RHSA-2026:56968HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.21.11 security, enhancement & bug fix update

Published
August 19, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

🎯 Affected products112

  • Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:16d7a55184a892c6bcf71b9974da1b5563a66758c9b874c38894c88ab0e58c0f_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:098e17d44639c23c2dc7fe1b60cb5ad15a7af1f68ab771ef85843a1db245447c_arm64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:3aa99754137309d98e2df4fc5f41fc30d8a7f82d5241cfe6f015f5fe1dc92d87_ppc64le as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:67558b6f4ae7e84f2461518a68b1c47206c455c898d76c799b58d3aa969ce3bb_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:ddcf39e8ce0f92557d43d4da7b187778d84bda2869cb442e7d71f8d4f72e400d_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:83237116629c7b841876eeb0ee44a1b5d2aeb367e4f45378cf826ebcdb252fc8_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:9ea718a3a96c44bcce3e66d59db0d24369080f5a4dd296b320c5a5dac577f694_arm64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:a2b9501223f1b71129aba03b1602c71a240eb3d64f0e8868f703acd2007404eb_ppc64le as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:a381b47d7206d459948d6263d9332065dbe0ddf179aa27869a5ccd50ed328073_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/devicefinder-rhel9@sha256:0f6e9669d79035368be36339aa70d6657836fa599952e0c57581d72de1b689b8_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/devicefinder-rhel9@sha256:2a0bf7cb09b465d6a717df233ab58b0b5cfe73054ea2243e3831062846d8ad56_arm64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/devicefinder-rhel9@sha256:99e79e1337e2b4b470d27823ddd08fcd3a4f9d12f050f13ebf0d09250c8bdb69_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/devicefinder-rhel9@sha256:adc08a51dc66724d02e64b9f40e3c53210de3c4d236fd54499a955a661c6ddd5_ppc64le as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:5296cf9cb65c354441801ebf9490f8d1d4f6cee09b433135e7a55a8aba7a753d_arm64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:58f2db382868e63c6d5fc1fa5762199026026cf128afcc5da5abbf6194f225bd_ppc64le as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:76cd00d6333754fad4fa125f908f4deb11c88727bb37c13c2aaa1648c7f68ff8_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:ef9fad3ce2f95c355a501131b5004a30c65af85a58f2ec0f5e0544e277450263_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:4c0e43f6354e794df76b81d85f6e5aecdea11978e893a3ea13fd4b23f5ecf196_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:2325522a398d1626ac418f39a25bd039a93f587609a6536e69a2b691344f8832_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:7388db0d01237c5bbbe1ba78008bf43c96b539d52764853c1e399458e8f14a84_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:79bb6185ab45511c0f6830b269fdc0cd32a5b83477423f64f0682a217eaa9496_arm64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:8aa46ae1a1eefebed1b574d96b52620deb1ac975dd599fd5e3fdfde641dc70fe_ppc64le as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:1f3a38eda3ff55a02a89558c53f2cdf6f99a08658f493da03edb3139570b1550_arm64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:60fb0d90e5b09ea304fc5a7c550cef7ad312a2cb29218e1c9cd1dbfc94b02de0_ppc64le as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:80af9acdea913d4ebb2e302bc0da953c38da21faee3bbcc2f78180c5687effd4_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:b397fed3d2de921a0a45c38ffc318f2d7540edde6323d106aa1dc7f9a1131a71_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:f6dcaeae2b040a59f6806860237773c33702dc04e4b1fa496300cbfa69ed2135_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:0b574ac52b3a46e7ee06cff731341afdc5ba3d60486bbab555dc4a043295556c_s390x as a component of Red Hat Openshift Data Foundation 4.21
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:435f560565844449ed8b4ce5cb73c247c92b7c25c16516918aa8dff4f8aae7fb_amd64 as a component of Red Hat Openshift Data Foundation 4.21
  • +82 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.21/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)