Skip to main content
EPSS 0.4%top 65%

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.19.15 security, enhancement & bug fix update

0
High
Published: 04/30/2026 (04/30/2026, 11:36:26 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4.19.15 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6345: RHODF 4.19.15 DFBUGS-5942: Backport to odf-4.19.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" DFBUGS-5819: [Backport to odf-4.19.z] [IBM_Support][Fusion HCI]"storageclient-xxxxx-status-reporter job" doesn't inherits the tolerations defined in "ocs-client-operator-controller-manager" deployment DFBUGS-5800: [Backport to odf-4.19.z] must-gather causes default RGW pools to be created and PGs to be stuck at 1 DFBUGS-4440: [4.19][ROSA HCP][UI]Bad gateway on Storage System creation wizard CVEs: ========== CVE-2026-34986 CVE-2025-61726 CVE-2026-33186 CVE-2025-61729 CVE-2026-4800 CVE-2025-58183 CVE-2026-33036

Affected software

Affected versions
>=4.19.0 <4.19.15Red HatRed Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.19amd64registry.redhat.io/odf4/cephcsi-rhel9@sha256:08d3d6db14a36f5338a958bc9ee5914f912f5980f20f8dc6775ad4cf1905aaaf_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 17:21:29 UTC

Technical Analysis

The advisory covers Red Hat OpenShift Data Foundation 4.19.15, which fixes several bugs and multiple CVEs including CVE-2025-58183. CVE-2025-58183 is a vulnerability in the Go standard library's archive/tar package where tar.Reader does not limit the number of sparse region data blocks in GNU tar pax 1.0 sparse files. An attacker can craft a tar archive with a large number of sparse regions, causing the Go application to allocate excessive memory, resulting in an out-of-memory condition and denial of service. Exploitation requires the application to process the malicious archive. The vulnerability is rated moderate severity by Red Hat and has a CVSS v3 base score of 7.5 (Red Hat rating). The update to version 4.19.15 addresses this and other issues.

Potential Impact

Successful exploitation of CVE-2025-58183 can cause a denial of service due to resource exhaustion (memory allocation) when processing a maliciously crafted tar archive. There is no impact on confidentiality or integrity. Other fixed bugs improve stability and functionality of the product. The overall severity is high due to the denial of service potential.

Mitigation Recommendations

A security update to Red Hat OpenShift Data Foundation 4.19.15 is available and should be applied to remediate these vulnerabilities. No effective mitigations are currently available that meet Red Hat's criteria. Ensure all previously released errata are applied before updating. Follow Red Hat's official update documentation for applying this fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:12279
Cve Count
7
Additional Cves
["CVE-2025-61726","CVE-2025-61729","CVE-2026-4800","CVE-2026-33036","CVE-2026-33186","CVE-2026-34986"]
State
PUBLISHED

Threat ID: 6a160955e29bf47b5061ac7a

Added to database: 05/26/2026, 20:57:57 UTC

Last enriched: 08/17/2026, 17:21:29 UTC

Last updated: 09/14/2026, 01:36:26 UTC

Views: 101

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses