Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update
Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-9558: [MDR]: Post-upgrade (4.21 to 4.22) DRPolicy validation failure in Metro DR DFBUGS-9404: [Backport to odf-4.22.2] Adjust key rotation mismatch alert to recommend contacting support DFBUGS-9071: [4.22 clone] - must-gather Helper pod fails with "realpath: /var/lib/rook-ceph-mon/secret.keyring: No such file or directory" causing all Ceph CLI collection to be skipped DFBUGS-9018: [Backport to odf-4.22.z] minor odf-operator.v4.23.0 failing on OCP 5.0 DFBUGS-8998: [Critical] Upgrade ceph version to RHCEPH-9.1z1 at ODF-4.22.1 DFBUGS-8996: The console pod in openshift console is continuously restarting DFBUGS-8956: RHODF 4.22.2 release DFBUGS-8896: drbd-setup script fails to pull odf-drbd-rhel9 image from registry.redhat.io — unauthorized error DFBUGS-8892: [backport-4.22] ocs-client-operator fails to find CSI images ConfigMap on OCP 5.0.0 — blocks entire Ceph CSI deployment DFBUGS-8890: Failed to install ODF 4.22 on OCP 5.0 DFBUGS-8882: [TNF/ODF-4.22] Failed to deploy a drbd module in the node DFBUGS-8812: Post completion of installation for FUSION and FDF cnsa-dependencies status is reported as UNKNOWN DFBUGS-8798: [MDR] [HCI client]CephFS NetworkFence fencing fails with EACCES error when listing active MDS clients DFBUGS-8514: [Backport to odf-4.22.2] ODF 4.19 OCS Metrics Exporter not receiving Network Attachment Annotation DFBUGS-8224: [RDR] DR protection for RBD workloads fails after DR configuration DFBUGS-8201: [odf-4.22] - [GSS] Red Hat Virtualization VMs in Paused State - "VMI was paused, low-level IO error detected" w/rbd Volumes Impacted and Clients Blocklisted DFBUGS-8115: [Backport to odf-4.22.z] [RDR] [dryRun] For cephfs discovered app in deployed state, after dryRun and abort, progression changes from TestingFailover to WaitOnUserToCleanUp but changes to Completed even without workload cleanup DFBUGS-7974: [Backport to odf-4.22.1] [GSS] PDB is created for rgw even though the gateway instance count is 1 DFBUGS-7410: [RDR] [dryRun] For workload in various states, ensure dryRun test failover abort works correctly and retains workloads original state DFBUGS-6160: [GSS] Random Pod delete makes the container in openshift-storage.rbd.csi.ceph.com-nodeplugin-csi-addons restart DFBUGS-5644: Customer is able to see the alert StorageClientHeartbeatMissed constantly, roughly every 6 minutes it goes alerting and then it gets auto resolved.
AI Analysis
Technical Summary
CVE-2026-6321 is a buffer overflow vulnerability in the cryptography library used by Red Hat Discovery, triggered when non-contiguous buffers are passed to certain Python APIs such as Hash.update(). This flaw can lead to a denial of service by crashing or restarting the affected service. The vulnerability has a CVSS 3.1 base score of 7.5 (high) with network attack vector, low complexity, no privileges required, and no user interaction. Red Hat products isolate affected services, limiting potential impact. A patch is available, and Red Hat has issued an official security advisory (RHSA-2026:20338) covering this and related CVEs.
Potential Impact
Exploitation of this vulnerability can cause a denial of service by crashing or restarting the affected service process. Due to Red Hat's default isolation of service processes, the impact is limited to the compromised service account without broader system access. There is no indication of confidentiality or integrity loss beyond the service scope. No known exploits are reported in the wild.
Mitigation Recommendations
A patch is available for this vulnerability as indicated by Red Hat's security advisory RHSA-2026:20338. Users should apply the official updates provided by Red Hat to affected products. No alternative mitigations are noted or recommended by Red Hat. The advisory emphasizes installing updated containers via discovery-installer RPM and following official documentation for deployment.
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-9558: [MDR]: Post-upgrade (4.21 to 4.22) DRPolicy validation failure in Metro DR DFBUGS-9404: [Backport to odf-4.22.2] Adjust key rotation mismatch alert to recommend contacting support DFBUGS-9071: [4.22 clone] - must-gather Helper pod fails with "realpath: /var/lib/rook-ceph-mon/secret.keyring: No such file or directory" causing all Ceph CLI collection to be skipped DFBUGS-9018: [Backport to odf-4.22.z] minor odf-operator.v4.23.0 failing on OCP 5.0 DFBUGS-8998: [Critical] Upgrade ceph version to RHCEPH-9.1z1 at ODF-4.22.1 DFBUGS-8996: The console pod in openshift console is continuously restarting DFBUGS-8956: RHODF 4.22.2 release DFBUGS-8896: drbd-setup script fails to pull odf-drbd-rhel9 image from registry.redhat.io — unauthorized error DFBUGS-8892: [backport-4.22] ocs-client-operator fails to find CSI images ConfigMap on OCP 5.0.0 — blocks entire Ceph CSI deployment DFBUGS-8890: Failed to install ODF 4.22 on OCP 5.0 DFBUGS-8882: [TNF/ODF-4.22] Failed to deploy a drbd module in the node DFBUGS-8812: Post completion of installation for FUSION and FDF cnsa-dependencies status is reported as UNKNOWN DFBUGS-8798: [MDR] [HCI client]CephFS NetworkFence fencing fails with EACCES error when listing active MDS clients DFBUGS-8514: [Backport to odf-4.22.2] ODF 4.19 OCS Metrics Exporter not receiving Network Attachment Annotation DFBUGS-8224: [RDR] DR protection for RBD workloads fails after DR configuration DFBUGS-8201: [odf-4.22] - [GSS] Red Hat Virtualization VMs in Paused State - "VMI was paused, low-level IO error detected" w/rbd Volumes Impacted and Clients Blocklisted DFBUGS-8115: [Backport to odf-4.22.z] [RDR] [dryRun] For cephfs discovered app in deployed state, after dryRun and abort, progression changes from TestingFailover to WaitOnUserToCleanUp but changes to Completed even without workload cleanup DFBUGS-7974: [Backport to odf-4.22.1] [GSS] PDB is created for rgw even though the gateway instance count is 1 DFBUGS-7410: [RDR] [dryRun] For workload in various states, ensure dryRun test failover abort works correctly and retains workloads original state DFBUGS-6160: [GSS] Random Pod delete makes the container in openshift-storage.rbd.csi.ceph.com-nodeplugin-csi-addons restart DFBUGS-5644: Customer is able to see the alert StorageClientHeartbeatMissed constantly, roughly every 6 minutes it goes alerting and then it gets auto resolved.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-6321 is a buffer overflow vulnerability in the cryptography library used by Red Hat Discovery, triggered when non-contiguous buffers are passed to certain Python APIs such as Hash.update(). This flaw can lead to a denial of service by crashing or restarting the affected service. The vulnerability has a CVSS 3.1 base score of 7.5 (high) with network attack vector, low complexity, no privileges required, and no user interaction. Red Hat products isolate affected services, limiting potential impact. A patch is available, and Red Hat has issued an official security advisory (RHSA-2026:20338) covering this and related CVEs.
Potential Impact
Exploitation of this vulnerability can cause a denial of service by crashing or restarting the affected service process. Due to Red Hat's default isolation of service processes, the impact is limited to the compromised service account without broader system access. There is no indication of confidentiality or integrity loss beyond the service scope. No known exploits are reported in the wild.
Mitigation Recommendations
A patch is available for this vulnerability as indicated by Red Hat's security advisory RHSA-2026:20338. Users should apply the official updates provided by Red Hat to affected products. No alternative mitigations are noted or recommended by Red Hat. The advisory emphasizes installing updated containers via discovery-installer RPM and following official documentation for deployment.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20338
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-39892","CVE-2026-42044","CVE-2026-44432"]
- Cvss Version
- null
Threat ID: 6a175ed5e29bf47b50ed924a
Added to database: 05/27/2026, 21:15:01 UTC
Last enriched: 08/10/2026, 21:08:23 UTC
Last updated: 09/04/2026, 10:52:11 UTC
Views: 237
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.