- Issued:
- 2025-07-28
- Updated:
- 2025-07-28
RHSA-2025:11814 - Security Advisory
Synopsis
Red Hat OpenShift Data Foundation 4.19 security, enhancement & bug fix update
Type/Severity
Security Advisory: Moderate
Topic
Red Hat OpenShift Data Foundation 4.19 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.19 security, enhancement & bug fix update.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.19/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf
Fixes
- DFBUGS-2705 - [Backport to 4.19.0] invalid_storage is shown in the --all_connection_details
- DFBUGS-2324 - rook-ceph-rgw-ocs-storagecluster-cephobjectstore pod crashes with ODF v4.19.0-75 deployment with host networking enabled
- DFBUGS-2279 - ODF 4.19.0-75 internal mode deployment deploys pods on Control nodes
- DFBUGS-2273 - Not able to create CORS rules from UI
- DFBUGS-2031 - Connection information is wrongly listed for noobaa-cli diagnose health --all_connection_details
- DFBUGS-1917 - [GSS]Rook-ceph-exporter pods keep spinning up
- DFBUGS-1801 - ODF with RDR and multipath fails during upgrade from 4.17 to 4.18 - OSD migration fails as ceph-volume fails to fetch the multipath device
- DFBUGS-1634 - [UI] Skeleton Screens, data elements are misplaced, incorrect color scheme
- DFBUGS-1627 - odf-console pie graph text has minimal contrast - is dark against a dark background
- DFBUGS-857 - [RDR] Unable to set recipe parameters when enrolling discovered application
- DFBUGS-734 - [2309444] [RDR] When cluster was upgraded from 4.16 to 4.17 osd migrated to new ceph osd id's
- DFBUGS-711 - [2313185] [IBM_Support] Rados clone data objects are not getting trimmed and consuming the space in the cluster even after upgrade to ODF 4.14
- DFBUGS-585 - [2323317] ODF mg doesn't capture everything with portworx installed
- DFBUGS-513 - [2319814] [RDR] Volsync Job Name exceeds 63 characters when application PVC exceeds 42 characters
- DFBUGS-501 - [2305603] [CNV][MDR] VM not failed over and in WaitForReadiness status
- DFBUGS-340 - [2321386] [RDR] When globalnet is needed but it's not enabled, output shows this as a info
- DFBUGS-289 - [2313368] Must-gather is not collecting old(.gz files) csi logs from client cluster in provider mode setup
- DFBUGS-280 - [2296500] Ceph osd aborted in thread 7f71d41a9640 thread_name:safe_timer
CVEs
amd64
| registry.redhat.io/odf4/cephcsi-rhel9@sha256:0a34f80704191711af925a5eafbf3d45f72fb55222ae357386df09a295a20834 |
| registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:70170410fbfc1121b81ec1598f345b3ca2dd3f4ff3214fea081d74d852e57351 |
| registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:3ca66371d708d76c3ec47c9b7a140a8cd7c1200ba7929aa419dbbdc936af4fe7 |
| registry.redhat.io/odf4/mcg-core-rhel9@sha256:5ada583afb6f8cf23741153e7a574b82cb485b2433972bb9c780d7a95652cb56 |
| registry.redhat.io/odf4/mcg-rhel9-operator@sha256:b7c2eee37459dc3ea41b6db3a56b7ef9928b58e41439125d3e8670019d10ff88 |
| registry.redhat.io/odf4/mcg-operator-bundle@sha256:00fff93a5a589711826118c506438877174e131584ebb871efe9d6059140a187 |
| registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:b0145219aad39170213553dafc87306d3b48aa3b98abf7ffb07c343cdfb3687a |
| registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:cbae777c37f01d401a1a6f1c5f74f623c9d0460437f4e60f917724b1df2d4ed1 |
| registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:1941ebe24223df7cc66733f908b4b3160c03e3cb0330ca0bfc1f87dfff86134c |
| registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:19aed11229ea7260503c01414734da44e3e17363a652ba62fb54c7418405216a |
| registry.redhat.io/odf4/ocs-rhel9-operator@sha256:f1fe3b8f74e5a44aea2654e02312b15035b74ba1bc73715e2aee50567ef1cb06 |
| registry.redhat.io/odf4/ocs-operator-bundle@sha256:cc7a6db8f49ad9795d9c5f44988eab9206df146e33752354c30a04f3129cad59 |
| registry.redhat.io/odf4/odf-cli-rhel9@sha256:1554434fe9e5dcba907c7ec48b5cbb38e74fbf909008706ec0349588187175a7 |
| registry.redhat.io/odf4/odf-cloudnative-pg-rhel9-operator@sha256:f07db836cd49057380480a19cdbcefc624991a2edbfa7dccb41a11a567cd3126 |
| registry.redhat.io/odf4/odf-console-rhel9@sha256:65beff9c26c5041c29baeb6b0cb0b9ce73531cdfbc1eff780de2ce1d73a01a35 |
| registry.redhat.io/odf4/odf-cosi-sidecar-rhel9@sha256:0aa482a9bb273ba3aa14b859d748398d662d2fe0ebca0c0adffabc1a099fce42 |
| registry.redhat.io/odf4/odf-csi-addons-rhel9-operator@sha256:b0d960c47d8b3047da9b4595d6915817935d52ad0299f36eab92d2f80c5048cc |
| registry.redhat.io/odf4/odf-csi-addons-operator-bundle@sha256:90b36e3de86d620badd58c7ea2aca05584a935b763b576a604e282c1a0c59247 |
| registry.redhat.io/odf4/odf-csi-addons-sidecar-rhel9@sha256:e9583e0bd0bc5a2d83684537093bc3cf7f96126766fd6477ad32c4478d10b03d |
| registry.redhat.io/odf4/odf-dependencies-operator-bundle@sha256:2b63eeb22137bfb692ed2369e371778517e084e4fb7ed3467d0c8e0f3da1e995 |
| registry.redhat.io/odf4/odf-multicluster-console-rhel9@sha256:b32a929cb4af5f23f57aad76387d3f4cca3f019361c88759545e04896c4afd9c |
| registry.redhat.io/odf4/odf-multicluster-rhel9-operator@sha256:01ab589db80dcd93ce5bd96f21c6fdfa0fc47de7f21bce44c77315f9385a9907 |
| registry.redhat.io/odf4/odf-multicluster-operator-bundle@sha256:b1f3607527c47dc64081babaf4a1e09bc21538b1be8c88c4336708ededeea54a |
| registry.redhat.io/odf4/odf-must-gather-rhel9@sha256:3db845c2a76cf8409362639a3b475082f96b8e7c7220e1b75c5bf6567227b0f5 |
| registry.redhat.io/odf4/odf-rhel9-operator@sha256:03c2b90f9c62efed4a2bfbaad061c45677c6fdc6696a34235b4c94b1421e4f9d |
| registry.redhat.io/odf4/odf-operator-bundle@sha256:b79e8e89597691a2644c4b0fa1a761788e496804a5ad9a094412b54cffedd186 |
| registry.redhat.io/odf4/odf-prometheus-operator-bundle@sha256:5c453cdbc218cb4af7cedb60539ad21641add9e4e8d8a40c77eda98cee466ee1 |
| registry.redhat.io/odf4/odr-cluster-operator-bundle@sha256:1f58e64ad3218bf667bc179649edb23951b78e1382d50bdffc7708f26d032e7b |
| registry.redhat.io/odf4/odr-hub-operator-bundle@sha256:810c532e01793c945482e47ade12f1273585654bffaa35d568ece93f0d2a1838 |
| registry.redhat.io/odf4/odr-rhel9-operator@sha256:c7e06848cb2507d01511a3b226aca037a40824e533ae2ad17cb67ba9eb641f1d |
| registry.redhat.io/odf4/odr-recipe-operator-bundle@sha256:195c19a950440bf7c6ae0d143fb555077aea184b4eea52ba6fb5ba904d83aa00 |
| registry.redhat.io/odf4/rook-ceph-rhel9-operator@sha256:620bb2e96a12ba5566d4117b7a61a5f3b86b6ea61991f8af34051cabded7c237 |
| registry.redhat.io/odf4/rook-ceph-operator-bundle@sha256:a2b3fde683d7e6d321fac899ac88a3a3f9bacace84ce0a15c2c288d4eeea1d97 |
ppc64le
| registry.redhat.io/odf4/cephcsi-rhel9@sha256:ce386e492abc222b731047626ddd3075040fcee46b4c8ea89cde9602c060e083 |
| registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:40bdf2103c5a138977f2a15043a7a4039887815196a1399d562ae4f707316551 |
| registry.redhat.io/odf4/mcg-core-rhel9@sha256:c34f5d37e289f1e68087b534c4dbfc630b4aca0e1941f91a67f9793d6dd6e548 |
| registry.redhat.io/odf4/mcg-rhel9-operator@sha256:e958b536892b02d3425eef7f751f2e14a0a9d44c900058734133b26e3e812ec4 |
| registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:d4b5113f003559411a39d19c379d3c1a2040ad85c4508a3b79a38d1672a89d9d |
| registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:f1306d1f5ef2e53abf5caddd5a1584adc798826624e74d9097c9f168446073e8 |
| registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:130604fd4f316d23e66a4bdc67f8eac203fa9f0f0dbd08358723a32813f98d28 |
| registry.redhat.io/odf4/ocs-rhel9-operator@sha256:147cedf47183ebe0ae5305d15e91c4faac0a663232154a16b1277654f96d4093 |
| registry.redhat.io/odf4/odf-cli-rhel9@sha256:d1ed3a4747e30619fb84d7110015f0bd668758eefe155b8563cf9e3793637204 |
| registry.redhat.io/odf4/odf-cloudnative-pg-rhel9-operator@sha256:ac20578ab27c892b5243473cf3e5f80c3aecdf1958b43869cd2c8ec6b61062a0 |
| registry.redhat.io/odf4/odf-console-rhel9@sha256:99d97e9b086bc193ab42affd8a9f27931e9510205f1ae8ea809302dcdab9157f |
| registry.redhat.io/odf4/odf-cosi-sidecar-rhel9@sha256:b3538144a39891bf365b822755199fc702f245e11fc701c6147612c2cebd8d3d |
| registry.redhat.io/odf4/odf-csi-addons-rhel9-operator@sha256:14a4e50ace47bcf9bea05e7a71061233c65248d8e39157e5edb4b9fd34be05fd |
| registry.redhat.io/odf4/odf-csi-addons-sidecar-rhel9@sha256:ed7e9c3c919247a40797a66e49e2310625c2c74ead8b959d78fa73861a4b679b |
| registry.redhat.io/odf4/odf-multicluster-console-rhel9@sha256:6082a53e5940638da9bffd433bb7fb05a9a8e769f2d7b183211808c6c7d30588 |
| registry.redhat.io/odf4/odf-multicluster-rhel9-operator@sha256:c26707a20e15e793da4f50142f6ceab9f74a02bc96a82cf22ec5b4f8d1b180ad |
| registry.redhat.io/odf4/odf-must-gather-rhel9@sha256:0b27f15e557fb5b99564fc8b5db18f5d6ba3c0acf1f4382f8a36fd5caa54f5b0 |
| registry.redhat.io/odf4/odf-rhel9-operator@sha256:71abfcce9c126d73377ea4652c10aadb961c7a44455f90e69d23350547f477c7 |
| registry.redhat.io/odf4/odr-rhel9-operator@sha256:e9b1124695bb4ccd241564f2a7b2162c9744c6fe99df3a0cf5099026612962ee |
| registry.redhat.io/odf4/rook-ceph-rhel9-operator@sha256:806e69da7d6549a3e2f7e1dc31326989d06146a8879f0aa6bbd255358eeaf794 |
s390x
| registry.redhat.io/odf4/cephcsi-rhel9@sha256:d6f4f842de110a58594c7fe8a353da37cff578d5af30cfc45658f7f18d32c2dd |
| registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:e141b26a1d13e1176e51e5785d5de80bb72e6639c0211e12868411e982408fe5 |
| registry.redhat.io/odf4/mcg-core-rhel9@sha256:2c1082623db60c5ae019de7743a103fb512555c06c74ac263f284f23ba3c2078 |
| registry.redhat.io/odf4/mcg-rhel9-operator@sha256:7ced63d4493804bfd19882a34a2fe320aab24609a5ff850db32465be9cae4064 |
| registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:9e6ba39ac9fc614fdddfd43f21e514261e51a444dc6b02dbc41259a8ec6029e9 |
| registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:b89febbc7b26393f01d9e82cd41a9fca4d620886d227c392026edaeca2e55a00 |
| registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:c04defcbf28652a25786819fb380b6a2cfb780136443d9b434d4e2b225d2b17c |
| registry.redhat.io/odf4/ocs-rhel9-operator@sha256:1ae3ddb3af0656b9a6b14b60d85520666acb52a94919db61bcef686bc564a39e |
| registry.redhat.io/odf4/odf-cli-rhel9@sha256:cdeff14d568574dca985b1ff7659d1e712aabbdbeddc15cf26b1f85e24800e52 |
| registry.redhat.io/odf4/odf-cloudnative-pg-rhel9-operator@sha256:7e692ed581d8e65ad171796cb93719eda81092c8d7571456c50004b10fe5a6a3 |
| registry.redhat.io/odf4/odf-console-rhel9@sha256:b070ab619d400fa2e82068767edf55d228b767bd220c59bebfa009a5b8a45a33 |
| registry.redhat.io/odf4/odf-cosi-sidecar-rhel9@sha256:5f9aade3f5a643c4f45259b5195dc0f161b08286c5b97c6e451c054f6ffcb649 |
| registry.redhat.io/odf4/odf-csi-addons-rhel9-operator@sha256:56953105c66b9e8af3b8fae74056c9fce05ab26d7a01c92946a60767c72f3f87 |
| registry.redhat.io/odf4/odf-csi-addons-sidecar-rhel9@sha256:bc1be8e7b4e75c61e6f0d66a63bb76d162987d5fc39d57226261de6931aed6a2 |
| registry.redhat.io/odf4/odf-multicluster-console-rhel9@sha256:eb3513c68ff1d169b41a79b7be3f9e192d82898e69b24e96638b052819630106 |
| registry.redhat.io/odf4/odf-multicluster-rhel9-operator@sha256:91400f75b1bd36b7b8687482a4a0acea0c17828dbfd103ad781997bf8feb2c10 |
| registry.redhat.io/odf4/odf-must-gather-rhel9@sha256:996d5ba1c85255ed83bdb360e1be1a369c00d59f78e22a4f7e80ba3e477776e6 |
| registry.redhat.io/odf4/odf-rhel9-operator@sha256:ca03b97ce758eadcc6098faacd13cc073c7a2632578976be941c0a810c2c62f0 |
| registry.redhat.io/odf4/odr-rhel9-operator@sha256:5b07432b346f8ad08a4477aa1c7857cb850eaa5d6694fbe36619db44a2a201ac |
| registry.redhat.io/odf4/rook-ceph-rhel9-operator@sha256:f397f3e30ac212a6b878b7c52d960c87ba9b189154697ef556bfbcd5552484dc |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.