RHSA-2026:22382: Red Hat OpenShift Data Foundation 4.21.6 security, enhancement & bug fix update
Red Hat OpenShift Data Foundation 4.21.6 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-6964: RHODF 4.21.6 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat OpenShift Data Foundation (RHODF)to a version that resolves this vulnerability.Fixed in 4.21.6 - Upgrade
Upgrade
NGINX (bundled with RHODF)to a version that resolves this vulnerability.Fixed in 4.21.6Patch DFBUGS-6964
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:22382?
RHSA-2026:22382 has a risk level of 80, indicating a significant security concern.
How do I fix RHSA-2026:22382?
To fix RHSA-2026:22382, you should update your Red Hat OpenShift Data Foundation to version 4.21.6 or later.
What vulnerabilities are addressed in RHSA-2026:22382?
RHSA-2026:22382 addresses an Arbitrary Code Execution Vulnerability in NGINX, identified as CVE-2026-42945.
Is RHSA-2026:22382 applicable to all versions of OpenShift Data Foundation?
No, RHSA-2026:22382 specifically applies to the Red Hat OpenShift Data Foundation version 4.21.6.
What should I do if I cannot update to address RHSA-2026:22382?
If you cannot update, consider applying workarounds or mitigating controls recommended by Red Hat until the update can be performed.