- Issued:
- 2021-11-10
- Updated:
- 2021-11-10
RHBA-2021:4119 - Bug Fix Advisory
Synopsis
OpenShift Container Platform 4.9.6 bug fix update
Type/Severity
Bug Fix Advisory
Topic
Red Hat OpenShift Container Platform release 4.9.6 is now available with
updates to packages and images that fix several bugs.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.9.6. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHSA-2021:4118
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.9.6-x86_64
The image digest is sha256:c9f58ccb8a9085df4eeb23e21ca201d4c7d39bc434786d58a55381e13215a199
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.9.6-s390x
The image digest is sha256:95fc8f2a0f1900ac1e4c88957fede97cca7b9085e6713080d3825289b8aaff85
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.9.6-ppc64le
The image digest is sha256:e68b76cff16016fdf45ed2ca3dfaa6f43ba6f3adf2c09bcd97655ce1ec0e8eca
All OpenShift Container Platform 4.9 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-between-minor.html#understanding-upgrade-channels_updating-cluster-between-minor
Solution
For OpenShift Container Platform 4.9 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html
Affected Products
- Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for ARM 64 4.9 aarch64
Fixes
- BZ - 1954309 - Handler locks not effective
- BZ - 1972082 - [4.9.0] Updating configmap within AgentServiceConfig is not logged properly
- BZ - 1973585 - [web-console] Storage-overview is "OpenShift Container Storage Overview" but not real "Storage Overview"
- BZ - 1989798 - yaml multi file dnd duplicates previous dragged files
- BZ - 1995190 - Community operator etcd fails to install on 4.9
- BZ - 2000858 - Add documentation link for MON_DISK_LOW
- BZ - 2002006 - Side nav list borders don't extend to edges of container
- BZ - 2002856 - "Subscription already exists in openshift-storage namespace" error message is seen while installing odf-operator via UI
- BZ - 2002878 - Remove response headers for downloads of binaries from OpenShift WebConsole
- BZ - 2002905 - cluster admin unable to view BuildConfigs in all namespaces
- BZ - 2003893 - (release-4.9) backport ApiRequestCounts conditional gatherer
- BZ - 2004052 - Upstream SR-IOV worker doc has broken links
- BZ - 2004075 - Could not select image tag version when create app from dev console
- BZ - 2004569 - cluster destruction fails to remove router in BYON with Kuryr as primary network (even after BZ 1940159 got fixed)
- BZ - 2004816 - (release-4.9) OCM controller must update operator status
- BZ - 2009493 - When LE takes a large amount of time, multiple whereabouts are seen
- BZ - 2009515 - Bump OVS to 2.16-15
- BZ - 2009670 - Calling 'supported-platforms' just after the cluster creation causes a panic.
- BZ - 2009787 - Failure to validate flavor RAM
- BZ - 2009849 - BMC credentials could be logged if they change
- BZ - 2009850 - Power off fails for drivers that don't support Soft power off
- BZ - 2009857 - ovnkube-node log spam (and security token leak?)
- BZ - 2010160 - Clicking on the perspective switcher shows a white page with loader
- BZ - 2010681 - console-operator is slow to mark Degraded as False once console starts working
- BZ - 2011385 - [4.9z] timedout waiting for flows during pod creation and ovn-controller pegged on worker nodes
- BZ - 2012798 - Ironic resumes clean before raid configuration job is actually completed
- BZ - 2013017 - Neutron Ports assigned to Completed Pods are not reused Edit
- BZ - 2013105 - ImageStreamTag alias results in wrong tag and invalid link in Web Console
- BZ - 2013690 - Nil pointer exception when phc2sys options are missing
- BZ - 2014145 - Failed to load RoleBindings list that will lead to ‘Role name’ is not able to be selected on Create RoleBinding page as well
- BZ - 2014303 - Service details page is showing wrong in-cluster hostname
- BZ - 2014633 - [release-4.9] obfuscation ovn clusters bug
- BZ - 2015571 - [4.9] kube_persistentvolumeclaim_labels and kube_persistentvolume_labels are missing in OCP 4.8 monitoring stack
- BZ - 2015829 - Too many haproxy processes in default-router pod causing high load average after upgrade from v4.8.3 to v4.8.10
- BZ - 2016174 - etcd pod on CrashLoopBackOff after master replacement procedure
- BZ - 2016267 - [IPI][OSP] densed master-only installation with 0 workers fails due to missing worker security group on masters
- BZ - 2016556 - [4.9.z] diskmaker-manager constantly redeployed by LSO when creating LV's
- BZ - 2017066 - NTO does not set io_timeout and max_retries for AWS Nitro instances
- BZ - 2017245 - ovirt csi operator static files creation is in the wrong order
- BZ - 2017434 - Collect Profiles pprof secret is hardcoded to openshift-operator-lifecycle-manager
- BZ - 2017488 - NTO does not restart TuneD daemon when profile application is taking too long
- BZ - 2017977 - ZTP Operator subscriptions for 4.9 release branch should point to 4.9 by default
- BZ - 2017985 - m5.large instance type for bootstrap node is hardcoded causing deployments to fail if instance type is not available
- BZ - 2018082 - Missing downstream ztp-site-generate-rhel8 4.9 container image
- BZ - 2018148 - Kuryr CI broken due to PrettyTable being bumped in global-constraints.txt
- BZ - 2018455 - Project Filesystem query returns No datapoints found
- BZ - 2018516 - go.sum not updated, that ART extracts version string from, WAS: Missing backport from 4.9 for Kube bump PR#950
- BZ - 2019518 - [sig-builds][Feature:Builds] clone repository using git:// protocol should clone using git:// if no proxy is configured [Skipped:Disconnected] [Suite:openshift/conformance/parallel]
CVEs
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.