OpenShift 4.22.12 fixes nine flaws across DNS, boot and local-console components
The Important-rated asynchronous update spans curl, BIND, Unbound, dracut, the SMB client and openvt; 4.22 operators should move when the release reaches their channel.
OpenShift Container Platform 4.22.12 is an Important-rated security update that closes nine CVEs across cluster images and underlying operating-system components. Red Hat issued the asynchronous release on Sept. 1 and advises every 4.22 operator to upgrade when it appears in the appropriate release channel.
What is fixed
The security advisory groups the fixes into six component families. Two curl flaws concern TLS-configuration mismatch and SSH host-key bypass. BIND receives fixes for a wildcard CNAME response-policy-zone bypass and incorrect acceptance of NSEC3 records, while Unbound receives fixes for potential cache poisoning and denial of service through a malformed EDNS Report-Channel option.
The remaining issues sit closer to the node. A dracut flaw could turn an unescaped error message into root code execution through a sourced emergency hook script. The kernel SMB client now validates the PathConsumed value in DFS referrals. The openvt utility receives a local-privilege-escalation fix for incorrect process-owner verification that could allow a passwordless root login.
The advisory covers OpenShift 4.22 on RHEL 8 and RHEL 9 across x86_64, 64-bit Arm, IBM Power and IBM Z/LinuxONE. It contains the updated container images; Red Hat links the accompanying RPM changes separately as RHBA-2026:60439.
Fixed release images
Red Hat identifies architecture-specific 4.22.12 release-image digests so operators can verify the payload they are promoting:
- x86_64:
sha256:c987c0017b86a5aed02d5fa854b4649039e7221e14fca2e824dc37b2937ce7b2 - aarch64:
sha256:ab1d1b8e7b22fb2a6b3923e6e8fe77b8f0f774c762836a07542b7ed5ad52d86d - ppc64le:
sha256:ea726e65a0f5f8ae5b5fe4ce31f2aa75943c893c91bd75feb644c4042c88865d - s390x:
sha256:e38f225c850f6fdbdaf6ac3ef1f762b1e7068da19ef3cd57a00f72554e3d0a72
Those digests matter in disconnected or staged environments where a release image is mirrored and promoted separately from the public channel metadata.
What operators should do
Check the web console or oc for 4.22.12 in the cluster's configured update channel, then follow the standard OpenShift 4.22 update procedure. Because the fixes span both release images and RPM packages, the operative action is a cluster update rather than replacing one workload image.
Red Hat's 4.22 release notes describe 4.22 as a Kubernetes 1.35-based release with CRI-O. The 4.22.12 advisory says those release notes will be updated with the full bug-fix and enhancement detail; the security action does not depend on waiting for that expansion.
sources
- RHSA-2026:60440 — OpenShift Container Platform 4.22.12 security updateaccess.redhat.com
- OpenShift Container Platform 4.22 release notesdocs.redhat.com
- Updating an OpenShift cluster using the CLIdocs.redhat.com
comments · 0