Skip to main content
EPSS 0.8%top 44%

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15 security, enhancement & bug fix update

0
High
Published: 02/05/2026 (02/05/2026, 18:06:29 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4.15 security, enhancement & bug fix update.

Affected software

Affected versions
>=4.15 <4.16>=16.2 <16.3Red HatRed Hat OpenStack PlatformRed Hat OpenStack Platform 16.2amd64rhosp-rhel8/osp-director-agent@sha256:7924ce959b8f61cb616be22d86c827a18d760793efa3c94e4f8126e4c9284435_amd64Network ObservabilityNETOBSERV 1.7 for RHEL 9network-observability/network-observability-cli-rhel9@sha256:7c2c2c0c0c255c1ef1579b63337d35174a330374a7deaff3c3c1e39ff48e89ee_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.15registry.redhat.io/odf4/cephcsi-rhel9@sha256:ccebdd77596e7390b18108eae3ae9058ee2ad9743e80f3f35bc30eb7d0b7c794_amd64Run Once Duration Override OperatorRODOO 1.1 for RHEL 9run-once-duration-override-operator/run-once-duration-override-rhel9@sha256:fb07ca8c78128d7ff84a0ff3a3865a05cab12c1510275868a1210f3346107c8f_amd64Cost Management Metrics OperatorCost Management Metrics Operator 3.3.2registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:85edd059d6196a5b0602f1c1b733d502fe44858ccb35f4cfd8bdf02b66a6ed3c_amd64OpenShift API for Data Protection9Base-OADP-1.4s390xoadp/oadp-kubevirt-velero-plugin-rhel9@sha256:446ccce4d7e6bf9746bf3d2227b63f43641dafc2283c2778ab24934357f6f260_s390xCryostatCryostat 3 on RHEL 8arm64cryostat-tech-preview/cryostat-db-rhel8@sha256:27642ac1b50de6deb1c40b9d0b39833b8ec7b36983872ebd10e0edc290967538_arm64MicrosoftAzure Linux3.0Azure Linux 3.02.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:42:25 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:2172) addresses multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15 and related products. Notably, CVE-2024-34155 involves golang parser functions where calling any Parse function with deeply nested literals can cause a panic or stack exhaustion. CVE-2024-34156 similarly involves golang's encoding/gob Decoder.Decode function causing panic due to deeply nested structures. These issues can lead to denial of service conditions by exhausting stack resources. The advisory includes fixes for these and other CVEs and is rated as important/high severity by Red Hat. The vendor advisory confirms that updates are available and provides detailed instructions for applying the fixes. No evidence of known exploits in the wild is reported. The affected products include Red Hat OpenShift Data Foundation 4.15 and Red Hat OpenStack Platform 16.2 among others.

Potential Impact

The vulnerabilities can cause application panics and stack exhaustion when processing deeply nested data structures, potentially leading to denial of service conditions in affected Red Hat products. This could disrupt normal operation of OpenShift Data Foundation and OpenStack Platform components. No known exploitation in the wild has been reported. The impact is rated as high severity by Red Hat Product Security.

Mitigation Recommendations

Red Hat has released official security updates addressing these vulnerabilities. Users should apply the Red Hat OpenShift Data Foundation 4.15 update and ensure all previously released errata relevant to their systems are applied. Detailed update instructions are available in the Red Hat documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.15/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf and the advisory at https://access.redhat.com/errata/RHSA-2026:2172. No additional mitigation is required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2172
Cve Count
5
Additional Cves
["CVE-2024-34156","CVE-2024-34158","CVE-2025-22868","CVE-2025-30204"]

Threat ID: 6a160977e29bf47b5064303e

Added to database: 05/26/2026, 20:58:31 UTC

Last enriched: 08/14/2026, 21:42:25 UTC

Last updated: 09/10/2026, 19:24:54 UTC

Views: 101

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2024:10883https://access.redhat.com/security/updates/classification/#important23105272310528Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2172https://access.redhat.com/security/cve/CVE-2024-34155https://access.redhat.com/security/cve/CVE-2024-34156https://access.redhat.com/security/cve/CVE-2024-34158https://access.redhat.com/security/cve/CVE-2025-22868https://access.redhat.com/security/cve/CVE-2025-30204https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2024:10895https://access.redhat.com/security/updates/classificationhttps://docs.redhat.com/en/documentation/cost_management_service/1-latest/html/getting_started_with_cost_management/steps-to-cost-managementCanonical URLhttps://access.redhat.com/errata/RHSA-2024:801423081932310529231090823111522311153231115423111712312631NETOBSERV-1377NETOBSERV-1509NETOBSERV-1538NETOBSERV-1540NETOBSERV-1564NETOBSERV-163NETOBSERV-1666NETOBSERV-1667https://access.redhat.com/errata/RHSA-2024:83292301456Canonical URLhttps://access.redhat.com/errata/RHSA-2024:8337https://access.redhat.com/security/updates/classification/#moderateCanonical URLhttps://access.redhat.com/errata/RHSA-2025:0771OADP-4995OADP-5044OADP-5095OADP-5362OADP-5388OADP-5460OADP-5470Canonical URLCVE-2024-34155 Stack exhaustion in all Parse functions in go/parser - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring SystemSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses