RHSA-2026:57545: OpenShift Container Platform 4.20.35 bug fix and security update
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.35. There are no RPM packages for this release.Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.20/html/releasenotes/
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenShift Container Platformto a version that resolves this vulnerability.Fixed in 4.20.35 - Operational
For OpenShift Container Platform 4.20.35, use the image digests for your architecture when validating the release image in the appropriate release channel: x86_64 sha256:ffb9ee7de8d13bce19d67ce5c6c13c56ad8e9e1906341fccc7c5d12e2fb6d97e; s390x sha256:cc186d91c9aa6912b0c9b37d4ad6a2a351c7d2a25057be1dd877d4fdfa749199; ppc64le sha256:53c1d50692a293687cdb9807dcbbe7fac623d7bfbe43e05424a3ed4669dff1c2; aarch64 sha256:e6afe3fe2624db9921344d41cd507f65156faf84e3bb6ee23a0cf0ec5990b68f.
Event History
Frequently Asked Questions
Which deployments need this update?
Deployments using Red Hat OpenShift Container Platform 4.20 are the relevant scope. The advisory provides container images for version 4.20.35 and does not include RPM packages.
Are individual affected components or vulnerabilities identified in this advisory?
No. The advisory states that it does not document all container images because of space constraints, and it directs readers to the 4.20 release notes for change details.
How can I determine whether the update has been applied?
Verify whether the OpenShift Container Platform deployment is running the 4.20.35 container-image release. The provided advisory data does not identify individual image names or component-level fixes.