RHSA-2026:2155HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.17 security, enhancement & bug fix update

Published
February 5, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2025-47907 — database/sql: Postgres Scan Race Condition

🎯 Affected products81

  • Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:a9ff9039f22a14b7c525b987822b02ad79dad3c4f435ee6d58d4abf9eb3d0fe0_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:36a63eadef61c38463ef5a4e823e37c3cf1fe9e679b68264cffdbb0d86edf751_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:52dc31183581360f901c73453f3afded6fd8f3b130e3ba4c59c1aaa3be9ec583_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:78742368c1679a1b69b6ef55c72c8ecbe3204f6ecf701622e7c7b298c484b2ec_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:98f64aaedf7451ca596f3cf8fd083bf5375a2ce3063c61b24c08b348b97cba73_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:0f428fbc2f749cb0a303b67b60282cf4908954fda072c8174fa7d798c1b0920c_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:2fb82dda2876c10013db5749ad2afd499d3e874c5e1f35afb4f890a4c8b60dfc_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:4d3c437f41c235f509892e4d2c1565fef4e5cc33381c8bedad30ff83408915cf_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:07f7d48437f0c0b9b7fe8ae2c7eed250f74b9e88fd8fd3214920ae39902b77eb_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:1315e5acfb0745d2b872d8856de90b117f63ea63e7b136f73362f51f3b3f32ea_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:ca4be2c61f049b117224fced3f3a2f740137b99d5f43dee915920ebea415b3d7_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:95dd96ba09bb2d62b6f736e1601ae37c262e38a1dcb8c0b5c3ee702286fab1dd_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:60aa3602cd7f640ded7db53022505c993b91429c45e6f1835a4edf45d1ed76ba_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:6e5ca922208fa04bae7aa4925627b2910ec5027c8323616f468087ea10be7dfe_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:879220d91be576939ca9f26a9f0b46e0bdcc340788bea75dfff13957276afd12_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:9d53bd43800e27cc3e9c4b3536cd944282068042a03e4ed158ae7ea568eb67bb_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:76689e75a38f9c07f976fcba259a1fb26887bdddf6aa9d10c27e15bf761930b0_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:b464a969642a0348dfb131a1a6a5db8e293370c75b0ed48e1a0c6860cf51a233_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:c424e2d14cf3369b5ed0c3108f658b3c9a024ecde76aed9a9da08d18206069e6_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:e7461dfd9c921498bca83758201156ab55237c25402022b144840f7baa8c3d59_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:5c0296b45947ea919285fb2b6d4ec2d2df98a8151454d2cc06408f18e836a893_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:bec544255599b80992347e6a6e3c45c6a191fa860306a8ce616f1e33ee70ef53_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:eceef4815ac7604575be589dd68553c5acd78b5dbbfd0271c4058bfca6d3034a_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:f836eea45a0944160ced7286aa720ab8261d6a2f4511d68144ee03b0af2b4ea1_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:3bf6d6a9f9ddd15bc57142e19da42bee30bfc528d7e8d827b62d0fc36f5b1476_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:df93509dffc184bcf6eefddd397017b24ea07ce24858c790ecfacfffc91bc71c_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:e23e303705ae4eb6903e557fb55a8e4211b61dd603dcab9ab1d0a7eda1e7cd16_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-operator-bundle@sha256:c67bf6279d530ea4ab96ee0a30e142c33676d50961e212baa26ca08daf4fb602_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:05c842a35c6cb9d6edc5d501de57dadbf7e93671a87e516eadfd9ea0da7c298e_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • +51 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.17/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (6)