RHSA-2026:3122HighCVSS 7.7

Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 director Operator container images

Published
February 23, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-25621 — github.com/containerd/containerd: containerd local privilege escalation CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS

🎯 Affected products5

  • Red Hat OpenStack Platform 16.2
  • registry.redhat.io/rhosp-rhel8/osp-director-agent@sha256:26005fbf7d5e2b62db9368a3ec4858c22c653e45abe328feda7dc26e3039b355_amd64 as a component of Red Hat OpenStack Platform 16.2
  • registry.redhat.io/rhosp-rhel8/osp-director-downloader@sha256:3e44aea04cf6633eeafba0cbd902447bcb76a46d299cce6eaccf0ee92f1d3988_amd64 as a component of Red Hat OpenStack Platform 16.2
  • registry.redhat.io/rhosp-rhel8/osp-director-operator-bundle@sha256:52d027283d31a428616b90315b0d67f489770e05260cebe35725f18d6f60ad3f_amd64 as a component of Red Hat OpenStack Platform 16.2
  • registry.redhat.io/rhosp-rhel8/osp-director-operator@sha256:74254effff84e9bfe9bca9dcf1d1b9c1cccbe5e874fbd6c34c86c257670480d8_amd64 as a component of Red Hat OpenStack Platform 16.2

✅ Remediation

The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io or registry.access.redhat.com using the 'podman pull' command. For more information about the images, search the image name in the Red Hat Ecosystem Catalog. Workaround: The system administrator on the host can manually chmod the directories to not have group or world accessible permissions: ``` chmod 700 /var/lib/containerd chmod 700 /run/containerd/io.containerd.grpc.v1.cri chmod 700 /run/containerd/io.containerd.sandbox.controller.v1.shim ``` An alternative mitigation would be to run containerd in rootless mode. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

🔗 References (6)