OCP AWS EBS and oVirt CSI drivers use "hostNetwork: true" and at the same time they use port 9808 for their liveness probes. Since range 9000 - 9999 is required to be accessible "All machines to all machines" in our docs [1], the liveness probe is accessible from all machines, which is not really wanted. Liveness probe should be accessible from the host only. 1: https://github.com/openshift/openshift-docs/blob/master/modules/installation-network-user-infra.adoc
Enhancement with port allocation has been merged: https://github.com/openshift/enhancements/pull/479 Trying to catch 4.6
Verified with: 4.6.0-0.nightly-2020-09-24-235241
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (OpenShift Container Platform 4.6 GA Images), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4196