live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

OpenShift 4.22.11 addresses CRI-O passwd injection and Go traversal flaws

Red Hat rates the asynchronous update Important and advises all OpenShift 4.22 users to install its updated packages and images.

Before-and-after OpenShift update illustration.
AI-generated illustration
By The News Desk· Aug 25, 2026

Red Hat has released OpenShift Container Platform 4.22.11 as an asynchronous security and bug-fix update, rating the security impact Important and advising all 4.22 users to upgrade when the release reaches their update channel. The update is split between an RPM package advisory and a container-image advisory.

Three named package-level fixes

The RPM advisory names three security fixes. One addresses a CRI-O bypass of an earlier fix that could allow /etc/passwd injection through the HOME environment variable (CVE-2026-15809). A second fixes directory traversal caused by symlink following in Go's os.Root implementation (CVE-2026-39822). The third addresses denial of service from a maliciously crafted MIME header in Go's MIME handling (CVE-2026-42504), according to RHSA-2026:57361.

Red Hat's companion image advisory carries the updated OpenShift release images for x86_64, s390x, ppc64le and aarch64. It also lists additional CVEs covered by the image update and a set of bug fixes, including a PinnedImageSet condition that could become stuck, an Azure Disk CSI controller crash, excessive creation of per-user console-settings ConfigMaps and kube-apiserver thread exhaustion in a FIPS-mode scenario.

What administrators should do

Red Hat says administrators can check for 4.22.11 through the OpenShift web console or with the oc command-line tool once the update is available in the appropriate release channel. Applying the update requires both the package and image components described by the paired advisories; the RPM advisory explicitly directs all OpenShift 4.22 users to move to the updated packages and images.

The practical takeaway is straightforward: this is not merely a routine patch-level rollup. Red Hat has attached an Important security rating, identified three package-level vulnerabilities by name and coupled those fixes with updated cluster images. Operators should review the advisories against their 4.22 estates and schedule the update through their normal cluster-change process.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.