Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-33036 — fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
🎯 Affected products82
- Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:a33a373914b9eb2ea271e8b3301598d0bb3fb98a782ad702f192d9bd1ff4c3a1_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:46748251be5edd0f4f95c428805ab301d780a53c0b971b29320022cb419e617c_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:90dbb2d2ceb32e43f0c6cace5577b334ff24668c2ccc856021c8783f080afeee_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:9cfaf068461013f6a57f35eba7569a5fbc547d44f7d41fba8b66a1ab54dfefbf_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:bfb9d3a0a263b4df2ec5f3b8ec50005908e1d53cdb79a4cf0f47549f175fd8c5_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:4fa3d35d6a129ff865be3cb7d0ed8a8a1d7171e447d3c7a24eb80321ebfb5c09_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:617e508dec70b2a6c487ca529121c84a2d84c0c3de0093c153d37b744a1e9422_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:ce15dfc0be507039379451792186dfef6b203c8243e1931886344006f2a9d565_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:04bb02437d6202fe5ed384d626dd0953f70689f68cd71a0d027ccb80fbcee64f_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:6620c020e6706ebfb7a4267dcc0106f913d37f7274af1c21dab5096bf1b9dc31_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:f6df78dce17d45a8d8160895d03da954443904f7a3d0211ffb1973fc9375ce88_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:fad44ef494f51a96438fe77c3bbdf3a1175057504293103edb49b1bbdcfceae8_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:3b1f9772e8ffba1d4cc664fbec3a7c43b13887d0dddaa33a7f3412529c94a379_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:3e8979947f6eed5d98a84b708a776bbb6d5948b83c8fdfad79f5e8238cdb6988_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:56323010958a7a0b769d363cce7ba224bed26db91d9e9149624e5658d098d8f0_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:883a1e88a497e6c04e5079f2f698c12901f07577e02ba1fd003c5171581687f7_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:371c2ab993d019f1389d32f97a3ce88e5b80a5f89a21a4344f8be2035b0a101d_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:4353b412c55a8891f7fbc4129343cc923b3f9d926f5409833ac6c30db33a9156_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:b423a54741e203c436d711b38ee96a096a3c318a53a8623a6df1bec1b6f1b470_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:7c0ba4f6576b19ab7282686998e768a2862e8e84825d6c117e2397c1a35dd69f_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:470404644ec1f361908e5297b6f423a89ba3cca23d4d5d3bcb4a64b397fe9ecf_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:7eca67fe1b479eafe4f20cc92f30147f2391ea71e920edae7b738c448fa47aed_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:81233957911937ee5f92451c000ea74632017a67ffe1763d6f8ec2e31b4c8177_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:8c963cf57c9bd34720cabdefdff27f6489116fff47ff213eeea80e187e230503_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:ab213ac11247b14abc62ef19c4d5b3ec0bba8f5b2b64d40511b3563e38beee0f_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:e33377b818b1dd9879d5beb5133ec7b0d06310dee9e8959e5381169254a5303a_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:ec4a752f159c7e8e49eecc57f54093f6bcf7c9094e67172643336c1fce443a92_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-operator-bundle@sha256:6025f18fc328f63338f1141e67bcd265d977d6b7ea27058c8bcc2c3a61963063_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:08577b1c1c19e28ccf2a8869763ac00a4989ad788f996a15f3f43f37e592144d_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- +52 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.18/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:17547
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2026-33036
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17547.json