Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.
AI Analysis
Technical Summary
CVE-2025-47907 is a race condition vulnerability in the database/sql package used by Red Hat OpenShift API for Data Protection. When a query is cancelled during a Scan method call on returned Rows, concurrent queries can produce unexpected and inconsistent results due to improper synchronization. This flaw could allow an attacker capable of initiating and cancelling queries to trigger inconsistent data returns. The vulnerability is related to CWE-362 (race condition), CWE-59, and CWE-1050, and impacts confidentiality, integrity, and availability to varying degrees. Red Hat has released a security advisory (RHSA-2026:2951) with a fix for this issue.
Potential Impact
The vulnerability can cause inconsistent data to be returned to applications using the affected database/sql package when queries are cancelled concurrently. This may lead to data integrity issues and potential denial of service conditions due to resource exhaustion or crashes. However, the scope of exploitation is limited to applications that cancel queries while running multiple queries concurrently. There is no indication of direct compromise or privilege escalation in typical deployments.
Mitigation Recommendations
Red Hat has released an updated version of OpenShift API for Data Protection that addresses this vulnerability. Users should apply the update as per Red Hat Security Advisory RHSA-2026:2951 after ensuring all previously released errata relevant to their system have been applied. No additional mitigations are specified or required beyond applying the official fix.
Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
Description
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-47907 is a race condition vulnerability in the database/sql package used by Red Hat OpenShift API for Data Protection. When a query is cancelled during a Scan method call on returned Rows, concurrent queries can produce unexpected and inconsistent results due to improper synchronization. This flaw could allow an attacker capable of initiating and cancelling queries to trigger inconsistent data returns. The vulnerability is related to CWE-362 (race condition), CWE-59, and CWE-1050, and impacts confidentiality, integrity, and availability to varying degrees. Red Hat has released a security advisory (RHSA-2026:2951) with a fix for this issue.
Potential Impact
The vulnerability can cause inconsistent data to be returned to applications using the affected database/sql package when queries are cancelled concurrently. This may lead to data integrity issues and potential denial of service conditions due to resource exhaustion or crashes. However, the scope of exploitation is limited to applications that cancel queries while running multiple queries concurrently. There is no indication of direct compromise or privilege escalation in typical deployments.
Mitigation Recommendations
Red Hat has released an updated version of OpenShift API for Data Protection that addresses this vulnerability. Users should apply the update as per Red Hat Security Advisory RHSA-2026:2951 after ensuring all previously released errata relevant to their system have been applied. No additional mitigations are specified or required beyond applying the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2951
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-52881","CVE-2025-61729"]
Threat ID: 6a160968e29bf47b5062e1bc
Added to database: 05/26/2026, 20:58:16 UTC
Last enriched: 08/14/2026, 21:35:58 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 225
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.