Skip to main content
EPSS 0.7%top 47%

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update

0
High
Published: 07/20/2026 (07/20/2026, 09:45:40 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-7342: RHODF 4.19.20 release DFBUGS-7332: [Backport for 4.19] - [GSS][ODF][MCG] noobaa-db-pg-cluster won't synchronize anymore - "could not receive data from WAL stream: ERROR: requested WAL segment 00000008000001C600000068 has already been removed" DFBUGS-6940: [4.19.z] Integrate ibm-storage-odf-operator 1.9.0 DFBUGS-6542: [ODF 4.19.z CLONE] - Provider Server sends sub channel to client only when provider side csv is at the tip of the sub channel in the catalogsource DFBUGS-6529: [Backport to 4.19.z] maintenance mode is always set for storageclients in non RDR clusters DFBUGS-6523: CLONE 4.19 - [UI] Resource profile calculations doesn't include NFS DFBUGS-4768: [Backport to odf-4.19.z]Remove duplicate PersistentVolumeUsageCritical alerts

Affected software

Affected versions
Red HatRed Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 2.6amd64registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:add09864ea186e10cbf36efa26c5e2be626c6e2a47726379d209e5a6cc5698fe_amd64Red Hat QuayRed Hat Quay 3.16registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:4061bfdf8eebf9aa51a7701a685daa5ef97741adab368a7c9c03fd9d01dd63ee_amd64Migration Toolkit for VirtualizationMigration Toolkit for Virtualization 2.9registry.redhat.io/migration-toolkit-virtualization/mtv-api-rhel9@sha256:487ad1c29aa180f6f76a74b87c285363aedcf87dadf00bde599a2ebf3790156d_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.2registry.redhat.io/odf4/cephcsi-rhel9@sha256:ffd512657b2587866bdd42012599027977206f8a1a11ea1119c1349e646d2ddf_amd64Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9@sha256:62dd37ed631205c855b9438396987008c5db68cbaa6d61eee4cdf2c5ddc2856b_amd64Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9@sha256:6d3eceda5b92beb26d20e83bd814ee25e83896c9ba1e5cc6b53cd97c860181ad_amd64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:c3b8ec42e978c4427c505d9851a21c7f2679ff5b029509602c981d376ea0dd89_amd64s390xregistry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8541ede516234b075163fe98a357547f2d4b28d042b01a3858673e8d252ccf86_s390x

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:20:16 UTC

Technical Analysis

This advisory covers security fixes in Kiali 1.73.25 for Red Hat OpenShift Service Mesh 2.6. Key vulnerabilities include CVE-2025-64756, a command injection flaw in the glob CLI when used with the -c/--cmd option, allowing arbitrary command execution via shell metacharacters in malicious filenames. Another is CVE-2025-66031, an unbounded recursion issue in node-forge ASN.1 parsing. Exploitation requires the ability to create or trick the system into processing malicious files with glob CLI. The glob CLI is not used by npm, reducing exposure. Red Hat provides fixed images and documentation for remediation.

Potential Impact

Successful exploitation of CVE-2025-64756 could lead to arbitrary command execution with the privileges of the user running the glob CLI, potentially allowing attackers to disable services, read or modify data, or hide malicious activities. The unbounded recursion in node-forge ASN.1 (CVE-2025-66031) could cause denial of service via resource exhaustion. These vulnerabilities impact confidentiality, integrity, and availability of affected systems. No known exploits in the wild have been reported.

Mitigation Recommendations

Red Hat has released Kiali 1.73.25 which includes fixes for these vulnerabilities. Users should upgrade to this version to remediate the issues. Specifically, avoid using the glob CLI with the -c/--cmd option on untrusted filenames. If programmatic use of glob is necessary, sanitize filenames thoroughly before passing them to shell commands. Follow Red Hat's official documentation and advisories for applying updates and patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:22936
Cve Count
3
Additional Cves
["CVE-2025-64756","CVE-2025-66031"]
State
PUBLISHED

Threat ID: 6a160974e29bf47b5063ebca

Added to database: 05/26/2026, 20:58:28 UTC

Last enriched: 08/14/2026, 22:20:16 UTC

Last updated: 09/12/2026, 10:01:26 UTC

Views: 114

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:22936https://access.redhat.com/security/cve/CVE-2025-64756https://access.redhat.com/security/cve/CVE-2025-66031https://access.redhat.com/security/cve/cve-2025-64756https://access.redhat.com/security/cve/cve-2025-66031https://access.redhat.com/security/cve/cve-2025-12816https://access.redhat.com/security/updates/classificationhttps://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20041https://access.redhat.com/security/cve/CVE-2025-12816https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2026-22029https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-27143https://access.redhat.com/security/cve/CVE-2026-27144https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-34043https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/cve/CVE-2026-40175https://access.redhat.com/security/cve/CVE-2026-4800Canonical URLhttps://access.redhat.com/errata/RHSA-2026:40984https://access.redhat.com/security/cve/CVE-2025-13465https://access.redhat.com/security/cve/CVE-2025-15284https://access.redhat.com/security/cve/CVE-2025-68157https://access.redhat.com/security/cve/CVE-2025-68458https://access.redhat.com/security/cve/CVE-2025-69873https://access.redhat.com/security/cve/CVE-2026-25128https://access.redhat.com/security/cve/CVE-2026-25896https://access.redhat.com/security/cve/CVE-2026-26278https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27904https://access.redhat.com/security/cve/CVE-2026-27942https://access.redhat.com/security/cve/CVE-2026-33036https://access.redhat.com/security/cve/CVE-2026-33815https://access.redhat.com/security/cve/CVE-2026-33816https://access.redhat.com/errata/RHSA-2026:41941https://access.redhat.com/security/cve/CVE-2025-47907https://access.redhat.com/security/cve/CVE-2025-58183https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/errata/RHSA-2026:0518https://access.redhat.com/security/cve/CVE-2025-59375Canonical URLhttps://access.redhat.com/errata/RHSA-2026:41944https://access.redhat.com/security/cve/CVE-2026-48779https://access.redhat.com/errata/RHSA-2026:1248https://docs.redhat.com/en/documentation/migration_toolkit_for_virtualizationCanonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses