live wire
SECURITY · Red Hat Advanced Cluster Security 4.10 moves to maintenance support Sept. 4Red Hat Customer PortalSECURITY · OpenShift 4.22.12 patches nine CVEs in an Important-rated updateRed Hat ErrataSECURITY · Red Hat maps automated vulnerability response from triage to governed remediationRed Hat BlogJAVA · Quarkus 3.39 adds post-quantum TLS controls ahead of 3.40 LTS (Aug. 27)QuarkusAI · RHEL AI publishes Muse Glimmer 30B modelcar images for x86, Arm, Power and IBM ZRed Hat ErrataAI · RamaLama 0.24 adds Pi coding-agent sandboxing and custom Hugging Face endpointsRamaLamaDATA · Kafka 4.4.0 awaits another release candidate as new KIPs target diagnostics and invalid ISR settingsRed Hat DeveloperAI · IBM puts four Granite time-series models inside Confluent Cloud’s Flink SQL early accessIBMAI · Red Hat separates skill routing from answer generation in Ask Red HatRed Hat BlogAI · OpenShift AI turns enterprise policy documents into automated red-team attacksRed Hat BlogSUPPLY CHAIN · Tekton Pipelines 1.16 enables restricted security contexts by defaultTektonAI · Apache Camel 4.23 adds OpenTelemetry spans and per-model token metrics for LLM routesApache CamelAI · IBM Spyre 12-card Power drawers require Red Hat AI Inference Server 3.5 (Aug. 25)IBM DocumentationAI · Red Hat turns Ray and Docling RAG into a five-component OpenShift AI pipelineRed Hat DeveloperSECURITY · Red Hat Advanced Cluster Security 4.10 moves to maintenance support Sept. 4Red Hat Customer PortalSECURITY · OpenShift 4.22.12 patches nine CVEs in an Important-rated updateRed Hat ErrataSECURITY · Red Hat maps automated vulnerability response from triage to governed remediationRed Hat BlogJAVA · Quarkus 3.39 adds post-quantum TLS controls ahead of 3.40 LTS (Aug. 27)QuarkusAI · RHEL AI publishes Muse Glimmer 30B modelcar images for x86, Arm, Power and IBM ZRed Hat ErrataAI · RamaLama 0.24 adds Pi coding-agent sandboxing and custom Hugging Face endpointsRamaLamaDATA · Kafka 4.4.0 awaits another release candidate as new KIPs target diagnostics and invalid ISR settingsRed Hat DeveloperAI · IBM puts four Granite time-series models inside Confluent Cloud’s Flink SQL early accessIBMAI · Red Hat separates skill routing from answer generation in Ask Red HatRed Hat BlogAI · OpenShift AI turns enterprise policy documents into automated red-team attacksRed Hat BlogSUPPLY CHAIN · Tekton Pipelines 1.16 enables restricted security contexts by defaultTektonAI · Apache Camel 4.23 adds OpenTelemetry spans and per-model token metrics for LLM routesApache CamelAI · IBM Spyre 12-card Power drawers require Red Hat AI Inference Server 3.5 (Aug. 25)IBM DocumentationAI · Red Hat turns Ray and Docling RAG into a five-component OpenShift AI pipelineRed Hat Developer
upstreambeat.ai
releaseSECURITY

OpenShift 4.22.12 fixes nine flaws across DNS, boot and local-console components

The Important-rated asynchronous update spans curl, BIND, Unbound, dracut, the SMB client and openvt; 4.22 operators should move when the release reaches their channel.

Nine vulnerabilities fixed across OpenShift 4.22.12 components.
AI-generated illustration
By The News Desk· Sep 2, 2026the quick take — two AI hosts, this story only

OpenShift Container Platform 4.22.12 is an Important-rated security update that closes nine CVEs across cluster images and underlying operating-system components. Red Hat issued the asynchronous release on Sept. 1 and advises every 4.22 operator to upgrade when it appears in the appropriate release channel.

What is fixed

The security advisory groups the fixes into six component families. Two curl flaws concern TLS-configuration mismatch and SSH host-key bypass. BIND receives fixes for a wildcard CNAME response-policy-zone bypass and incorrect acceptance of NSEC3 records, while Unbound receives fixes for potential cache poisoning and denial of service through a malformed EDNS Report-Channel option.

The remaining issues sit closer to the node. A dracut flaw could turn an unescaped error message into root code execution through a sourced emergency hook script. The kernel SMB client now validates the PathConsumed value in DFS referrals. The openvt utility receives a local-privilege-escalation fix for incorrect process-owner verification that could allow a passwordless root login.

The advisory covers OpenShift 4.22 on RHEL 8 and RHEL 9 across x86_64, 64-bit Arm, IBM Power and IBM Z/LinuxONE. It contains the updated container images; Red Hat links the accompanying RPM changes separately as RHBA-2026:60439.

Fixed release images

Red Hat identifies architecture-specific 4.22.12 release-image digests so operators can verify the payload they are promoting:

  • x86_64: sha256:c987c0017b86a5aed02d5fa854b4649039e7221e14fca2e824dc37b2937ce7b2
  • aarch64: sha256:ab1d1b8e7b22fb2a6b3923e6e8fe77b8f0f774c762836a07542b7ed5ad52d86d
  • ppc64le: sha256:ea726e65a0f5f8ae5b5fe4ce31f2aa75943c893c91bd75feb644c4042c88865d
  • s390x: sha256:e38f225c850f6fdbdaf6ac3ef1f762b1e7068da19ef3cd57a00f72554e3d0a72

Those digests matter in disconnected or staged environments where a release image is mirrored and promoted separately from the public channel metadata.

What operators should do

Check the web console or oc for 4.22.12 in the cluster's configured update channel, then follow the standard OpenShift 4.22 update procedure. Because the fixes span both release images and RPM packages, the operative action is a cluster update rather than replacing one workload image.

Red Hat's 4.22 release notes describe 4.22 as a Kubernetes 1.35-based release with CRI-O. The 4.22.12 advisory says those release notes will be updated with the full bug-fix and enhancement detail; the security action does not depend on waiting for that expansion.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.