Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.32 security, enhancement & bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-52881 — runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
🎯 Affected products73
- Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:7636fee1502c605e0750dec101d6b80c7364d4a0ce0c577a5440874443089ea4_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:e815f903dcbdf54273354bef1235c3569f383985500afe2e7af89ae2687d379f_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:e86f9ae265d624026d1a4deaefd5831ff88fa8c43b98a029ae6b6cd34ca307a3_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:0e5acd681f9b29add1d7286c624bf9963df12560ebac2e81ce27a74a06ccb19b_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:17657e817449a8f09c5e72e7327812436bf9a88a8b0459d8e082d0807f28b015_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:2f8ae65fb61862d0134306f8fa40c651f8ef3af073c7332986b5d7aa7fe813b5_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:f13f245be1ba88ce20b5354e61fcca3ece1728391f60f4acd80538cde0ceb398_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:6643dfb5165db59882d07c9b346c45cf59ff0c8d4bb67f6f3c9df792a5111ba2_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:778ccfab38238a3bf2371008b8c9aba79978c85015b4115047d6d7bf6cec620b_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:edb139f3ac615e35346ef5193cbc6ce4ad2b4de080f1b4411c01003d20c1949e_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:3d3e9a252cf614a7023656048f34286b35e999a023873e12b95c3f9970014aa2_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:ad1944ce8966af258930fdf524a06b13a820a39ca23a9518d38a290a080c5e98_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:bc6ec7c8d4392c02d94ebd167a30d48d5a260bb9c98c8ccace0fa27072656a91_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:c9179cca481e71e43326dabfdf18667611f36e479a1ee15617da550b64ceb1d1_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:efdd8fda819419a495decbb988970f15dec7386fc9a4031f1c0ac26c83b83b17_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:4d68f9835986b1d23b67799901351c4c7102daf3ab91e24d9ed2f3db6b2cf358_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:74bed9873406cab704348fb7d807fecb19e2dce7ab3bd96eb4a5ae2be840f2cd_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:e55606adf99a1e208fccabb6d2aad37df187d2315789795c295df94324e29a4b_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:327730f3c734d69512557014969170e5e41220af2685a8ab9e7bf87444c316f8_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:18ffbe6282c685479ae2897c07ca800e71504707992b87837874b1ea7b5b8d61_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:1c030a9d83c25cfa5f3861f95c607bd129c59af34dbe3071bce9c3fafc226958_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:1d7710191f033bc8ec6d517d39e0c5ff4f08a698687fa7410c230960a8cddd43_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:38178d06f71418180365aad12adf2fc5076fa8648725d7790432764a76038f35_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:68af5f206f7d84a1d07ee15a166b0e9569edc4668cf2a54dc58577383f74f86d_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:b5ce616893e2213d9ed1c7d4088788dcd5cab5e0d644e92fb1d787d298f6f6f7_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:cf296ff05e38fe5129028e9a207115944f37a0b1a399febb10c2196849282a3d_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-operator-bundle@sha256:ef48d8f29b24a2cc8e6276ffda8249783fe962fc1b41c89c268e664935781421_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:2d04ec7e9b8587b6a258b4107678de764893fd3f2a0429eb74a1e7dfca0e56b3_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:55c6ba6875b2130896e0b3cd3c1820973193500cfc549e69df47b19668c5ba00_s390x as a component of Red Hat Openshift Data Foundation 4.14
- +43 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.14/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Potential mitigations for this issue include: * Using rootless containers, as doing so will block most of the inadvertent writes (runc would run with reduced privileges, making attempts to write to procfs files ineffective). * Based on our analysis, neither AppArmor or SELinux can protect against the full version of the redirected write attack. The container runtime is generally privileged enough to write to arbitrary procfs files, which is more than sufficient to cause a container breakout.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:19244
- externalhttps://access.redhat.com/security/cve/CVE-2025-52881
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19244.json