerabilities in OpenSSH, nghttp2, libarchive, sudo, and the Linux kernel.
Red Hat released an Important-rated OpenShift 4.19.32 update fixing vulnerabilities in OpenSSH, libarchive, nghttp2, and sudo, including privilege-escalation and arbitrary-code-execution flaws.
Red Hat addressed the GRUB2 gettext-command use-after-free through advisories for RHEL 7 through 10 variants and OpenShift Container Platform releases 4.12 through 4.19.
Red Hat issued an Important-rated OpenShift 4.19.28 security and bug-fix update addressing seven flaws in libpng, Vim, Expat, and GRUB2, including CVE-2025-61662.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.