RHSA-2026:60445: Important: OpenShift Container Platform 4.20.36 bug fix and security update
Important: OpenShift Container Platform 4.20.36 bug fix and security update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.This advisory contains the container images for Red Hat OpenShift ContainerPlatform 4.20.36. See the following advisory for the RPM packages for thisrelease:https://access.redhat.com/errata/RHSA-2026:60444 Space precludes documenting all of the container images in this advisory.See the following Release Notes documentation, which will be updatedshortly for this release, for details about these changes:https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.20/html/releasenotes/ Security Fix(es): dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.All OpenShift Container Platform 4.20 users are advised to upgrade to theseupdated packages and images when they are available in the appropriaterelease channel. To check for available updates, use the OpenShift CLI (oc)or web console. Instructions for upgrading a cluster are available athttps://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.20/html-single/updatingclusters/index#updating-cluster-cli.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.20.36Patch RHSA-2026:60444 - Upgrade
Upgrade
openshift-release-dev/ocp-releaseto a version that resolves this vulnerability.Fixed in 4.20.36Patch RHSA-2026:60444 - Upgrade
Upgrade
dracutto a version that resolves this vulnerability.Fixed in 4.20.36Patch CVE-2026-15816
Event History
Frequently Asked Questions
Which environments are covered by this update?
The update applies to Red Hat OpenShift Container Platform 4.20.36, including the standard platform and builds for ARM 64, Power, and IBM Z and LinuxONE.
What should teams prioritize when responding?
This is classified as an Important security update with high severity. Organizations running the affected OpenShift Container Platform 4.20 release should assess and apply the 4.20.36 update through their normal Red Hat update process.