- Issued:
- 2026-07-16
- Updated:
- 2026-07-16
RHSA-2026:40984 - Red Hat OpenShift Data Foundation 4.20.15 security, enhancement & bug fix update
Synopsis
Red Hat OpenShift Data Foundation 4.20.15 security, enhancement & bug fix update
Type/Severity
Security Advisory Important
Topic
Red Hat OpenShift Data Foundation 4.20.15 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.20.15 security, enhancement & bug fix update
FIXED BUGS:
DFBUGS-7340: RHODF 4.20.15 release DFBUGS-7331: [Backport for 4.20] - [GSS][ODF][MCG] noobaa-db-pg-cluster won't synchronize anymore - "could not receive data from WAL stream: ERROR: requested WAL segment 00000008000001C600000068 has already been removed" DFBUGS-6939: [4.20.z] Integrate ibm-storage-odf-operator 1.9.0 DFBUGS-6666: [Backport to odf-4.20.z] Remove duplicate PersistentVolumeUsageCritical alerts DFBUGS-6528: [Backport to 4.20.z] maintenance mode is always set for storageclients in non RDR clusters DFBUGS-6522: CLONE 4.20 - [UI] Resource profile calculations doesn't include NFS DFBUGS-5418: [Backport to odf-4.20.z]Local Storage Operator not installed install link broken in OCP 4.20 DFBUGS-4843: [Backport to odf-4.20.z] [RDR] Failover for an RBD appset workload remains stuck, workload pods don't restore
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat OpenShift Data Foundation | 4.20 | x86_64 |
Fixes
(none)
CVEs
- CVE-2025-12816
- CVE-2025-13465
- CVE-2025-15284
- CVE-2025-66031
- CVE-2025-68157
- CVE-2025-68458
- CVE-2025-69873
- CVE-2026-22029
- CVE-2026-25128
- CVE-2026-25896
- CVE-2026-26278
- CVE-2026-26996
- CVE-2026-27904
- CVE-2026-27942
- CVE-2026-29063
- CVE-2026-33036
- CVE-2026-33186
- CVE-2026-33815
- CVE-2026-33816
- CVE-2026-34986
- CVE-2026-4800
- CVE-2026-48779
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.