RHSA-2026:28887: Critical: OpenShift Container Platform 4.14.68 bug fix and security update
Critical: OpenShift Container Platform 4.14.68 bug fix and security update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.This advisory contains the container images for Red Hat OpenShift ContainerPlatform 4.14.68. See the following advisory for the RPM packages for thisrelease:https://access.redhat.com/errata/RHSA-2026:28886 Space precludes documenting all of the container images in this advisory.See the following Release Notes documentation, which will be updatedshortly for this release, for details about these changes:https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.14/html/releasenotes/ Security Fix(es): kernel: ip6tunnel: clear skb2->cb[] in ip4ip6err() (CVE-2026-43037) libcap: libcap: Privilege escalation via TOCTOU race condition in capsetfile() (CVE-2026-4878) OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode (CVE-2026-35385) sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535) jq: out-of-bounds read in jvparsesized() on error formatting for non-NUL-terminated buffers (CVE-2026-39979) jq: jq: Denial of Service via crafted JSON object causing hash collisions (CVE-2026-40164) rsync: Rsync: Use-after-free vulnerability in extended attribute handling (CVE-2026-41035) kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions (CVE-2026-46243) kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in theLinux kernel (CVE-2026-46300) kernel: net/sched: actpedit: extend the writable skb range per key (CVE-2026-46331)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.All OpenShift Container Platform 4.14 users are advised to upgrade to theseupdated packages and images when they are available in the appropriaterelease channel. To check for available updates, use the OpenShift CLI (oc)or web console. Instructions for upgrading a cluster are available athttps://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.14/html-single/updatingclusters/index#updating-cluster-cli.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
openshift/openShift Container Platformto a version that resolves this vulnerability.Fixed in 4.14.68Patch RHSA-2026:28886
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:28887?
The severity of RHSA-2026:28887 is classified as critical with a CVSS score of 9.
How do I fix RHSA-2026:28887?
To fix RHSA-2026:28887, you should apply the latest security update for Red Hat OpenShift Container Platform 4.14.68.
What vulnerabilities are addressed in RHSA-2026:28887?
RHSA-2026:28887 addresses vulnerabilities classified as Use After Free and Race Condition.
What products are affected by RHSA-2026:28887?
RHSA-2026:28887 affects various versions of Red Hat OpenShift Container Platform for IBM Z, LinuxONE, Power, and ARM 64.
When was RHSA-2026:28887 published?
RHSA-2026:28887 was published on July 1, 2026.