Skip to main content
EPSS 0.2%top 95%

Red Hat Security Advisory: RHOAI 3.3 - Red Hat OpenShift AI

0
Critical
Published: 03/04/2026 (03/04/2026, 07:18:30 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Release of RHOAI 3.3 provides these changes:

Affected software

Affected versions
Red HatOpenShift API for Data ProtectionOpenShift API for Data Protection 1.3amd64registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:56a93ad53df1c0445b3fee293ab42caa375f88b72872d8fb844efeb114869eaa_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.22registry.redhat.io/odf4/cephcsi-rhel9@sha256:05df2bcbadb214e4873082f282ef013565f04f24dce406d3802288d6ad574741_amd64Red Hat OpenShift AIRed Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:894f3f6f3b8de4c4a448284d12ac7a8bddecc370d64aa71e02ace54d68778e35_amd64OpenShift API for Data Protection 1.5registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:2c9332fa68acce79d7defcec12c651d6d331a32208f4325e798cf37971a35fed_amd64Red Hat OpenShift Dev Spaces (RHOSDS)Red Hat OpenShift Dev Spaces (RHOSDS) 3.26registry.redhat.io/devspaces/code-rhel9@sha256:772af8d40b674ce306850d3ecf2b70b39bdceaf9e045a2db9299c0dd8bd5e6b5_amd64Multicluster Global HubMulticluster Global Hub 1.4.5registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:242aee0257e823b6537c263d99138a0e801a1d586f211c45290e64722c18acf4_amd64Network Observability (NETOBSERV)Network Observability (NETOBSERV) 1.11.0registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:9e495db6e28bb6e38b263557d303081ed3199039dc1e7d18c704be8b64d8dd18_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.7registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:6ec722f4a9558cd2c409811b2da56a0af971a7f586a8d3c7a1ae1f47e25c7fb5_amd64Network Observability (NETOBSERV) 1.11.1Red Hat Advanced Cluster Management for KubernetesRed Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:bbe086814cc2fe9e53699ff23705479b493a62f9521b5f2664fcdb97dd5705a9_amd64registry.redhat.io/odf4/odf-dependencies-operator-bundle@sha256:9361befe3f0fe01ff32ecf2d7de1a3f6ffac4b43a13e654a276798c196e0131b_amd64

Weaknesses

CWE-279CWE-918CWE-22CWE-179CWE-476CWE-502CWE-94CWE-770CWE-130CWE-59CWE-208CWE-1050CWE-787CWE-78CWE-674CWE-91CWE-1188CWE-409CWE-405CWE-73CWE-400CWE-1333CWE-119CWE-209CWE-1286CWE-367CWE-1241CWE-1284CWE-551CWE-131CWE-303CWE-190CWE-276CWE-88CWE-20CWE-909CWE-771CWE-79CWE-354CWE-606CWE-524CWE-1289CWE-772CWE-281CWE-347CWE-358CWE-426CWE-601CWE-427CWE-295CWE-681CWE-1287CWE-436CWE-197CWE-158CWE-362CWE-1321CWE-1341CWE-1046CWE-807

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 19:57:04 UTC

Technical Analysis

A local privilege escalation vulnerability (CVE-2024-25621) exists in containerd due to overly permissive default directory permissions. Local users on the host can access the metadata store, content store, and Kubernetes local volumes, potentially exploiting setuid binaries to elevate privileges. The vulnerability affects Red Hat OpenShift AI 3.3 and other related Red Hat products that include containerd components. Red Hat has provided updated container images and documented manual mitigation steps involving restricting directory permissions or running containerd in rootless mode.

Potential Impact

The vulnerability allows local users with access to the host to read and modify containerd metadata and content stores, including Kubernetes local volumes. This can lead to privilege escalation on the host system by leveraging setuid binaries found in these volumes. The impact includes confidentiality and integrity compromise of container data and potential full host privilege escalation.

Mitigation Recommendations

Red Hat has released updated container images for Red Hat OpenShift AI 3.3 and related products to address this issue. Administrators should upgrade to these updated versions following Red Hat's documented upgrade instructions. As an immediate mitigation, system administrators can manually restrict permissions on containerd directories by running: chmod 700 /var/lib/containerd, chmod 700 /run/containerd/io.containerd.grpc.v1.cri, and chmod 700 /run/containerd/io.containerd.sandbox.controller.v1.shim. Alternatively, running containerd in rootless mode mitigates the risk. Check Red Hat's official advisory for detailed guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:3713
Cve Count
46
Additional Cves
["CVE-2025-6242","CVE-2025-12638","CVE-2025-12816","CVE-2025-14180","CVE-2025-14920","CVE-2025-14921","CVE-2025-14922","CVE-2025-14924","CVE-2025-14925","CVE-2025-14926","CVE-2025-14927","CVE-2025-14928","CVE-2025-14929","CVE-2025-14930","CVE-2025-15284","CVE-2025-48956","CVE-2025-52881","CVE-2025-59425","CVE-2025-61726","CVE-2025-61729","CVE-2025-62164","CVE-2025-62593","CVE-2025-64756","CVE-2025-66031","CVE-2025-66034","CVE-2025-66416","CVE-2025-66418","CVE-2025-66448","CVE-2025-66471","CVE-2025-66506","CVE-2025-66626","CVE-2025-67725","CVE-2025-67726","CVE-2025-68156","CVE-2025-68476","CVE-2025-68665","CVE-2025-69223","CVE-2025-69872","CVE-2026-0897","CVE-2026-1260","CVE-2026-21441","CVE-2026-22778","CVE-2026-22807","CVE-2026-24049","CVE-2026-24486"]

Threat ID: 6a160964e29bf47b506297b7

Added to database: 05/26/2026, 20:58:12 UTC

Last enriched: 08/10/2026, 19:57:04 UTC

Last updated: 09/15/2026, 01:45:37 UTC

Views: 314

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:3713https://access.redhat.com/security/cve/CVE-2024-25621https://access.redhat.com/security/cve/CVE-2025-12638https://access.redhat.com/security/cve/CVE-2025-12816https://access.redhat.com/security/cve/CVE-2025-14180https://access.redhat.com/security/cve/CVE-2025-14920https://access.redhat.com/security/cve/CVE-2025-14921https://access.redhat.com/security/cve/CVE-2025-14922https://access.redhat.com/security/cve/CVE-2025-14924https://access.redhat.com/security/cve/CVE-2025-14925https://access.redhat.com/security/cve/CVE-2025-14926https://access.redhat.com/security/cve/CVE-2025-14927https://access.redhat.com/security/cve/CVE-2025-14928https://access.redhat.com/security/cve/CVE-2025-14929https://access.redhat.com/security/cve/CVE-2025-14930https://access.redhat.com/security/cve/CVE-2025-15284https://access.redhat.com/security/cve/CVE-2025-48956https://access.redhat.com/security/cve/CVE-2025-52881https://access.redhat.com/security/cve/CVE-2025-59425https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/errata/RHSA-2026:25127https://access.redhat.com/security/cve/CVE-2025-61728https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2025-68151https://access.redhat.com/security/cve/CVE-2026-21441https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-26017https://access.redhat.com/security/cve/CVE-2026-26018https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32936https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-35579https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37387https://access.redhat.com/security/cve/CVE-2024-40635https://access.redhat.com/security/cve/CVE-2024-45310https://access.redhat.com/security/cve/CVE-2025-21613https://access.redhat.com/security/cve/CVE-2025-21614https://access.redhat.com/security/cve/CVE-2025-22870https://access.redhat.com/security/cve/CVE-2025-47911https://access.redhat.com/security/cve/CVE-2025-54410https://access.redhat.com/security/cve/CVE-2025-58058https://access.redhat.com/security/cve/CVE-2025-64329https://access.redhat.com/security/cve/CVE-2025-66506https://access.redhat.com/security/cve/CVE-2025-8766https://access.redhat.com/security/cve/CVE-2026-22772https://access.redhat.com/security/cve/CVE-2026-23831https://access.redhat.com/security/cve/CVE-2026-24117https://access.redhat.com/security/cve/CVE-2026-25680https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-25934https://access.redhat.com/errata/RHSA-2026:2343https://access.redhat.com/security/cve/CVE-2025-58183https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restoreCanonical URLhttps://access.redhat.com/errata/RHSA-2025:23248https://access.redhat.com/security/cve/CVE-2025-47907https://access.redhat.com/security/cve/CVE-2025-59375https://access.redhat.com/security/cve/CVE-2025-6965https://access.redhat.com/security/cve/CVE-2025-9648https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html-single/release_notes/index#about-this-release-479_release-notes-47Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2456https://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.26/html/administration_guide/installing-devspaceshttps://access.redhat.com/security/cve/CVE-2025-64756https://access.redhat.com/security/cve/CVE-2025-65945https://access.redhat.com/security/cve/CVE-2025-66031https://access.redhat.com/security/cve/CVE-2025-66418https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2025-66490https://access.redhat.com/security/cve/CVE-2026-22029Canonical URLhttps://access.redhat.com/errata/RHSA-2026:51033https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33747https://access.redhat.com/security/cve/CVE-2026-33748https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/errata/RHSA-2026:2900https://access.redhat.com/security/cve/CVE-2025-13465https://access.redhat.com/security/cve/CVE-2026-23745https://access.redhat.com/security/cve/CVE-2026-24049https://access.redhat.com/security/cve/CVE-2026-24842https://docs.openshift.com/container-platform/latest/observability/network_observability/network-observability-operator-release-notes.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2025:23428Canonical URLhttps://access.redhat.com/errata/RHSA-2025:22955https://access.redhat.com/security/cve/CVE-2025-47913https://catalog.redhat.com/software/containers/searchCanonical URLhttps://access.redhat.com/errata/RHSA-2025:23644Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses