Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 52%

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update

0
High
Published: 08/19/2026 (08/19/2026, 10:53:50 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-9558: [MDR]: Post-upgrade (4.21 to 4.22) DRPolicy validation failure in Metro DR DFBUGS-9404: [Backport to odf-4.22.2] Adjust key rotation mismatch alert to recommend contacting support DFBUGS-9071: [4.22 clone] - must-gather Helper pod fails with "realpath: /var/lib/rook-ceph-mon/secret.keyring: No such file or directory" causing all Ceph CLI collection to be skipped DFBUGS-9018: [Backport to odf-4.22.z] minor odf-operator.v4.23.0 failing on OCP 5.0 DFBUGS-8998: [Critical] Upgrade ceph version to RHCEPH-9.1z1 at ODF-4.22.1 DFBUGS-8996: The console pod in openshift console is continuously restarting DFBUGS-8956: RHODF 4.22.2 release DFBUGS-8896: drbd-setup script fails to pull odf-drbd-rhel9 image from registry.redhat.io — unauthorized error DFBUGS-8892: [backport-4.22] ocs-client-operator fails to find CSI images ConfigMap on OCP 5.0.0 — blocks entire Ceph CSI deployment DFBUGS-8890: Failed to install ODF 4.22 on OCP 5.0 DFBUGS-8882: [TNF/ODF-4.22] Failed to deploy a drbd module in the node DFBUGS-8812: Post completion of installation for FUSION and FDF cnsa-dependencies status is reported as UNKNOWN DFBUGS-8798: [MDR] [HCI client]CephFS NetworkFence fencing fails with EACCES error when listing active MDS clients DFBUGS-8514: [Backport to odf-4.22.2] ODF 4.19 OCS Metrics Exporter not receiving Network Attachment Annotation DFBUGS-8224: [RDR] DR protection for RBD workloads fails after DR configuration DFBUGS-8201: [odf-4.22] - [GSS] Red Hat Virtualization VMs in Paused State - "VMI was paused, low-level IO error detected" w/rbd Volumes Impacted and Clients Blocklisted DFBUGS-8115: [Backport to odf-4.22.z] [RDR] [dryRun] For cephfs discovered app in deployed state, after dryRun and abort, progression changes from TestingFailover to WaitOnUserToCleanUp but changes to Completed even without workload cleanup DFBUGS-7974: [Backport to odf-4.22.1] [GSS] PDB is created for rgw even though the gateway instance count is 1 DFBUGS-7410: [RDR] [dryRun] For workload in various states, ensure dryRun test failover abort works correctly and retains workloads original state DFBUGS-6160: [GSS] Random Pod delete makes the container in openshift-storage.rbd.csi.ceph.com-nodeplugin-csi-addons restart DFBUGS-5644: Customer is able to see the alert StorageClientHeartbeatMissed constantly, roughly every 6 minutes it goes alerting and then it gets auto resolved.

Affected software

Affected versions
>=3.0.0 <3.1.1<2.4.1Red HatRed Hat Developer HubRed Hat Developer Hub 1.8amd64registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:51671ad52a7a212954d04773ac544807db4d1a67f1272d992e8bee8630d0f0c3_amd64Red Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6 for RHEL 9Network Observability (NETOBSERV)Network Observability (NETOBSERV) 1.12.0registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:b3040a476d85a4ea7f80107bb52aa07a35205df9a582275c4ea5850e134f37ed_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.16registry.redhat.io/odf4/cephcsi-rhel9@sha256:8fa720611f9480c85a98aa02820b753375e3a2b6cf3ff48c2cccfa85f252ff9d_amd64Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:dca74b10e54c6598ef2f8d962f677895ee6ca745778f0f5db25e0ebfe443990e_amd64Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9@sha256:df28004d1ccae16b592e6d4ac7ea199a412fcc30724b8ccb336ab0ec1a57739e_amd64Red Hat OpenShift Dev SpacesRed Hat OpenShift Dev Spaces 3.28registry.redhat.io/devspaces/code-rhel9@sha256:bb9e332650eb73ce20accc25d8bc73bb935e39e0bc6a9b0e7b163707ae25ce6f_amd64Red Hat DiscoveryRed Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:feab2c46a1aa558963e8931df75379d5a9ca3a8cd5a18e9d84fa088b0275044b_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux Extensions Channel (v. 10)srcrh-podman-desktop-0:1.1.1-1.el10_2.srcNetwork Observability (NETOBSERV) 1.12.2Red Hat Openshift Data Foundation 4.22registry.redhat.io/odf4/cephcsi-rhel9@sha256:f46cbaa4c84c3de5822b1fbd4556213492d519e772aee22828c17702a3262a5b_amd64Network Observability (NETOBSERV) 1.12.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 21:08:23 UTC

Technical Analysis

CVE-2026-6321 is a buffer overflow vulnerability in the cryptography library used by Red Hat Discovery, triggered when non-contiguous buffers are passed to certain Python APIs such as Hash.update(). This flaw can lead to a denial of service by crashing or restarting the affected service. The vulnerability has a CVSS 3.1 base score of 7.5 (high) with network attack vector, low complexity, no privileges required, and no user interaction. Red Hat products isolate affected services, limiting potential impact. A patch is available, and Red Hat has issued an official security advisory (RHSA-2026:20338) covering this and related CVEs.

Potential Impact

Exploitation of this vulnerability can cause a denial of service by crashing or restarting the affected service process. Due to Red Hat's default isolation of service processes, the impact is limited to the compromised service account without broader system access. There is no indication of confidentiality or integrity loss beyond the service scope. No known exploits are reported in the wild.

Mitigation Recommendations

A patch is available for this vulnerability as indicated by Red Hat's security advisory RHSA-2026:20338. Users should apply the official updates provided by Red Hat to affected products. No alternative mitigations are noted or recommended by Red Hat. The advisory emphasizes installing updated containers via discovery-installer RPM and following official documentation for deployment.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:20338
Cve Count
4
Additional Cves
["CVE-2026-39892","CVE-2026-42044","CVE-2026-44432"]
Cvss Version
null

Threat ID: 6a175ed5e29bf47b50ed924a

Added to database: 05/27/2026, 21:15:01 UTC

Last enriched: 08/10/2026, 21:08:23 UTC

Last updated: 09/04/2026, 10:52:11 UTC

Views: 237

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:20338https://access.redhat.com/security/cve/CVE-2026-39892https://access.redhat.com/security/cve/CVE-2026-42044https://access.redhat.com/security/cve/CVE-2026-44432https://access.redhat.com/security/cve/CVE-2026-6321https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/subscription_central/1-latest/#DiscoveryCanonical URLhttps://access.redhat.com/errata/RHSA-2026:26416https://access.redhat.com/security/cve/CVE-2026-33186https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26234https://access.redhat.com/security/cve/CVE-2026-24781https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-41242https://access.redhat.com/security/cve/CVE-2026-41672https://access.redhat.com/security/cve/CVE-2026-41673https://access.redhat.com/security/cve/CVE-2026-41674https://access.redhat.com/security/cve/CVE-2026-41675https://access.redhat.com/security/cve/CVE-2026-44293https://access.redhat.com/security/cve/CVE-2026-6322https://catalog.redhat.com/search?gs&searchType=containers&q=rhdhhttps://developers.redhat.com/rhdh/overviewhttps://docs.redhat.com/en/documentation/red_hat_developer_hubhttps://issues.redhat.com/browse/RHDHBUGS-3128Canonical URLhttps://access.redhat.com/errata/RHSA-2026:21338https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-41240https://access.redhat.com/security/cve/CVE-2026-42033https://access.redhat.com/security/cve/CVE-2026-42035https://access.redhat.com/security/cve/CVE-2026-42039https://access.redhat.com/security/cve/CVE-2026-42041https://access.redhat.com/security/cve/CVE-2026-42043https://issues.redhat.com/browse/RHIDP-13087https://access.redhat.com/errata/RHSA-2026:24473https://access.redhat.com/security/cve/CVE-2026-29063https://docs.openshift.com/container-platform/latest/observability/network_observability/network-observability-operator-release-notes.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:42079https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade24563332460927246658224678222477154248075624807572480761248420724853792490703Canonical URLhttps://access.redhat.com/errata/RHSA-2026:25123https://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.28/html/administration_guide/installing-devspaceshttps://access.redhat.com/security/cve/CVE-2026-42578https://access.redhat.com/security/cve/CVE-2026-42579https://access.redhat.com/security/cve/CVE-2026-42581https://access.redhat.com/security/cve/CVE-2026-42584https://access.redhat.com/security/cve/CVE-2026-42587https://access.redhat.com/security/cve/CVE-2026-43512Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37385RHEL-182245Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26068Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19238Canonical URLReference 75Reference 76Reference 77Reference 78Reference 79Reference 80Reference 81Reference 82Reference 83Reference 84Reference 85Reference 86Reference 87Reference 88Reference 89https://access.redhat.com/errata/RHSA-2026:56928https://access.redhat.com/security/cve/CVE-2026-33671https://access.redhat.com/security/cve/CVE-2026-33672https://access.redhat.com/security/cve/CVE-2026-33750https://access.redhat.com/security/cve/CVE-2026-40181https://access.redhat.com/security/cve/CVE-2026-41305https://access.redhat.com/security/cve/CVE-2026-41650https://access.redhat.com/security/cve/CVE-2026-41907https://access.redhat.com/security/cve/CVE-2026-42338https://access.redhat.com/security/cve/CVE-2026-44665https://access.redhat.com/security/cve/CVE-2026-45149https://access.redhat.com/security/cve/CVE-2026-45736https://access.redhat.com/security/cve/CVE-2026-9358Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses