Submariner 0.24 goes GA in ACM 2.17 with cross-cluster networking fixes
The Important-rated release updates ACM’s multi-cluster data plane and addresses OVN-Kubernetes, Azure, service-discovery and lifecycle failures.
The Important-rated release updates ACM’s multi-cluster data plane and addresses OVN-Kubernetes, Azure, service-discovery and lifecycle failures.
The early-access branch adds new modules and lifecycle changes that OpenShift AI operators should test as an integrated platform, not as isolated components.
The update reaches internet-facing HTTP/2 and authentication paths, but several fixes matter only when specific Tomcat features are enabled.
The new containerized deployment keeps selected host data and recommendation processing inside Satellite, but it replaces hosted console services for managed hosts.
The open-source release adds an end-to-end path for training and serving draft models that predict several future tokens in one pass.
Red Hat rates the asynchronous update Important and tells 4.17 operators to apply both its package and container-image payloads.
Platform teams can now attach authentication, rate limits and plans to GRPCRoute resources while using Kubernetes-native request and approval objects for API keys.
The update spans RPM packages and container images; Red Hat advises all 4.19 clusters to move to 4.19.45 and provides no general workaround for most flaws.
The Important-rated service pack fixes 13 CVEs across common Quarkus extensions; teams should update the platform BOM and retest the features they actually ship.
Version 0.3.45 lets CI operators assign CPU, memory and GPUs to OpenShell sandboxes instead of inheriting opaque host defaults.
A crafted archive can redirect extraction through malicious links and overwrite files outside the chosen directory with the extractor’s permissions.
The release adds native-friendly bridges for agent tools, embedding stores and declarative RAG ingestion while staying on Java 17 and 21.
OpenShift sandboxed containers 1.13 takes confidential AI on bare metal to GA while a new Agent Sandbox operator enters Technology Preview.
Red Hat’s limited-availability program requires a fresh RHEL 10 installation while it tests containerized operations and ML-DSA-signed content distribution.
Standard GenAI spans and model-tagged token metrics let integration teams trace latency and attribute consumption by route and model.
The Important-rated asynchronous update spans curl, BIND, Unbound, dracut, the SMB client and openvt; 4.22 operators should move when the release reaches their channel.
The August Kafka digest points operators to unresolved 4.4 blockers, a stricter replication-safety proposal and a Strimzi release with Kafka 4.3.1 support.
The release improves compatibility with Kubernetes restricted Pod Security Standards, but user-authored steps and sidecars still need their own settings.
Red Hat’s two-month notice gives 4.14 operators until November to arrange the optional third support term or move to another supported OpenShift release.
The upstream identity release addresses OIDC policy bypasses, delegated-admin authorization gaps, token-exchange restrictions and an incomplete path-traversal fix.
The two patches share Scaffolder and catalog hardening, while 1.50.5 also tightens TechDocs configuration handling and 1.49.6 adjusts service credential delegation.
The Red Hat community project’s first post-audit release closes an anonymous YAML-read path and reconnects four deployment paths that had failed silently.
Updated EAP 8.1 and 7.4 ELS images require consumers to pull new containers and rebuild anything derived from them.
The August 24 update spans controller, gateway, Lightspeed and execution-environment images, while a new endpoint lets MCP clients discover tools progressively.
The Critical-rated release touches 106 image families and 143 CVEs; operators need the platform update, not only the earlier AI Inference image replacements.
The release adds configurable quantum-resistant key exchange while reverting reflection-free Jackson serializers to opt-in.
The asynchronous update addresses code-execution, privilege-escalation, policy-bypass and denial-of-service risks across supported OpenShift 4.19 architectures.
The important-rated vulnerability could let a compromised source repository inject code during operator-bundle builds; Red Hat says deployed systems have no configuration workaround.
The first stable release combines Open Workflow Specification YAML, a Java DSL, LangChain4j agents, event messaging and recoverable state without a separate workflow service.
The release adds tiered cache management, multimodal gRPC inference and broad accelerator work while removing several deprecated interfaces.
Red Hat’s Important update covers 28 CVEs, makes OpenJDK 21 the default, offers OpenJDK 25 and removes OpenJDK 17.
The Important-rated update covers a Punycode privilege-escalation issue and three denial-of-service flaws across MicroShift 4.16 packages and images.
Two 470M-parameter encoder-only models trade licensing and a small accuracy difference for unusually high vendor-reported throughput.
The Apache 2.0 model family adds thinking modes, native tool calling and agent training in live environments for its larger variants.
The release makes server-side apply permanent, changes installation security contexts and gives operators new controls for volumes, builds and rebalancing.
The tech-preview release adds user- and tool-level audit records, streams stateless-protocol requests and hardens Kubernetes deployment behavior.
The add-on combines task, event and AI-driven steps on one governed canvas, although Red Hat’s product page still describes early access.
RHSA-2026:53643 fixes four component flaws in Red Hat build of Quarkus and leaves operators with one supported remediation: move affected applications to 3.27.5.
Four advisories map the 3.4.4 CPU, CUDA, ROCm and Spyre images to their CVE sets; the practical response is to replace the deployed variant.
The upstream fix lands on the 26.7 line; operators on other streams should follow their distributor’s advisory rather than assume the same backport.
The early-access release previews MCP gateway guardrails, an EvalHub MCP server and batch scheduling for distributed inference.
The upstream identity release addresses eight CVEs, a cleartext vault-password exposure and a set of authentication and clustering regressions.
Critical updates cover the 26.6 and 26.4 streams across standalone packages and OpenShift images, with the newer stream also fixing secret exposure and privilege boundaries.
The Quarkus-backed Java implementation adds fail-closed checks and stream controls, but adopters must account for three breaking changes.
The release adds agent-oriented catalog types while requiring migration work for connection APIs and some OAuth allowlist patterns.
The asynchronous update lists 20 CVEs and repairs failures in vLLM inference, model serving, pipelines and dashboard access.
The release broadens the inference stack, but each new path carries distinct storage, hardware and control-plane prerequisites.
The new registry removes framework-specific route definitions, while the MCP bridge adds a deliberate exposure boundary that integration teams must configure.
The supported add-on extends OpenShift’s Metal3-based lifecycle management to external physical hosts, with separate subscription and infrastructure prerequisites.
The release adds operator modules for gateway and MCP infrastructure while expanding the dashboard’s agent, NVIDIA NIM and NeMo Guardrails paths.