Skip to main content
EPSS 0.4%top 68%

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.21.4 security update

0
High
Published: 09/03/2026 (09/03/2026, 10:51:56 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-10472 () * GITOPS-10477 ()

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64grype-main@aarch64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 8)s390xgrafana-0:9.2.10-32.el8_10.s390xRed Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.21amd64registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:74b2f0104ce1214d4447cbe9ede3dafadbd68ed7065b45f303329320ac7b759a_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 18:06:23 UTC

Technical Analysis

The advisory covers a set of vulnerabilities including CVE-2026-44740, CVE-2026-47262, CVE-2026-53489, and CVE-2026-53492 affecting Red Hat Hardened Images RPMs, specifically the grype package version 0.115.0-0.1.hum1 for aarch64 and x86_64 architectures. CVE-2026-47262 is a denial of service vulnerability in containerd caused by uncontrolled resource consumption from maliciously crafted container images. Red Hat products are not affected by this vulnerability because they use CRI-O instead of containerd as the container runtime, and the vulnerable code path is not executed. The advisory includes updated RPMs to address bugs and enhancements but does not explicitly state fixes for the CVEs. No exploits are known in the wild. The advisory references multiple CWEs related to resource allocation and security controls.

Potential Impact

The primary impact is a potential denial of service condition caused by resource exhaustion in container runtimes when processing malicious images. However, Red Hat products are not vulnerable to this specific containerd flaw due to their use of CRI-O. The vulnerabilities may affect components included in Red Hat Hardened Images, but no active exploitation is reported. The overall impact is disruption of container runtime services if exploited, but this is mitigated in Red Hat environments by architectural choices.

Mitigation Recommendations

Red Hat states that no mitigation is needed for their products regarding the containerd-related vulnerability because the vulnerable code path is not executed in their container runtime implementation. Users should apply the updated RPM packages (grype-0.115.0-0.1.hum1) provided in the advisory to benefit from bug fixes and enhancements. For other vulnerabilities mentioned, follow Red Hat's standard update procedures as detailed in the advisory. Monitor Red Hat's official channels for any further updates or patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:32963
Cve Count
4
Additional Cves
["CVE-2026-47262","CVE-2026-53489","CVE-2026-53492"]
State
PUBLISHED

Threat ID: 6a58b3f868715ace43d66469

Added to database: 07/16/2026, 10:35:36 UTC

Last enriched: 08/15/2026, 18:06:23 UTC

Last updated: 09/14/2026, 13:31:26 UTC

Views: 46

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses