Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10986 - Security Advisory
Issued:
2024-12-12
Updated:
2024-12-12

RHSA-2024:10986 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Low: Red Hat OpenShift Data Foundation 4.17.1 Bug Fix Update

Type/Severity

Security Advisory: Low

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.17.1 on Red Hat Enterprise Linux 9 from Red Hat Container Registry.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • cross-spawn: regular expression denial of service (CVE-2024-21538)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Bug fixes:

Previously, as part of monitoring the health of NamespaceStores, Multicloud Object Gateway (MCG) counted the I/O errors. This included read errors that occurred when the read failed due to no object existing. However, these errors should not be counted towards I/O failures as some clients use this type of read errors to find out whether an object exists. With this fix, these specific types of errors such as Read, No Such Object are not counted as I/O errors.
(JIRA#DFBUGS-834)

Previously, Ceph S3 object stores in OpenShift Data Foundation external mode needed to rotate certificates each time the RADOS Gateway (RGW) rotated. With this fix, well-known certificate authorities (CAs) are used to attempt the authentication of Ceph RGW daemons. The well-known CAs are determined based on Red Hat base container image’s certificates’ RPM package. The enables OpenShift Data Foundation to continue to operate in a healthy status.
(JIRA#DFBUGS-825)

Previously, in some cases, a race between an incomplete multipart upload that would later be cancelled and a new multipart upload of the same object would be deduped togetehr causing inconsistencies in object mapping and making it unavailable to read. With this fix, the Multicloud Object Gateway deduplication issue is resolved.
(JIRA#DFBUGS-356)

All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service
  • DFBUGS-856 - [Critical] Upgrade ceph version to RHCEPH-7.1z2 at ODF-4.17.1
  • DFBUGS-834 - [backport for ODF 4.17][2277298] [GSS] Namespace store stuck in rejected state
  • DFBUGS-750 - [2316577] cluster-cleanup-job pod not cleaning /var/lib/rook
  • DFBUGS-330 - [2313711] [ISF 2.8.1] [FDF 4.16.1] DF Native Client deletion should be disabled
  • DFBUGS-123 - [2322684] [Backport to 4.17.1] DBS3 and Scale CES-S3 Backports needed
  • DFBUGS-81 - [2316926] [Provider mode] Improve logs on client in case StorageClient fails to connect
  • DFBUGS-375 - [2322680] Update the deployment guide section to include AWS STS

CVEs

  • CVE-2021-3903
  • CVE-2024-2236
  • CVE-2024-2511
  • CVE-2024-3596
  • CVE-2024-4603
  • CVE-2024-4741
  • CVE-2024-5535
  • CVE-2024-6232
  • CVE-2024-9675
  • CVE-2024-9676
  • CVE-2024-10963
  • CVE-2024-21538
  • CVE-2024-34064
  • CVE-2024-34155
  • CVE-2024-34156
  • CVE-2024-34158
  • CVE-2024-50602

References

  • https://access.redhat.com/security/updates/classification/#low

aarch64

odf4/cephcsi-rhel9-operator@sha256:1ee5d22952951e8081330d52b15f9c42452dcda540809156277d4da8a411abec
odf4/mcg-core-rhel9@sha256:e9de3c31c6bb874386d60908ad7d2d8704174c1bd71afd5cb045f9e56bbc9d83
odf4/mcg-rhel9-operator@sha256:b907b18b2562057bb00b58c8690e1a8dc705ed241037fcc10b79d399891d6cfb
odf4/ocs-client-rhel9-operator@sha256:05410c2614da9e93eb4424090c0eeb27e255f482f9386f0eeb7b688780e5e6c0
odf4/ocs-rhel9-operator@sha256:673f70520c4bf7d597dc61e7526542874a36619e6c6dc19b580971129e6b7c0b
odf4/odf-cli-rhel9@sha256:e8c69f0afb3184c5b07bb34d08def3c0f709acb2c184f8ca3b7594551e42f417
odf4/odf-csi-addons-rhel9-operator@sha256:96acb3c36218fcd7d7cce2bdeb3f9844681d2219578ae14e9929f933b3f797a0
odf4/odf-csi-addons-sidecar-rhel9@sha256:aedf860e4a17ed618cb988f8966ba8a23727a0c21e205b3253d81211ab336334
odf4/odf-multicluster-rhel9-operator@sha256:04ba709bf819078e9bdddafef414896181ba7df707ecc58206c5cf8f1cafdaf7
odf4/odf-must-gather-rhel9@sha256:cf0afa7b3c66c9944bcc24f450870eb34905544c07963ab7bcb886391da7dc8e
odf4/odf-rhel9-operator@sha256:4f067fe1c123fc7c7cde0277446894555ae23b55c042bb769b7f311c5b8a4e82
odf4/odr-rhel9-operator@sha256:7f07045131c02fab04af3e137b8cb86394bada363fcc1331bdcfc44fc0e05e24

ppc64le

odf4/cephcsi-operator-bundle@sha256:677487e412e58da799f49188d2720f96e69cf3750515619e71e8c98f8a4f80cd
odf4/cephcsi-rhel9@sha256:6417a13d7117f5691f75073c5f893e5fe818aa188d641d86244bf5a3b4aa1894
odf4/cephcsi-rhel9-operator@sha256:2da4ad0da1883639225a98481ae0ce9d04d78fb3f68864122f4658e88f5584aa
odf4/mcg-core-rhel9@sha256:9200b22b74f5273b361b1d1e15bfaa6c09deb7dde70110a22461f7dae8680f9c
odf4/mcg-operator-bundle@sha256:ea0d0f22de398ba4f3f04943145818adc9cafcd307b994a0e7f5f5ac364b88c2
odf4/mcg-rhel9-operator@sha256:5aedbfa5c856eebd6adb198a0f04857e47d020803d7534e7058435405bd26031
odf4/ocs-client-console-rhel9@sha256:964f1d381ef6246791316e633110b6bc01264b62cb99c14924cf20d93280e2b4
odf4/ocs-client-operator-bundle@sha256:f2195100b1ca3b98ec9f9e056368e62dbb4ee2122ecde049bea446c64ab9dd30
odf4/ocs-client-rhel9-operator@sha256:fba266d10823dc543c6c65779a5790987dbd041990718a4e6e033420d4ec6b8e
odf4/ocs-metrics-exporter-rhel9@sha256:1470f9b65258bfe01ee822afc90b45ae07ebb815ec6e98712648a100c1c205f1
odf4/ocs-operator-bundle@sha256:9510fce166b116e0c4ecddbcd70fdc577e799ff08c50a25d6386e7ab18de8cc0
odf4/ocs-rhel9-operator@sha256:58eb3a9482ab4fe57c725dc503a020c5e0236360dc7eb0ee994f331707c5d672
odf4/odf-cli-rhel9@sha256:eb3e4e6341925d167b4cee3461d7613303365dc8fd137c5871e00006cf89caf4
odf4/odf-console-rhel9@sha256:df4ac23949ee52b12a98ecb60989e09f43c1025c8dc4bc5ae44ea560e0d99ccd
odf4/odf-cosi-sidecar-rhel9@sha256:0f4b6c7d8756a97aff5b8eae52d1aabc0cf796e7d4df15ee6c3196f5510ea7e0
odf4/odf-csi-addons-operator-bundle@sha256:1139a4665b08d32925b4190c986a609cad915ae3c6dcd7eac2601c71e77f0dca
odf4/odf-csi-addons-rhel9-operator@sha256:f3ecfb23720ce4b47331b19d249aed2226ee63d68fe93748afb94e3a9ad2131e
odf4/odf-csi-addons-sidecar-rhel9@sha256:25f96f20128d204caba81d4693ec61baafc5f8a900f43e90527cbd64a045a8cc
odf4/odf-multicluster-console-rhel9@sha256:8fb24296dfcf41cbe962ae2d3a8d86ab39786e23481f3a92833aadad43a2f308
odf4/odf-multicluster-operator-bundle@sha256:a844ee697841cb51eac559c8c561cfd7a906bb947a6907ded57875decb19137d
odf4/odf-multicluster-rhel9-operator@sha256:c445dc0b1b2b1c94c55960eac7e84e4e81c3aec81ca02d3da8c53213b394df89
odf4/odf-must-gather-rhel9@sha256:f2bae7c89d640f6b8cb5c32fa7e67afed52b505cc45f65e7ae5b2a2d5a5589a7
odf4/odf-operator-bundle@sha256:62c5794bfddc62e1d5659cd74bd413ed9405ed0f37593a9d1aa9aad8e6cdce14
odf4/odf-prometheus-operator-bundle@sha256:0d840d865e07a03e4ca28f03f7664f0ccebe59bb66d8bb3ad9225d752c3dbb6e
odf4/odf-rhel9-operator@sha256:2eeaf709db0105f76eb22866dc954def36f1bef841c169aac9d4bbb82107cc22
odf4/odr-cluster-operator-bundle@sha256:2408fa36474bb15c44b2c62e44b593830cdb5c02aad97ba5c0e06ed822340899
odf4/odr-hub-operator-bundle@sha256:46290400c65f199a162934a44e3598daa5e0afc9d559bb0804e2e26334fe0c3d
odf4/odr-recipe-operator-bundle@sha256:f2b76b42a6bd1304a343424b39dfc0eeac5e36b55885e78182bbf3462f2b5c08
odf4/odr-rhel9-operator@sha256:4510316e9ecaf26e0119f9f3d204e35c7eea9e6ac2413ccd545e11686ad491ca
odf4/rook-ceph-operator-bundle@sha256:38807f2cd0fe69b52673cae4185d55d6f6e1616cc9f06fcbc2b406ef8ad41262
odf4/rook-ceph-rhel9-operator@sha256:296e091bd6e552ce9d404860894bdbaaf6b6ecfe02bf4ef06c50c1035d4b4f4d

s390x

odf4/cephcsi-operator-bundle@sha256:30d43c3be80862cedb6005de7796914c92fd11714676b6d19b05d640009d9532
odf4/cephcsi-rhel9@sha256:add249635e156c1a593e8fc5d94b0573417dc995c0bd539930f2db33516ff03c
odf4/cephcsi-rhel9-operator@sha256:16ffe818c3aad7f8ca4234f7e1532de6103cabf18118d3bd2e804096039ca797
odf4/mcg-core-rhel9@sha256:72015e7ada8b27de1d5c4f51cbc7e1acd43ecd6d76dcad4179d168d7efedd6bb
odf4/mcg-operator-bundle@sha256:a28502df667109bbf0ae7753133773cf7b17d3402ca94fe034d537d6eca1ebff
odf4/mcg-rhel9-operator@sha256:61cbb4eb6890fa4f05ad94db49aea48d9e5e16b1a3b2207ef83481dee4023b01
odf4/ocs-client-console-rhel9@sha256:4139d6018427699d5f58483763d903580e0058d47a4796245839ff7bf4de8b67
odf4/ocs-client-operator-bundle@sha256:444132c650a1edb4c0ebb15c0335930c0b35ff1ee82a14dd6cd1773cc0cc0c7d
odf4/ocs-client-rhel9-operator@sha256:ef7c14e6a139a8dfff61ebc0a64907e245b7fce61e53a203290ccdc90224e96e
odf4/ocs-metrics-exporter-rhel9@sha256:ded2f695ffdbbe6756b5e453b661661a7af4e1a44d654ad16b3c46c342eb0fad
odf4/ocs-operator-bundle@sha256:5ec543d8f01082a1bc9aebce4bc25d15d5ed82ca22fa4decd74339815e927254
odf4/ocs-rhel9-operator@sha256:5ac92144c3654ef2b5aa1777707f6d7c62a7df8a824fe6ed8bfa939eee1c5653
odf4/odf-cli-rhel9@sha256:9bd96b85a88e7ed5a0f59a085ed202f9a367507a8a36ee0e2490e0988be051b1
odf4/odf-console-rhel9@sha256:a41716b3576340cdf6238b14c608dd8f004cb4b73e152af850f775668a9b038c
odf4/odf-cosi-sidecar-rhel9@sha256:2790462ac5c501fd0086833e40fd61e48d98abe2da432ef8693b76767bb7cb4a
odf4/odf-csi-addons-operator-bundle@sha256:467d4e95473a00a19f7283b3dcafb17a83aab41e5058bf595a0fcd6142b7a9f2
odf4/odf-csi-addons-rhel9-operator@sha256:e978a7dea357209b7521a473c6902343f66d986c6dd6c127e7cee316a5018069
odf4/odf-csi-addons-sidecar-rhel9@sha256:7be537a65414e2b3c6e09b5217fa71ac6efda974ddd0fea6ebc7fbe1a6e70fe1
odf4/odf-multicluster-console-rhel9@sha256:ab8a42c3c9141933c51b938014274c6e3dd5961805e59f53993c0e64fb979ac3
odf4/odf-multicluster-operator-bundle@sha256:0044ed69aeda2737c6f7c17f30c84cb33f576da6cb1833e68a6cf013f2468c82
odf4/odf-multicluster-rhel9-operator@sha256:4f73f8e61c41e41f9d2ee0e2843fcfef826825a5936d339b113f4206b1dcc63e
odf4/odf-must-gather-rhel9@sha256:e4ff4b076eba03977f59249ac10980e16b5f08f989f3c8ec3f73f852691ed9bf
odf4/odf-operator-bundle@sha256:f69f0fa516eda64f03a4ec9501647325080b3f3db356aea6901ef6cea3254393
odf4/odf-prometheus-operator-bundle@sha256:759495471a32610f9800b24b2c7da0c81be28e9b5fe63a77f430e31e32e65ea1
odf4/odf-rhel9-operator@sha256:0c9b66608ecfdf44123faf627911d9ef0930108713a35093c36030c102e435b9
odf4/odr-cluster-operator-bundle@sha256:b3fd73799713d22a947afebf4cf4b1e19450ad378da1719ee4b381ff432de578
odf4/odr-hub-operator-bundle@sha256:bf05f0a956189e3b50cf436b607912940f7919ad4d69011467a9f275eba0866c
odf4/odr-recipe-operator-bundle@sha256:ac55c4614e5667e15f7e477247b4cbf200f1d60bdbab3f4caa406b266aee5197
odf4/odr-rhel9-operator@sha256:cef164813b3b6c823fd4308a06017318183d5e58c6a8e74ef017cd98dd1fcc99
odf4/rook-ceph-operator-bundle@sha256:b68e507479e62b2aac047f7d2234c5b18e273546cde5b9a091a088af7957ad3b
odf4/rook-ceph-rhel9-operator@sha256:f57751a1d6ae5d5def0b6e92af63b887aeda8be98fdc2870a916dd14448af0f0

x86_64

odf4/cephcsi-operator-bundle@sha256:d600ce5b1b0cd8f7892b4987fca42033ba432012055be1a2326b71692e222978
odf4/cephcsi-rhel9@sha256:f12b9c820f9980c425a4a76003c07eb9b32187c26d944db64f1869b7a23ff196
odf4/cephcsi-rhel9-operator@sha256:640902f3b14d380dab2dc1bb4bf2a3fb3e7677bce6e651d0db37669b93140558
odf4/mcg-core-rhel9@sha256:0d29e75cd1c1ee1ead3a3f0a08ad19143a6a13c94d42496e07a1f3507f44f9ac
odf4/mcg-operator-bundle@sha256:f8d28240d1a1d30ad403f630275af447b53c2ed7c8c5e6dd69d8668124f8732b
odf4/mcg-rhel9-operator@sha256:d1397b951bd69bd738d7e8483acfcf1d26e81a23725212d514cb55f2a6918866
odf4/ocs-client-console-rhel9@sha256:c22a421fdbce6d0854b6ce5f506e258d0cbd8e246016852cbcf4da0cc435b0a1
odf4/ocs-client-operator-bundle@sha256:d87c7482adc413b531ecc4e02b8f184c2f57b47d00fb83f29e290db38e079b43
odf4/ocs-client-rhel9-operator@sha256:7e7af8c80bea737633a37f583780026dd6b60c75350e879aede0dda310d650eb
odf4/ocs-metrics-exporter-rhel9@sha256:46aebee17d667d6837e91592d76200d8855bb77e18fe321813c250d70a7b4747
odf4/ocs-operator-bundle@sha256:e00dd0625fd985e093554675e84295599ae225e8125e6288cc88753112013b0f
odf4/ocs-rhel9-operator@sha256:07032c346831793eac94de088aa1acae84e96133cf3515f923df5485b9e0d85c
odf4/odf-cli-rhel9@sha256:c72f2f39b2372fced7c2e0b7a99569f27730586b8e76a416b0d938f6fe6dd22d
odf4/odf-console-rhel9@sha256:977a0a4220d79920eeb4c459cd03145709f295ffd2ae3dfea0c45060e662b60a
odf4/odf-cosi-sidecar-rhel9@sha256:965634a329569350b4a604535e3545a008677f26609f92d16c68f993258143ca
odf4/odf-csi-addons-operator-bundle@sha256:612a3cc79df0b85024d37269ef5a444ce9af95623e10a254e3092671a1ec8222
odf4/odf-csi-addons-rhel9-operator@sha256:74a88775abbb0db9e992fbff45e398e1c6b6c9018eb8da21f1769c616e6d83eb
odf4/odf-csi-addons-sidecar-rhel9@sha256:292a444e09771b4899a519c81c140da95552d500715b5295d625d9b804609b52
odf4/odf-multicluster-console-rhel9@sha256:5daad7730035918838fa6329f6538967ee35d3ff02225d18cf7076479bb4d1d4
odf4/odf-multicluster-operator-bundle@sha256:f6e581bec8e759e91a96dd06590707fe3e60dcb1ba6cfa8e001b45ea0f327055
odf4/odf-multicluster-rhel9-operator@sha256:dac23d2afda5e7dc8c3c8afc338bb35dac5ddbb864653d5679c8ac23326e4c79
odf4/odf-must-gather-rhel9@sha256:92cea5daccad0974092d2d27a7d38f6ef00f3c7d0df0580b5735b163554db50a
odf4/odf-operator-bundle@sha256:e286de5001faea1747b483793d51b39e83dbe25f8a1094e459f17e1341047762
odf4/odf-prometheus-operator-bundle@sha256:963e67fccc6fa4c67f811ba29438745b9e6d73c63007af63a69505fac4a5ddba
odf4/odf-rhel9-operator@sha256:6737d42a1b9d11a2b5f35a4004f28a82e42fe753c1f3e4e96fef0f735ab45bd0
odf4/odr-cluster-operator-bundle@sha256:38de32b6fd0aa1a501025e8be7450dc2753faad0d97f30a15a0193e194cbca95
odf4/odr-hub-operator-bundle@sha256:d93fe3b85485da38ceedfc5a62ddac731c8a1eff38e5ba82782d2a899050a36d
odf4/odr-recipe-operator-bundle@sha256:76369c4ae3fae85d0a5497f164e566c16fcc581f6d5cd449ce030a19b9892ed0
odf4/odr-rhel9-operator@sha256:039b6d64c7665ef886c518746662e394657090f752dd1cb473f23ed6fbaaa20c
odf4/rook-ceph-operator-bundle@sha256:be2a4701442d53220033db3668f8d8a0b2e83e420689b22a77ac4ffc4c17c66f
odf4/rook-ceph-rhel9-operator@sha256:9ec9c59be6e0702337027afde5727e1886e741e6358faa722bf6973fa3e3efb0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility