RHSA-2026:57013: Red Hat OpenShift Data Foundation 4.20.17 security, enhancement & bug fix update

Published Aug 19, 2026
·
Updated

Red Hat OpenShift Data Foundation 4.20.17 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-8962: RHODF 4.20.17 releaseDFBUGS-8003: [GSS] Rook Ceph metrics are not being scraped, and the rook-ceph-mgr-external service is inaccessible from within the cluster.DFBUGS-7951: [upgrade from 4.19 to 4.20] Clusters with Convergence changes always have nfs driver deployedDFBUGS-7393: [Backport to odf-4.20.z] [MCG] noobaa-core pod restart overwrites admin account defaultresource to arbitrary backingstoreDFBUGS-7380: [Backport to odf-4.20.z] [GSS] PDB is created for rgw even though the gateway instance count is 1DFBUGS-7318: [Backport to 4.20] - noobaa-core-0 intermittent CrashLoopBackOff due to OOMKilled during object delete workload - mapdeleter unbounded memory consumptionDFBUGS-7004: [Backport to odf-4.20.z] [GSS][Disconnected env] ODF is upgraded itself from ODF v4.20.2 to ODF v4.20.7 without Manual Approval when upgrdaing OCP v4.20.5 to OCP v4.20.16DFBUGS-6997: [Backport to odf-4.20.z] [GSS][ODF] Noobaa DBCLEANER not honoring set valueDFBUGS-6814: release-4.20 ODF must-gather missing CR storageclusterpeer.yamlDFBUGS-5767: [4.20.z] Landing page after installation of operator is not correct

Affected Software

1 affected component
Red Hat OpenShift Data Foundation=4.20.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Red Hat OpenShift Data Foundation to a version that resolves this vulnerability.

    Fixed in 4.20.17
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-8962
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-8003
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-7951
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-7393
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-7380
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-7318
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-7004
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-6997
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-6814
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch DFBUGS-5767

Event History

Aug 19, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

Does the available advisory information identify specific CVEs or security impact details?

No. The provided information labels this as a security, enhancement, and bug fix update, but it does not list CVEs, affected components for security issues, or exploitation details.

2

What operational problems addressed by this update may be relevant to existing clusters?

The listed fixes include missing Rook Ceph metric scraping, inaccessible rook-ceph-mgr-external service access within a cluster, an intermittent noobaa-core CrashLoopBackOff caused by OOMKilled during object deletion, and unintended ODF upgrades in disconnected environments.

3

Is there a fix for unexpected changes to the NooBaa administrator default resource?

Yes. The update lists a fix for noobaa-core pod restarts overwriting the admin account default_resource with an arbitrary backing store.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203