- Issued:
- 2026-07-09
- Updated:
- 2026-07-09
RHSA-2026:37387 - Red Hat OpenShift Data Foundation 4.22.0 security, enhancement & bug fix update
Synopsis
Red Hat OpenShift Data Foundation 4.22.0 security, enhancement & bug fix update
Type/Severity
Security Advisory Important
Topic
Red Hat OpenShift Data Foundation 4.22.0 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.22.0 security, enhancement & bug fix update
FIXED BUGS:
DFBUGS-8228: DRPolicy is not updated with the SC name after creating EC RBD pool and SC on a default replica3 cluster DFBUGS-8114: [Backport to odf-4.22.0] [RDR] Same groupreplicationID value is set to all RBD StorageClasses in peerClasses irrespective of different blockpools DFBUGS-8039: [RDR] Granular VM DR is broken DFBUGS-8004: Buckets page went inaccessible after recovering from disruptions induced to node where noobaa core pod is running DFBUGS-8002: [MCG] OLM continuously cycles MCG deployments on Azure STS clusters due to non-deterministic env var ordering DFBUGS-8000: [Backport to odf-4.22] [GSS] NooBaa NamespaceStore: Stale External Connection on Endpoint Change DFBUGS-7980: Node Shutdown trigger read-write failure, needs to modify terminationGracePeriodSeconds Values DFBUGS-7411: [RDR] [dryRun] For workload in various states, ensure dryRun test failover can be promoted to real failover and works correctly DFBUGS-7388: [4.22] CLONE - DR Page UI broken after OCP upgrade from 4.21 to 4.22 nightly DFBUGS-7378: [release-4.22] CLONE - [GSS] odf-blackbox-exporter ODFNodeLatencyHighOnOSDNodes : msg="Timeout reading from socket" module=icmp_internal DFBUGS-7355: CVE vulnerabilities in ODF 4.22 release DFBUGS-7347: ocs-operator hardcodes NooBaa autoscalerType to hpav2, preventing KEDA autoscaling DFBUGS-7337: [4.22] QueryVectors returns identical distance values regardless of index distance metric (cosine vs euclidean) DFBUGS-7328: High CPU usage of nodejs built in https.Agent.getName function DFBUGS-7327: [Fusion Access][Migration]Scale operator deployment scales down to 0 following upgrade from 6.0.0.2 to 6.0.1.0 during migration DFBUGS-7325: [Fusion Access][Migration] FDF UI is not enabled following Fusion Access to Data Foundation Fusion access migration
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat OpenShift Data Foundation | 4.22 | x86_64 |
Fixes
(none)
CVEs
- CVE-2024-25621
- CVE-2024-40635
- CVE-2024-45310
- CVE-2025-21613
- CVE-2025-21614
- CVE-2025-22870
- CVE-2025-47911
- CVE-2025-52881
- CVE-2025-54410
- CVE-2025-58058
- CVE-2025-64329
- CVE-2025-66506
- CVE-2025-8766
- CVE-2026-22772
- CVE-2026-23831
- CVE-2026-24117
- CVE-2026-25680
- CVE-2026-25681
- CVE-2026-25934
- CVE-2026-27136
- CVE-2026-27141
- CVE-2026-27903
- CVE-2026-33540
- CVE-2026-33747
- CVE-2026-33748
- CVE-2026-33814
- CVE-2026-34986
- CVE-2026-35172
- CVE-2026-35469
- CVE-2026-39821
- CVE-2026-39827
- CVE-2026-39828
- CVE-2026-39829
- CVE-2026-39830
- CVE-2026-39831
- CVE-2026-39832
- CVE-2026-39833
- CVE-2026-39834
- CVE-2026-39835
- CVE-2026-39883
- CVE-2026-41506
- CVE-2026-41567
- CVE-2026-41568
- CVE-2026-42502
- CVE-2026-42506
- CVE-2026-42508
- CVE-2026-44740
- CVE-2026-45571
- CVE-2026-46595
- CVE-2026-46597
- CVE-2026-46598
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.