SB20260825123 - Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22



SB20260825123 - Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22

Published: August 25, 2026

Security Bulletin ID SB20260825123
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Resource exhaustion (CVE-ID: CVE-2026-11622)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the DNSSEC validating resolver when processing queries during a random subdomain attack against a DNSSEC-signed zone. A remote attacker can send queries faster than the resolver can perform validation to cause a denial of service.

Only DNSSEC validating resolvers targeted with a random subdomain attack against a DNSSEC-signed zone are affected.


2) Input validation error (CVE-ID: CVE-2026-11721)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to poison the DNS cache.

The vulnerability exists due to improper input validation in named when processing DNS responses containing an RRSIG with fewer labels than the containing zone and wildcard records. A remote attacker can operate an authoritative zone that returns a specially crafted response to poison the DNS cache.

The issue has effect only when the resolver under attack has synth-from-dnssec yes; enabled, which is the default.


3) Reachable assertion (CVE-ID: CVE-2026-13204)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an assertion failure in the DNSSEC validation logic when validating a provably insecure domain covered by both an NSEC and NSEC3 record at the parent with an RRSIG for only one of these types. A remote attacker can provide crafted DNS data to cause a denial of service.


4) Input validation error (CVE-ID: CVE-2026-13321)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to poison the DNS cache and cause authenticated denial-of-service responses.

The vulnerability exists due to improper input validation in DNSSEC NSEC record validation when processing validly signed NSEC records whose next domain name points outside the signer's zone. A remote attacker can craft malicious NSEC records to poison the DNS cache and cause authenticated denial-of-service responses.

Exploitation requires control of any DNSSEC-signed zone.


5) Improper input validation (CVE-ID: CVE-2026-64531)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of oversized nested action attributes in openvswitch flow action construction when processing user-supplied openvswitch nested action attributes. A local user can supply specially crafted nested CLONE or CT actions to cause a denial of service.

The issue occurs because a generated nested action attribute can be closed with a truncated nla_len, causing later dump or teardown operations to walk a structurally different action stream than the one that was validated.


Remediation

Install update from vendor's website.