Where
-Infinity
0

Red Hat OpenShift Data Foundation 4.20.17 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-8962: RHODF 4.20.17 releaseDFBUGS-8003: [GSS] Rook Ceph metrics are not being scraped, and the rook-ceph-mgr-external service is inaccessible from within the cluster.DFBUGS-7951: [upgrade from 4.19 to 4.20] Clusters with Convergence changes always have nfs driver deployedDFBUGS-7393: [Backport to odf-4.20.z] [MCG] noobaa-core pod restart overwrites admin account defaultresource to arbitrary backingstoreDFBUGS-7380: [Backport to odf-4.20.z] [GSS] PDB is created for rgw even though the gateway instance count is 1DFBUGS-7318: [Backport to 4.20] - noobaa-core-0 intermittent CrashLoopBackOff due to OOMKilled during object delete workload - mapdeleter unbounded memory consumptionDFBUGS-7004: [Backport to odf-4.20.z] [GSS][Disconnected env] ODF is upgraded itself from ODF v4.20.2 to ODF v4.20.7 without Manual Approval when upgrdaing OCP v4.20.5 to OCP v4.20.16DFBUGS-6997: [Backport to odf-4.20.z] [GSS][ODF] Noobaa DBCLEANER not honoring set valueDFBUGS-6814: release-4.20 ODF must-gather missing CR storageclusterpeer.yamlDFBUGS-5767: [4.20.z] Landing page after installation of operator is not correct

First published (updated )
Race Condition

Red Hat OpenShift Data Foundation 4.21.11 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-9563: [Backport to odf-4.21.10] Race condition may allow multiple CephCluster reconciles in parallelDFBUGS-8999: [odf-4.21] - [GSS] Red Hat Virtualization VMs in Paused State - "VMI was paused, low-level IO error detected" w/rbd Volumes Impacted and Clients BlocklistedDFBUGS-8997: [4.21] CLONE - The console pod in openshift console is continuously restartingDFBUGS-8957: RHODF 4.21.11 releaseDFBUGS-8200: [Backport to odf-4.21.z] - [GSS] Red Hat Virtualization VMs in Paused State - "VMI was paused, low-level IO error detected" w/rbd Volumes Impacted and Clients BlocklistedDFBUGS-7048: Hide data replication separation option from UI in 4.21 as its not supportedDFBUGS-7003: [Backport to odf-4.21.z] [GSS][Disconnected env] ODF is upgraded itself from ODF v4.20.2 to ODF v4.20.7 without Manual Approval when upgrdaing OCP v4.20.5 to OCP v4.20.16DFBUGS-6995: [Backport to odf-4.21.z] [GSS][ODF] Noobaa DBCLEANER not honoring set valueDFBUGS-6938: [4.21.z] Integrate ibm-storage-odf-operator 1.9.0DFBUGS-6813: release-4.21 - ODF must-gather missing CR storageclusterpeer.yamlDFBUGS-6510: CLONE 4.21 - Object Browser sends unnecessary getObject API callsDFBUGS-6471: CLONE - In storage cluster UI page , tick mark background colour changed from green to black in 4.22DFBUGS-5965: [OLS]: RAG content image is using ODF 4.20 documentation when deployed on OCP/ODF 4.21DFBUGS-4988: ocs-metrics-exporter does not provide metrics during cache refresh

First published (updated )

Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-9558: [MDR]: Post-upgrade (4.21 to 4.22) DRPolicy validation failure in Metro DRDFBUGS-9404: [Backport to odf-4.22.2] Adjust key rotation mismatch alert to recommend contacting supportDFBUGS-9071: [4.22 clone] - must-gather Helper pod fails with "realpath: /var/lib/rook-ceph-mon/secret.keyring: No such file or directory" causing all Ceph CLI collection to be skippedDFBUGS-9018: [Backport to odf-4.22.z] minor odf-operator.v4.23.0 failing on OCP 5.0DFBUGS-8998: [Critical] Upgrade ceph version to RHCEPH-9.1z1 at ODF-4.22.1DFBUGS-8996: The console pod in openshift console is continuously restarting DFBUGS-8956: RHODF 4.22.2 releaseDFBUGS-8896: drbd-setup script fails to pull odf-drbd-rhel9 image from registry.redhat.io — unauthorized errorDFBUGS-8892: [backport-4.22] ocs-client-operator fails to find CSI images ConfigMap on OCP 5.0.0 — blocks entire Ceph CSI deploymentDFBUGS-8890: Failed to install ODF 4.22 on OCP 5.0DFBUGS-8882: [TNF/ODF-4.22] Failed to deploy a drbd module in the nodeDFBUGS-8812: Post completion of installation for FUSION and FDF cnsa-dependencies status is reported as UNKNOWNDFBUGS-8798: [MDR] [HCI client]CephFS NetworkFence fencing fails with EACCES error when listing active MDS clientsDFBUGS-8514: [Backport to odf-4.22.2] ODF 4.19 OCS Metrics Exporter not receiving Network Attachment AnnotationDFBUGS-8224: [RDR] DR protection for RBD workloads fails after DR configurationDFBUGS-8201: [odf-4.22] - [GSS] Red Hat Virtualization VMs in Paused State - "VMI was paused, low-level IO error detected" w/rbd Volumes Impacted and Clients BlocklistedDFBUGS-8115: [Backport to odf-4.22.z] [RDR] [dryRun] For cephfs discovered app in deployed state, after dryRun and abort, progression changes from TestingFailover to WaitOnUserToCleanUp but changes to Completed even without workload cleanupDFBUGS-7974: [Backport to odf-4.22.1] [GSS] PDB is created for rgw even though the gateway instance count is 1DFBUGS-7410: [RDR] [dryRun] For workload in various states, ensure dryRun test failover abort works correctly and retains workloads original stateDFBUGS-6160: [GSS] Random Pod delete makes the container in openshift-storage.rbd.csi.ceph.com-nodeplugin-csi-addons restartDFBUGS-5644: Customer is able to see the alert StorageClientHeartbeatMissed constantly, roughly every 6 minutes it goes alerting and then it gets auto resolved.

First published (updated )

Red Hat OpenShift Data Foundation 4.19.22 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7382: [Backport to odf-4.19.z] [GSS] PDB is created for rgw even though the gateway instance count is 1DFBUGS-7005: [Backport to odf-4.19.z] [GSS][Disconnected env] ODF is upgraded itself from ODF v4.20.2 to ODF v4.20.7 without Manual Approval when upgrdaing OCP v4.20.5 to OCP v4.20.16DFBUGS-6996: [Backport to odf-4.19.z] [GSS][ODF] Noobaa DBCLEANER not honoring set valueDFBUGS-6815: release-4.19 ODF must-gather missing CR storageclusterpeer.yamlDFBUGS-6704: Backport to odf-4.19.z [GSS] Unnecessary OSD redeployments on 4.19.z upgrade for already-encrypted OSDsDFBUGS-5636: [4.19]Topology awareness issueDFBUGS-3947: 4.19 [RDR] cephblockpool radosnamespaces contains "failed to retrieve mirroring pool ocs-storagecluster-cephblockpool" message after the uninstallation of DR

First published (updated )

Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7383: [Backport to odf-4.18.z] [GSS] PDB is created for rgw even though the gateway instance count is 1DFBUGS-6998: [Backport to odf-4.18.z] [GSS][ODF] Noobaa DBCLEANER not honoring set value

First published (updated )
Severity
7

Red Hat OpenShift Data Foundation 4.22.0 security, enhancement & bug fix update

1 / 2
Source: Red Hat
First published (updated )

Red Hat OpenShift Data Foundation 4.21.6 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-6964: RHODF 4.21.6 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.20.13 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7039: RHODF 4.20.13 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.17.27 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7033: RHODF 4.17.27 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.15.29 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-6992: RHODF 4.15.29 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.19.18 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7031: RHODF 4.19.18 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.14.33 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-6993: RHODF 4.14.33 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.18.23 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7032: RHODF 4.18.23 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )

Red Hat OpenShift Data Foundation 4.16.29 security, enhancement & bug fix updateFIXED BUGS:==========DFBUGS-7034: RHODF 4.16.29 releaseNGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)

First published (updated )
Severity
4

Red Hat OpenShift Data Foundation 4.16 security, enhancement & bug fix update

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.16/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf" target="_blank">https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.16/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf</a>
First published (updated )
Severity
7
XSS

Important: RHODF-4.16-RHEL-9 security update

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenShift Data Foundation 4.15.14 Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenShift Data Foundation 4.17.7 Bug Fix Update

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenShift Data Foundation 4.18.3 Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
XSS

Important: RHODF-4.18-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHODF-4.14-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHODF-4.15-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHODF-4.17-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHODF-4.16-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Input Validation

Important: RHODF-4.18-RHEL-9 enhancement, bug fix and security update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Input Validation

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.Security Fix(es): go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104) node-gettext: Prototype Pollution (CVE-2024-21528) PostCSS: Improper input validation in PostCSS (CVE-2023-44270) golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

First published (updated )
Severity
7
Input Validation

Important: RHODF-4.17-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Input Validation

Important: RHODF-4.16-RHEL-9 security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenShift Data Foundation 4.17.3 Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenShift Data Foundation 4.16.6 Bug fix update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203