RHSA-2026:54544: Important: OpenShift Container Platform 4.18.53 bug fix and security update
Important: OpenShift Container Platform 4.18.53 bug fix and security update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.This advisory contains the container images for Red Hat OpenShift ContainerPlatform 4.18.53. See the following advisory for the RPM packages for thisrelease:https://access.redhat.com/errata/RHBA-2026:54543 Space precludes documenting all of the container images in this advisory.See the following Release Notes documentation, which will be updatedshortly for this release, for details about these changes:https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.18/html/releasenotes/ Security Fix(es): kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263) icu: Stack buffer overflow in the SRBRoot::addTag function (CVE-2025-5222) kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.All OpenShift Container Platform 4.18 users are advised to upgrade to theseupdated packages and images when they are available in the appropriaterelease channel. To check for available updates, use the OpenShift CLI (oc)or web console. Instructions for upgrading a cluster are available athttps://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.18/html-single/updatingclusters/index#updating-cluster-cli.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.18.53 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHBA-2026:54543 - Compensating control
Upgrade OpenShift Container Platform 4.18 to the updated packages and images in the appropriate release channel; use the OpenShift CLI (oc) or the web console to check for available updates.
Event History
Frequently Asked Questions
Which security issues are included in this update?
The update addresses CVE-2025-10263, an Arm processor issue that may allow privilege escalation or information disclosure; CVE-2025-5222, a stack buffer overflow in ICU; and CVE-2025-40026, a KVM x86 issue.
Which OpenShift platforms are covered by the advisory?
The advisory covers Red Hat OpenShift Container Platform, including variants for IBM Z and LinuxONE, ARM 64, and Power.
Are RPM packages included with this container image advisory?
No. The advisory states that RPM packages for this release are provided separately in RHBA-2026:54543.