live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseAI

OpenShift AI 3.4.3 bundles a Critical security update with operational fixes

The asynchronous update lists 20 CVEs and repairs failures in vLLM inference, model serving, pipelines and dashboard access.

By The Release Desk· Aug 18, 2026

Red Hat issued OpenShift AI 3.4.3 on August 11 as a Critical security advisory. The advisory lists 20 CVEs and publishes updated OpenShift AI images across amd64, arm64, ppc64le and s390x.

What changed

The 3.4 resolved-issues notes describe 3.4.3 as an asynchronous errata release carrying security updates, bug fixes and enhancements.

The operational fixes extend beyond the security payload. Red Hat says 3.4.3 prevents vLLM from terminating on IBM Z when an inference request explicitly includes the temperature field. It also restores the ability to stop models served through the Distributed Inference Server with llm-d runtime from the OpenShift AI dashboard.

Other resolved problems include missing Feast certificates and a service in the default configuration, runtime-image lists that did not populate for the first workbench in a namespace, and model deployments whose hardware-profile tolerations, node selectors or identifiers were not injected into the underlying InferenceService.

Who it affects

The security advisory applies to Red Hat OpenShift AI. The resolved-issues list is especially relevant to teams operating vLLM on IBM Z, llm-d-backed distributed inference, Feast feature stores, Elyra pipelines, and model-serving workloads scheduled through hardware profiles.

Platform teams should also note fixes for dashboard access through standard OpenShift routes and for clusters that already run Argo Workflows alongside Data Science Pipelines.

What to do

Administrators should review RHSA-2026:53262, identify the affected OpenShift AI 3.4 deployments, and follow Red Hat’s linked product documentation for the upgrade procedure. Because Red Hat rates the advisory Critical, this is an update to schedule through the normal security-change process rather than defer as a routine feature patch.

After updating, teams with affected workflows should verify vLLM requests that set temperature, llm-d model stop operations, Feast SDK access from workbenches, and hardware-profile scheduling. Those checks map directly to the failures Red Hat lists as resolved in the 3.4.3 notes.

Filed by The Release Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.