- Issued:
- 2026-07-20
- Updated:
- 2026-07-20
RHSA-2026:41941 - Red Hat OpenShift Data Foundation 4.18.25 security, enhancement & bug fix update
Synopsis
Red Hat OpenShift Data Foundation 4.18.25 security, enhancement & bug fix update
Type/Severity
Security Advisory Important
Topic
Red Hat OpenShift Data Foundation 4.18.25 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.18.25 security, enhancement & bug fix update
FIXED BUGS:
DFBUGS-7343: RHODF 4.18.25 release DFBUGS-7010: [GSS] kube-rbac-proxy in OCS metrics exporter logging full bearer tokens DFBUGS-6941: [4.18.z] Integrate ibm-storage-odf-operator 1.9.0 DFBUGS-6821: [GSS] noobaa DB grows with errors BlockStoreAzure _delete_blocks failed for block DFBUGS-6524: CLONE 4.18 - [UI] Resource profile calculations doesn't include NFS DFBUGS-6462: Backport to odf-4.18.z [RDR] Partial s3StoreProfile missing in ramen-hub-operator-config after upgrading hub from ODF 4.17 to 4.18 DFBUGS-6406: [Backport to odf-4.18.z] Fail upgrade Provider with client cluster. ocs-operator csv stuck in pending DFBUGS-6178: Backport to odf-4.18.z Noobaa POD keeps Failing when Clusterwide encryption is enabled with IBM KeyProtect on ROKS Cluster DFBUGS-4848: [Backport to odf-4.18.z] [GSS] Noobaa certificate verification for NamespaceStore endpoints
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat OpenShift Data Foundation | 4.18 | x86_64 |
Fixes
(none)
CVEs
- CVE-2025-12816
- CVE-2025-13465
- CVE-2025-15284
- CVE-2025-47907
- CVE-2025-58183
- CVE-2025-61726
- CVE-2025-61729
- CVE-2025-66031
- CVE-2025-68157
- CVE-2025-68458
- CVE-2025-69873
- CVE-2026-25896
- CVE-2026-26278
- CVE-2026-26996
- CVE-2026-27904
- CVE-2026-27942
- CVE-2026-29063
- CVE-2026-33036
- CVE-2026-33186
- CVE-2026-34986
- CVE-2026-4800
- CVE-2026-48779
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.