live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsPLATFORM

OpenShift 4.21.30 addresses Zen 2 privilege escalation and Vim archive command injection

Red Hat rates the asynchronous update Important and advises all OpenShift 4.21 users to move to the updated packages and images.

OpenShift update split across images and RPM packages.
AI-generated illustration
By The News Desk· Aug 26, 2026

Red Hat has issued OpenShift Container Platform 4.21.30 as an Important security and bug-fix update, covering container images and the accompanying RPM package set. The update addresses three vulnerabilities, including a privilege-escalation issue affecting AMD Zen 2 processors and a Vim command-injection flaw triggered while decompressing .tgz archives.

What changed

The container-image advisory lists CVE-2025-54518, an AMD Zen 2 cache-isolation flaw in Xen that can allow privilege escalation. It also fixes CVE-2026-43112, an out-of-bounds read in the Linux CIFS client’s path sanitization, and CVE-2026-46483, a Vim command-injection vulnerability involving compressed tar archives.

Red Hat split the asynchronous OpenShift release across two advisories: RHSA-2026:57457 carries the release images, while RHSA-2026:57456 supplies the RPM packages. The package advisory updates OpenShift components and supporting software across the RHEL 8 and RHEL 9 variants used by OpenShift 4.21, including client and node-side packages.

Who is affected

The advisory applies to OpenShift Container Platform 4.21 on x86_64, aarch64, IBM Z and LinuxONE, and Power architectures. The Zen 2 vulnerability is hardware-specific, but the release also contains the CIFS and Vim fixes, so operators should use the complete OpenShift update rather than attempting to reason from CPU exposure alone.

Red Hat rates the overall update Important. The advisory does not describe a configuration-only mitigation; its prescribed solution is to install the updated packages and images through the supported OpenShift update path.

What operators should do

OpenShift 4.21 administrators should check whether 4.21.30 is available in their cluster’s configured release channel using the web console or oc, then follow the product’s cluster-update procedure. Red Hat advises all OpenShift 4.21 users to upgrade when the release becomes available in the appropriate channel.

Because the fix spans both release images and RPM content, teams should verify that the cluster completes the supported update rather than treating an individual host-package update as sufficient. Operators with Zen 2 worker or control-plane hardware should prioritize the change because one of the corrected defects is a privilege-escalation path; teams whose workloads handle untrusted archives should also account for the Vim command-injection fix.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.