Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update
Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6235: [4.18] [ROSA HCP][UI blocker] Broken Storage System wizard DFBUGS-6185: ocs-operator should not use image gcr.io/kubebuilder/kube-rbac-proxy DFBUGS-6172: RHODF 4.18.20 DFBUGS-5939: Backport to odf-4.18.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN"
AI Analysis
Technical Summary
This Red Hat security advisory addresses several vulnerabilities in Red Hat OpenShift Data Foundation 4.18.20 and related components, notably CVE-2025-61729, a denial of service vulnerability in Go's crypto/x509 package caused by excessive resource consumption from crafted certificates. Additional fixes include denial of service issues in TLS 1.3 key update handling, authorization bypass in gRPC-Go due to improper HTTP/2 path validation, and incorrect parsing of IPv6 host literals. The advisory also includes bug fixes for UI blockers and image usage in the ocs-operator. The update is classified as important and fixes multiple CVEs affecting Red Hat Satellite and OpenShift Data Foundation products.
Potential Impact
The primary impact is denial of service caused by crafted certificates leading to excessive resource consumption in Go's crypto/x509 package, potentially affecting services relying on certificate validation. Other vulnerabilities fixed include authorization bypass and denial of service in TLS and gRPC components. These issues could disrupt availability or allow unauthorized access if exploited. No known exploits in the wild have been reported at the time of this advisory.
Mitigation Recommendations
An official security update is available for Red Hat OpenShift Data Foundation 4.18.20 and related Red Hat Satellite components that addresses these vulnerabilities. Users should apply this update after ensuring all previously released errata relevant to their systems are installed. Detailed update instructions are provided in the Red Hat documentation. No additional mitigation steps are indicated beyond applying the official patches.
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6235: [4.18] [ROSA HCP][UI blocker] Broken Storage System wizard DFBUGS-6185: ocs-operator should not use image gcr.io/kubebuilder/kube-rbac-proxy DFBUGS-6172: RHODF 4.18.20 DFBUGS-5939: Backport to odf-4.18.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN"
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory addresses several vulnerabilities in Red Hat OpenShift Data Foundation 4.18.20 and related components, notably CVE-2025-61729, a denial of service vulnerability in Go's crypto/x509 package caused by excessive resource consumption from crafted certificates. Additional fixes include denial of service issues in TLS 1.3 key update handling, authorization bypass in gRPC-Go due to improper HTTP/2 path validation, and incorrect parsing of IPv6 host literals. The advisory also includes bug fixes for UI blockers and image usage in the ocs-operator. The update is classified as important and fixes multiple CVEs affecting Red Hat Satellite and OpenShift Data Foundation products.
Potential Impact
The primary impact is denial of service caused by crafted certificates leading to excessive resource consumption in Go's crypto/x509 package, potentially affecting services relying on certificate validation. Other vulnerabilities fixed include authorization bypass and denial of service in TLS and gRPC components. These issues could disrupt availability or allow unauthorized access if exploited. No known exploits in the wild have been reported at the time of this advisory.
Mitigation Recommendations
An official security update is available for Red Hat OpenShift Data Foundation 4.18.20 and related Red Hat Satellite components that addresses these vulnerabilities. Users should apply this update after ensuring all previously released errata relevant to their systems are installed. Detailed update instructions are provided in the Red Hat documentation. No additional mitigation steps are indicated beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:17547
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-4800","CVE-2026-33036","CVE-2026-34986"]
- State
- PUBLISHED
Threat ID: 6a16095be29bf47b50624919
Added to database: 05/26/2026, 20:58:03 UTC
Last enriched: 08/14/2026, 19:15:21 UTC
Last updated: 09/13/2026, 10:01:28 UTC
Views: 104
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.