live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseSECURITY

OpenShift 4.19.44 closes 11 Important-rated security flaws

The asynchronous update addresses code-execution, privilege-escalation, policy-bypass and denial-of-service risks across supported OpenShift 4.19 architectures.

OpenShift 4.19.44 fixes 11 security flaws.
AI-generated illustration
By The News Desk· Aug 27, 2026

Red Hat has released OpenShift Container Platform 4.19.44 as an asynchronous security and bug-fix update, rating the advisory Important and advising every OpenShift 4.19 user to move to the updated packages and images when they reach the appropriate release channel. The RHSA-2026:57402 advisory, issued August 26, lists 11 vulnerabilities across the release payload.

What changed

The fixes span several layers of the OpenShift host and tooling stack. Red Hat lists a Linux kernel privilege-escalation issue affecting AMD Zen 2 cache isolation, two GnuTLS denial-of-service flaws, and a GnuTLS name-constraints policy bypass. The same advisory also names a systemd issue that can permit arbitrary code execution or denial of service through malformed IPC API data.

Developer and administrative tooling accounts for another part of the update. Three Vim vulnerabilities cover a modeline sandbox bypass, path traversal in the zip plugin and command injection through malicious tag files; a fourth covers command injection while decompressing .tgz archives. Red Hat also includes an out-of-bounds read in the kernel CIFS client and a heap buffer overflow in libsolv’s handling of compressed repository data.

OpenShift 4.19.44 ships updated release images for x86_64, aarch64, ppc64le and s390x. Red Hat points users to a separate RPM advisory for the matching package updates, so administrators should treat the container-image and RPM portions as one maintenance event rather than applying only the release image.

Who is affected

The advisory covers OpenShift Container Platform 4.19 deployments on RHEL 8 and RHEL 9 across x86_64, ARM64, Power and IBM Z/LinuxONE. Exposure to an individual vulnerability depends on the workloads, host hardware and components in use, but the vendor’s instruction is not conditional: all 4.19 users should upgrade.

The mix matters operationally. Some flaws require crafted files or protocol traffic, while the systemd and kernel issues sit below application workloads. Platform teams therefore cannot reduce this release to a single exposed service or application dependency.

What to do

Administrators should monitor the OpenShift update channel, inspect the offered 4.19.44 payload with the oc CLI or web console, and follow Red Hat’s linked cluster-update procedure. The advisory publishes architecture-specific image digests, which can be checked against the release selected for rollout.

Normal OpenShift update discipline still applies: confirm operator and workload health, stage the update where the deployment model permits, and verify nodes and cluster operators after completion. Teams that mirror release content should also make sure both the updated images and associated RPM content are available before scheduling the maintenance window.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.