Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update
Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-7342: RHODF 4.19.20 release DFBUGS-7332: [Backport for 4.19] - [GSS][ODF][MCG] noobaa-db-pg-cluster won't synchronize anymore - "could not receive data from WAL stream: ERROR: requested WAL segment 00000008000001C600000068 has already been removed" DFBUGS-6940: [4.19.z] Integrate ibm-storage-odf-operator 1.9.0 DFBUGS-6542: [ODF 4.19.z CLONE] - Provider Server sends sub channel to client only when provider side csv is at the tip of the sub channel in the catalogsource DFBUGS-6529: [Backport to 4.19.z] maintenance mode is always set for storageclients in non RDR clusters DFBUGS-6523: CLONE 4.19 - [UI] Resource profile calculations doesn't include NFS DFBUGS-4768: [Backport to odf-4.19.z]Remove duplicate PersistentVolumeUsageCritical alerts
AI Analysis
Technical Summary
This advisory covers security fixes in Kiali 1.73.25 for Red Hat OpenShift Service Mesh 2.6. Key vulnerabilities include CVE-2025-64756, a command injection flaw in the glob CLI when used with the -c/--cmd option, allowing arbitrary command execution via shell metacharacters in malicious filenames. Another is CVE-2025-66031, an unbounded recursion issue in node-forge ASN.1 parsing. Exploitation requires the ability to create or trick the system into processing malicious files with glob CLI. The glob CLI is not used by npm, reducing exposure. Red Hat provides fixed images and documentation for remediation.
Potential Impact
Successful exploitation of CVE-2025-64756 could lead to arbitrary command execution with the privileges of the user running the glob CLI, potentially allowing attackers to disable services, read or modify data, or hide malicious activities. The unbounded recursion in node-forge ASN.1 (CVE-2025-66031) could cause denial of service via resource exhaustion. These vulnerabilities impact confidentiality, integrity, and availability of affected systems. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released Kiali 1.73.25 which includes fixes for these vulnerabilities. Users should upgrade to this version to remediate the issues. Specifically, avoid using the glob CLI with the -c/--cmd option on untrusted filenames. If programmatic use of glob is necessary, sanitize filenames thoroughly before passing them to shell commands. Follow Red Hat's official documentation and advisories for applying updates and patches.
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-7342: RHODF 4.19.20 release DFBUGS-7332: [Backport for 4.19] - [GSS][ODF][MCG] noobaa-db-pg-cluster won't synchronize anymore - "could not receive data from WAL stream: ERROR: requested WAL segment 00000008000001C600000068 has already been removed" DFBUGS-6940: [4.19.z] Integrate ibm-storage-odf-operator 1.9.0 DFBUGS-6542: [ODF 4.19.z CLONE] - Provider Server sends sub channel to client only when provider side csv is at the tip of the sub channel in the catalogsource DFBUGS-6529: [Backport to 4.19.z] maintenance mode is always set for storageclients in non RDR clusters DFBUGS-6523: CLONE 4.19 - [UI] Resource profile calculations doesn't include NFS DFBUGS-4768: [Backport to odf-4.19.z]Remove duplicate PersistentVolumeUsageCritical alerts
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers security fixes in Kiali 1.73.25 for Red Hat OpenShift Service Mesh 2.6. Key vulnerabilities include CVE-2025-64756, a command injection flaw in the glob CLI when used with the -c/--cmd option, allowing arbitrary command execution via shell metacharacters in malicious filenames. Another is CVE-2025-66031, an unbounded recursion issue in node-forge ASN.1 parsing. Exploitation requires the ability to create or trick the system into processing malicious files with glob CLI. The glob CLI is not used by npm, reducing exposure. Red Hat provides fixed images and documentation for remediation.
Potential Impact
Successful exploitation of CVE-2025-64756 could lead to arbitrary command execution with the privileges of the user running the glob CLI, potentially allowing attackers to disable services, read or modify data, or hide malicious activities. The unbounded recursion in node-forge ASN.1 (CVE-2025-66031) could cause denial of service via resource exhaustion. These vulnerabilities impact confidentiality, integrity, and availability of affected systems. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released Kiali 1.73.25 which includes fixes for these vulnerabilities. Users should upgrade to this version to remediate the issues. Specifically, avoid using the glob CLI with the -c/--cmd option on untrusted filenames. If programmatic use of glob is necessary, sanitize filenames thoroughly before passing them to shell commands. Follow Red Hat's official documentation and advisories for applying updates and patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:22936
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-64756","CVE-2025-66031"]
- State
- PUBLISHED
Threat ID: 6a160974e29bf47b5063ebca
Added to database: 05/26/2026, 20:58:28 UTC
Last enriched: 08/14/2026, 22:20:16 UTC
Last updated: 09/12/2026, 10:01:26 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.