CVE-2026-31431 Mitigation for Managed OpenShift (Zero-Reboot BPF LSM DaemonSet)
Issue
All OpenShift clusters are confirmed to be affected by CVE-2026-31431 ("Copy Fail"), which has been classified as an important vulnerability.
Red Hat is developing a fix for the CVE that will be released in z-streams for OpenShift 4.16, 4.18, 4.19, 4.20, and 4.21. Until the fix is released, a mitigation can be applied to the cluster to disable the affected component.
Environment
- Red Hat OpenShift Service on AWS (ROSA Classic)
- 4
- Red Hat OpenShift on AWS with Hosted Control Plane (ROSA HCP)
- 4
- Azure Red Hat OpenShift (ARO)
- 4
- Red Hat OpenShift Dedicated (OSD)
- 4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.