Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2021:3934 - Security Advisory
Issued:
2021-10-26
Updated:
2021-10-26

RHSA-2021:3934 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: OpenShift Container Platform 4.9.4 packages and security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat OpenShift Container Platform release 4.9.4 is now available with
updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.9.4. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHBA-2021:3935

Security Fix(es):

  • coreos-installer: incorrect signature verification on gzip-compressed install images (CVE-2021-20319)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.9 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-between-minor.html#understanding-upgrade-channels_updating-cluster-between-minor

Solution

For OpenShift Container Platform 4.9 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.9 for RHEL 7 x86_64
  • Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.9 aarch64

Fixes

  • BZ - 2011862 - CVE-2021-20319 coreos-installer: incorrect signature verification on gzip-compressed install images
  • BZ - 2015804 - Placeholder bug for OCP 4.9.0 rpm release

CVEs

  • CVE-2021-20319

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 4.9 for RHEL 8

SRPM
coreos-installer-0.10.1-1.rhaos4.9.el8.src.rpm SHA-256: 8c42de9a34ea770485b299e41b7f5371b4dcfecef89b7e83b3a47b4725edebe2
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.src.rpm SHA-256: c179dca97b2466bf198a736fcad329c09bb6c7f0f0c348442e60963247c29ac1
openshift-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.src.rpm SHA-256: f11d920e025fdac6ae858b16aac28bbdd758411752af1b02c22cc14f55a9cbee
openstack-ironic-18.1.1-0.20211006122217.5134847.el8.src.rpm SHA-256: d408976efc7195d8e7158180e1671e82b42459a364d9f74e9c2e41d502107ca1
x86_64
coreos-installer-0.10.1-1.rhaos4.9.el8.x86_64.rpm SHA-256: 7cc404bd808f6f2956b451c77e094c981524046aaab8fcbe24f16b0d73a3b73e
coreos-installer-bootinfra-debuginfo-0.10.1-1.rhaos4.9.el8.x86_64.rpm SHA-256: 00736ca224ff26720a321fb4ff0c3f33990a93558e6ac708d1fa5c2e96c82744
coreos-installer-debuginfo-0.10.1-1.rhaos4.9.el8.x86_64.rpm SHA-256: 2dfc0030f149ef9b99d93bf0e12e82c2acbeec5fd9092e3e172e014bb42f1374
coreos-installer-debugsource-0.10.1-1.rhaos4.9.el8.x86_64.rpm SHA-256: 2ffffc69d2c3a77cf586b8f31b327a9665baca78e61990b5f3c51fc6cc95618e
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.x86_64.rpm SHA-256: 03e59e3d7623e14b7cd0a497c8ad5d7a5fe48535449b7aa8df8e1995c87498cb
cri-o-debuginfo-1.22.0-74.rhaos4.9.gitd745cab.el8.x86_64.rpm SHA-256: 2de00593ee256c21daea223042bf53a41ccdb258762825927d532b8092554d9c
cri-o-debugsource-1.22.0-74.rhaos4.9.gitd745cab.el8.x86_64.rpm SHA-256: 6312cf136ac3b34fd9323e1c708611f1e064273cf654c596110c1ebf35fed691
openshift-hyperkube-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.x86_64.rpm SHA-256: b7492dab640d4ed23163fc11338039e5147ca43f4e133040ec4af35951e0a12d
openstack-ironic-api-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 5461cb40c1dfe5bf4ecc4543c5005c0542fd71a946bf0d669b7537c05c565f61
openstack-ironic-common-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 76eaae5afaf80a9cf4352fc92d6b15491c7b16f71c9aeebff7368e8bbf9b3d30
openstack-ironic-conductor-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: d537702394aa12c8e674bc2df9d32e06f8c1ea904ce6006fecf1e6a91c0bde07
python3-ironic-tests-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 3ab834cf634c7f797db9a8efe6b5c0e6b75740634628aaf12b681aa3dcc0a77f

Red Hat OpenShift Container Platform 4.9 for RHEL 7

SRPM
cri-o-1.22.0-89.rhaos4.9.gitd745cab.el7.src.rpm SHA-256: f73e7f1f30c6ba0076743272e05e5e593d08d0d3f65a89ba5df914a3f1f1a62f
openshift-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el7.src.rpm SHA-256: e70ee61f96bacb7bb722373152540f9b035d7b2fc57537142adbdc318563b0ab
x86_64
cri-o-1.22.0-89.rhaos4.9.gitd745cab.el7.x86_64.rpm SHA-256: 3637bd8b19b2b7305ab83c7f5fb23aa487480c853a4a4ed9207f9405b5c761d7
cri-o-debuginfo-1.22.0-89.rhaos4.9.gitd745cab.el7.x86_64.rpm SHA-256: a9370a250bdabe0b22a33c805ad0b8f6208383549a559dc2e40d1db5901cd1d4
openshift-hyperkube-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el7.x86_64.rpm SHA-256: f5af64e65b088121b2846890be77c2517d4410165ec83ea8b49a9c9e995bdeb5

Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8

SRPM
coreos-installer-0.10.1-1.rhaos4.9.el8.src.rpm SHA-256: 8c42de9a34ea770485b299e41b7f5371b4dcfecef89b7e83b3a47b4725edebe2
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.src.rpm SHA-256: c179dca97b2466bf198a736fcad329c09bb6c7f0f0c348442e60963247c29ac1
openshift-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.src.rpm SHA-256: f11d920e025fdac6ae858b16aac28bbdd758411752af1b02c22cc14f55a9cbee
openstack-ironic-18.1.1-0.20211006122217.5134847.el8.src.rpm SHA-256: d408976efc7195d8e7158180e1671e82b42459a364d9f74e9c2e41d502107ca1
ppc64le
coreos-installer-0.10.1-1.rhaos4.9.el8.ppc64le.rpm SHA-256: faab8a9030ab8117823eec213d9b229eb5c3a6dcc913370318c94923b1703c35
coreos-installer-bootinfra-0.10.1-1.rhaos4.9.el8.ppc64le.rpm SHA-256: 233d87e2594bac73aaa7a7c233feb11e49304338a2e44fc00c99df966d68448f
coreos-installer-bootinfra-debuginfo-0.10.1-1.rhaos4.9.el8.ppc64le.rpm SHA-256: f12a5c8141b97b9deb8aa7452d08aae7375413558f252390f57deec66b1354f8
coreos-installer-debuginfo-0.10.1-1.rhaos4.9.el8.ppc64le.rpm SHA-256: bb6c7d5b812e02994c49d9bb9e08f4ff89880b22ff2e659a71815aaada946c47
coreos-installer-debugsource-0.10.1-1.rhaos4.9.el8.ppc64le.rpm SHA-256: 93941d844f1f54f41c3dcf497ec9f565376535a7fbb7846e32f302de513cc96d
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.ppc64le.rpm SHA-256: f5c61cc61a3266dc98d7e3c845be2e31950c8adb70b0399c30adaa8fee93945b
cri-o-debuginfo-1.22.0-74.rhaos4.9.gitd745cab.el8.ppc64le.rpm SHA-256: 810bdc785a7272e1dc11b69be08b78a1fac9af109d57a2aa3c80941f56c3315a
cri-o-debugsource-1.22.0-74.rhaos4.9.gitd745cab.el8.ppc64le.rpm SHA-256: bf11272c7f67ed9adfd13c64fb7f5f657a8041bf0cfcbc2474159007e5b826c3
openshift-hyperkube-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.ppc64le.rpm SHA-256: 6a412a3391ced3eba19d831036be0bd71c4821d8e7421914012cfc19623d228f
openstack-ironic-api-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 5461cb40c1dfe5bf4ecc4543c5005c0542fd71a946bf0d669b7537c05c565f61
openstack-ironic-common-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 76eaae5afaf80a9cf4352fc92d6b15491c7b16f71c9aeebff7368e8bbf9b3d30
openstack-ironic-conductor-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: d537702394aa12c8e674bc2df9d32e06f8c1ea904ce6006fecf1e6a91c0bde07
python3-ironic-tests-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 3ab834cf634c7f797db9a8efe6b5c0e6b75740634628aaf12b681aa3dcc0a77f

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8

SRPM
coreos-installer-0.10.1-1.rhaos4.9.el8.src.rpm SHA-256: 8c42de9a34ea770485b299e41b7f5371b4dcfecef89b7e83b3a47b4725edebe2
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.src.rpm SHA-256: c179dca97b2466bf198a736fcad329c09bb6c7f0f0c348442e60963247c29ac1
openshift-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.src.rpm SHA-256: f11d920e025fdac6ae858b16aac28bbdd758411752af1b02c22cc14f55a9cbee
openstack-ironic-18.1.1-0.20211006122217.5134847.el8.src.rpm SHA-256: d408976efc7195d8e7158180e1671e82b42459a364d9f74e9c2e41d502107ca1
s390x
coreos-installer-0.10.1-1.rhaos4.9.el8.s390x.rpm SHA-256: 04876f5330e5b3d2fa5bfa100031c4399ac25a7168792681206624bd5d1a9f3c
coreos-installer-bootinfra-0.10.1-1.rhaos4.9.el8.s390x.rpm SHA-256: 3f9d9ac145bf567745c653afb8d3cfb3ca44776b676181374ea13703e82ba279
coreos-installer-bootinfra-debuginfo-0.10.1-1.rhaos4.9.el8.s390x.rpm SHA-256: 75c6874688c62db251dd007f5519047c2a0923c1c251f2aeec584268cda4bab8
coreos-installer-debuginfo-0.10.1-1.rhaos4.9.el8.s390x.rpm SHA-256: 2b957918c465843f6db73bd281eec5218cf03cbe2aacaca7d68e98e75986427a
coreos-installer-debugsource-0.10.1-1.rhaos4.9.el8.s390x.rpm SHA-256: 198ef27452077ecbae1a0c8ead48713173e44802d40de0ba55502496c7242b52
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.s390x.rpm SHA-256: 5d543f8d08aee6f49e49922c4837c5cb76198b01112f5363597e0b587e4d60b0
cri-o-debuginfo-1.22.0-74.rhaos4.9.gitd745cab.el8.s390x.rpm SHA-256: 1c08023a29df4ccbc702f3b0cdb83920648f2efe0843d866526e47ee289407c3
cri-o-debugsource-1.22.0-74.rhaos4.9.gitd745cab.el8.s390x.rpm SHA-256: 068b33add470c52c86296c6ccbd9a9d30bebe4f79a534be072243eb248046803
openshift-hyperkube-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.s390x.rpm SHA-256: 8d426b39507f08a104c84e7c6c71418d01e0ac58303657e5846426ab733dfb41
openstack-ironic-api-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 5461cb40c1dfe5bf4ecc4543c5005c0542fd71a946bf0d669b7537c05c565f61
openstack-ironic-common-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 76eaae5afaf80a9cf4352fc92d6b15491c7b16f71c9aeebff7368e8bbf9b3d30
openstack-ironic-conductor-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: d537702394aa12c8e674bc2df9d32e06f8c1ea904ce6006fecf1e6a91c0bde07
python3-ironic-tests-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 3ab834cf634c7f797db9a8efe6b5c0e6b75740634628aaf12b681aa3dcc0a77f

Red Hat OpenShift Container Platform for ARM 64 4.9

SRPM
coreos-installer-0.10.1-1.rhaos4.9.el8.src.rpm SHA-256: 8c42de9a34ea770485b299e41b7f5371b4dcfecef89b7e83b3a47b4725edebe2
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.src.rpm SHA-256: c179dca97b2466bf198a736fcad329c09bb6c7f0f0c348442e60963247c29ac1
openshift-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.src.rpm SHA-256: f11d920e025fdac6ae858b16aac28bbdd758411752af1b02c22cc14f55a9cbee
openstack-ironic-18.1.1-0.20211006122217.5134847.el8.src.rpm SHA-256: d408976efc7195d8e7158180e1671e82b42459a364d9f74e9c2e41d502107ca1
aarch64
coreos-installer-0.10.1-1.rhaos4.9.el8.aarch64.rpm SHA-256: 87261cb2db38155468ace9df25202577c934bdd6e95f87a884a3c89eb07fac2c
coreos-installer-bootinfra-debuginfo-0.10.1-1.rhaos4.9.el8.aarch64.rpm SHA-256: 9c89f113ad6b399e05341d73dcdfedd463847b47c0ec58d77f2f21feae0adce8
coreos-installer-debuginfo-0.10.1-1.rhaos4.9.el8.aarch64.rpm SHA-256: 71e30095985fb8f7a740541bb02be25b71174a15a524b06c2a4dac6d53e806d9
coreos-installer-debugsource-0.10.1-1.rhaos4.9.el8.aarch64.rpm SHA-256: 625b84ea7b153f50a4701c2c3a58d85ed7d54093497cdad34cf7bc06ab96c079
cri-o-1.22.0-74.rhaos4.9.gitd745cab.el8.aarch64.rpm SHA-256: 6f00e2c5e5b2594f277813321b25cc7577bc1ba7a8709b8e7c6ec0fbda695f92
cri-o-debuginfo-1.22.0-74.rhaos4.9.gitd745cab.el8.aarch64.rpm SHA-256: 6d4798f2ad23978cfee16e388c0df61a66059644ceffb88fea835528f87d921e
cri-o-debugsource-1.22.0-74.rhaos4.9.gitd745cab.el8.aarch64.rpm SHA-256: 0dd5ece1d0b1f74f05d5c72c2a17761573235678af3c33ab3c50fd30a1db3628
openshift-hyperkube-4.9.0-202110140556.p0.git.ef241fd.assembly.stream.el8.aarch64.rpm SHA-256: afdb543b25d03f327935d92cc7d22e81428cf17bc8226ac4e8dc85c23c66b490
openstack-ironic-api-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 5461cb40c1dfe5bf4ecc4543c5005c0542fd71a946bf0d669b7537c05c565f61
openstack-ironic-common-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 76eaae5afaf80a9cf4352fc92d6b15491c7b16f71c9aeebff7368e8bbf9b3d30
openstack-ironic-conductor-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: d537702394aa12c8e674bc2df9d32e06f8c1ea904ce6006fecf1e6a91c0bde07
python3-ironic-tests-18.1.1-0.20211006122217.5134847.el8.noarch.rpm SHA-256: 3ab834cf634c7f797db9a8efe6b5c0e6b75740634628aaf12b681aa3dcc0a77f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility