---
name: openshift-openshift_versions_changelog_421
title: 4.21 version change log
description: View information of version changes for major, minor, and patch updates that are available for your Red Hat&reg; OpenShift&reg; on IBM Cloud&reg; clusters that run this version. Changes include updates to Red Hat OpenShift, Kubernetes, and IBM Cloud Provider components.
last-updated: 2026-08-28
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/openshift?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# 4.21 version change log
{: #openshift_changelog_421}

View information of version changes for major, minor, and patch updates that are available for your Red Hat&reg; OpenShift&reg; on IBM Cloud&reg; clusters that run this version. Changes include updates to Red Hat OpenShift, Kubernetes, and IBM Cloud Provider components.
{: shortdesc}

## Overview
{: #changelog_overview_421}


Unless otherwise noted in the change logs, the IBM Cloud provider version enables Red Hat OpenShift APIs and features that are at beta. Red Hat OpenShift alpha features are disabled and subject to change.
{: shortdesc}

Check the [Security Bulletins on IBM Cloud Status](https://cloud.ibm.com/status?selected=security){: external} for security vulnerabilities that affect Red Hat OpenShift on IBM Cloud. You can filter the results to view only **Kubernetes Service** security bulletins that are relevant to Red Hat OpenShift on IBM Cloud. Change log entries that address other security vulnerabilities but don't include an IBM security bulletin are for vulnerabilities that are not known to affect Red Hat OpenShift on IBM Cloud in normal usage. If you run privileged containers, run commands on the workers, or execute untrusted code, then you might be at risk.

Master patch updates are applied automatically. Worker node patch updates can be applied by reloading or updating the worker nodes. For more information about major, minor, and patch versions and preparation actions between minor versions, see [Red Hat OpenShift versions](https://cloud.ibm.com/docs/openshift?topic=openshift-openshift_versions&format=markdown).
{: tip}

## Version 4.21
{: #421_components}


## Worker node fix pack 4.21.29_1529_openshift, released 25 August 2026
{: #cl-boms-42129_1529_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.29_1529_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-687.39.1.el9_8
:   Resolves the following CVEs: [RHSA-2026:54510](https://access.redhat.com/errata/RHSA-2026:54510){: external}, [CVE-2026-10723](https://nvd.nist.gov/vuln/detail/cve-2026-10723){: external}, [CVE-2026-11331](https://nvd.nist.gov/vuln/detail/cve-2026-11331){: external}, [CVE-2026-11622](https://nvd.nist.gov/vuln/detail/cve-2026-11622){: external}, [CVE-2026-11721](https://nvd.nist.gov/vuln/detail/cve-2026-11721){: external}, [CVE-2026-13204](https://nvd.nist.gov/vuln/detail/cve-2026-13204){: external}, [CVE-2026-13321](https://nvd.nist.gov/vuln/detail/cve-2026-13321){: external}, [RHSA-2026:55439](https://access.redhat.com/errata/RHSA-2026:55439){: external}, [CVE-2026-1965](https://nvd.nist.gov/vuln/detail/cve-2026-1965){: external}, [CVE-2026-3783](https://nvd.nist.gov/vuln/detail/cve-2026-3783){: external}, [CVE-2026-8286](https://nvd.nist.gov/vuln/detail/cve-2026-8286){: external}, [CVE-2026-9547](https://nvd.nist.gov/vuln/detail/cve-2026-9547){: external}, [RHSA-2026:54571](https://access.redhat.com/errata/RHSA-2026:54571){: external}, [CVE-2026-15816](https://nvd.nist.gov/vuln/detail/cve-2026-15816){: external}, [RHSA-2026:55772](https://access.redhat.com/errata/RHSA-2026:55772){: external}, [CVE-2026-55203](https://nvd.nist.gov/vuln/detail/cve-2026-55203){: external}, [CVE-2026-55204](https://nvd.nist.gov/vuln/detail/cve-2026-55204){: external}, [RHSA-2026:53844](https://access.redhat.com/errata/RHSA-2026:53844){: external}, [CVE-2026-44943](https://nvd.nist.gov/vuln/detail/cve-2026-44943){: external}, [CVE-2026-44944](https://nvd.nist.gov/vuln/detail/cve-2026-44944){: external}, [RHSA-2026:53847](https://access.redhat.com/errata/RHSA-2026:53847){: external}, [CVE-2026-55995](https://nvd.nist.gov/vuln/detail/cve-2026-55995){: external}, [RHSA-2026:53329](https://access.redhat.com/errata/RHSA-2026:53329){: external}, [CVE-2025-54518](https://nvd.nist.gov/vuln/detail/cve-2025-54518){: external}, [CVE-2026-31530](https://nvd.nist.gov/vuln/detail/cve-2026-31530){: external}, [CVE-2026-64368](https://nvd.nist.gov/vuln/detail/cve-2026-64368){: external}, [CVE-2026-64531](https://nvd.nist.gov/vuln/detail/cve-2026-64531){: external}, [RHSA-2026:54443](https://access.redhat.com/errata/RHSA-2026:54443){: external}, [CVE-2026-53202](https://nvd.nist.gov/vuln/detail/cve-2026-53202){: external}, [CVE-2026-53264](https://nvd.nist.gov/vuln/detail/cve-2026-53264){: external}, [RHSA-2026:54268](https://access.redhat.com/errata/RHSA-2026:54268){: external}, [CVE-2026-11940](https://nvd.nist.gov/vuln/detail/cve-2026-11940){: external}, [RHSA-2026:55440](https://access.redhat.com/errata/RHSA-2026:55440){: external}, [CVE-2026-15588](https://nvd.nist.gov/vuln/detail/cve-2026-15588){: external}, [CVE-2026-58010](https://nvd.nist.gov/vuln/detail/cve-2026-58010){: external}, [CVE-2026-58011](https://nvd.nist.gov/vuln/detail/cve-2026-58011){: external}, [CVE-2026-58012](https://nvd.nist.gov/vuln/detail/cve-2026-58012){: external}, [CVE-2026-58013](https://nvd.nist.gov/vuln/detail/cve-2026-58013){: external}, [CVE-2026-58014](https://nvd.nist.gov/vuln/detail/cve-2026-58014){: external}, [CVE-2026-58015](https://nvd.nist.gov/vuln/detail/cve-2026-58015){: external}, [RHSA-2026:57610](https://access.redhat.com/errata/RHSA-2026:57610){: external}, [CVE-2026-72693](https://nvd.nist.gov/vuln/detail/cve-2026-72693){: external}, [RHSA-2026:51035](https://access.redhat.com/errata/RHSA-2026:51035){: external}, [CVE-2026-23415](https://nvd.nist.gov/vuln/detail/cve-2026-23415){: external}, [CVE-2026-43450](https://nvd.nist.gov/vuln/detail/cve-2026-43450){: external}, [RHSA-2026:52674](https://access.redhat.com/errata/RHSA-2026:52674){: external}, [CVE-2026-14164](https://nvd.nist.gov/vuln/detail/cve-2026-14164){: external}, [RHSA-2026:54662](https://access.redhat.com/errata/RHSA-2026:54662){: external}, [CVE-2026-58055](https://nvd.nist.gov/vuln/detail/cve-2026-58055){: external}, [RHSA-2026:54484](https://access.redhat.com/errata/RHSA-2026:54484){: external}, and [CVE-2026-45409](https://nvd.nist.gov/vuln/detail/cve-2026-45409){: external}.


RHEL 9 (Satellite) 5.14.0-687.39.1.el9_8
:   


RHEL 9 (Classic) 5.14.0-687.39.1.el9_8
:   Resolves the following CVEs: [RHSA-2026:54510](https://access.redhat.com/errata/RHSA-2026:54510){: external}, [CVE-2026-10723](https://nvd.nist.gov/vuln/detail/cve-2026-10723){: external}, [CVE-2026-11331](https://nvd.nist.gov/vuln/detail/cve-2026-11331){: external}, [CVE-2026-11622](https://nvd.nist.gov/vuln/detail/cve-2026-11622){: external}, [CVE-2026-11721](https://nvd.nist.gov/vuln/detail/cve-2026-11721){: external}, [CVE-2026-13204](https://nvd.nist.gov/vuln/detail/cve-2026-13204){: external}, [CVE-2026-13321](https://nvd.nist.gov/vuln/detail/cve-2026-13321){: external}, [RHSA-2026:55439](https://access.redhat.com/errata/RHSA-2026:55439){: external}, [CVE-2026-1965](https://nvd.nist.gov/vuln/detail/cve-2026-1965){: external}, [CVE-2026-3783](https://nvd.nist.gov/vuln/detail/cve-2026-3783){: external}, [CVE-2026-8286](https://nvd.nist.gov/vuln/detail/cve-2026-8286){: external}, [CVE-2026-9547](https://nvd.nist.gov/vuln/detail/cve-2026-9547){: external}, [RHSA-2026:54571](https://access.redhat.com/errata/RHSA-2026:54571){: external}, [CVE-2026-15816](https://nvd.nist.gov/vuln/detail/cve-2026-15816){: external}, [RHSA-2026:55772](https://access.redhat.com/errata/RHSA-2026:55772){: external}, [CVE-2026-55203](https://nvd.nist.gov/vuln/detail/cve-2026-55203){: external}, [CVE-2026-55204](https://nvd.nist.gov/vuln/detail/cve-2026-55204){: external}, [RHSA-2026:53844](https://access.redhat.com/errata/RHSA-2026:53844){: external}, [CVE-2026-44943](https://nvd.nist.gov/vuln/detail/cve-2026-44943){: external}, [CVE-2026-44944](https://nvd.nist.gov/vuln/detail/cve-2026-44944){: external}, [RHSA-2026:53847](https://access.redhat.com/errata/RHSA-2026:53847){: external}, [CVE-2026-55995](https://nvd.nist.gov/vuln/detail/cve-2026-55995){: external}, [RHSA-2026:53329](https://access.redhat.com/errata/RHSA-2026:53329){: external}, [CVE-2025-54518](https://nvd.nist.gov/vuln/detail/cve-2025-54518){: external}, [CVE-2026-31530](https://nvd.nist.gov/vuln/detail/cve-2026-31530){: external}, [CVE-2026-64368](https://nvd.nist.gov/vuln/detail/cve-2026-64368){: external}, [CVE-2026-64531](https://nvd.nist.gov/vuln/detail/cve-2026-64531){: external}, [RHSA-2026:54443](https://access.redhat.com/errata/RHSA-2026:54443){: external}, [CVE-2026-53202](https://nvd.nist.gov/vuln/detail/cve-2026-53202){: external}, [CVE-2026-53264](https://nvd.nist.gov/vuln/detail/cve-2026-53264){: external}, [RHSA-2026:54268](https://access.redhat.com/errata/RHSA-2026:54268){: external}, [CVE-2026-11940](https://nvd.nist.gov/vuln/detail/cve-2026-11940){: external}, [RHSA-2026:55440](https://access.redhat.com/errata/RHSA-2026:55440){: external}, [CVE-2026-15588](https://nvd.nist.gov/vuln/detail/cve-2026-15588){: external}, [CVE-2026-58010](https://nvd.nist.gov/vuln/detail/cve-2026-58010){: external}, [CVE-2026-58011](https://nvd.nist.gov/vuln/detail/cve-2026-58011){: external}, [CVE-2026-58012](https://nvd.nist.gov/vuln/detail/cve-2026-58012){: external}, [CVE-2026-58013](https://nvd.nist.gov/vuln/detail/cve-2026-58013){: external}, [CVE-2026-58014](https://nvd.nist.gov/vuln/detail/cve-2026-58014){: external}, [CVE-2026-58015](https://nvd.nist.gov/vuln/detail/cve-2026-58015){: external}, [RHSA-2026:57610](https://access.redhat.com/errata/RHSA-2026:57610){: external}, [CVE-2026-72693](https://nvd.nist.gov/vuln/detail/cve-2026-72693){: external}, [RHSA-2026:51035](https://access.redhat.com/errata/RHSA-2026:51035){: external}, [CVE-2026-23415](https://nvd.nist.gov/vuln/detail/cve-2026-23415){: external}, [CVE-2026-43450](https://nvd.nist.gov/vuln/detail/cve-2026-43450){: external}, [RHSA-2026:52674](https://access.redhat.com/errata/RHSA-2026:52674){: external}, [CVE-2026-14164](https://nvd.nist.gov/vuln/detail/cve-2026-14164){: external}, [RHSA-2026:54662](https://access.redhat.com/errata/RHSA-2026:54662){: external}, [CVE-2026-58055](https://nvd.nist.gov/vuln/detail/cve-2026-58055){: external}, [RHSA-2026:54484](https://access.redhat.com/errata/RHSA-2026:54484){: external}, and [CVE-2026-45409](https://nvd.nist.gov/vuln/detail/cve-2026-45409){: external}.


Red Hat OpenShift 4.21.29
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-29_release-notes){: external}.


Red Hat CoreOS 4.21.29
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-29_release-notes){: external}.


HAProxy a70e8a8452c4d476687ad749df47b6f27a61851a
:   Resolves the following CVEs: [CVE-2026-54411](https://nvd.nist.gov/vuln/detail/cve-2026-54411){: external}, [CVE-2026-54371](https://nvd.nist.gov/vuln/detail/cve-2026-54371){: external}, [CVE-2026-55204](https://nvd.nist.gov/vuln/detail/cve-2026-55204){: external}, and [CVE-2026-58055](https://nvd.nist.gov/vuln/detail/cve-2026-58055){: external}.


## Worker node fix pack 4.21.27_1528_openshift, released 12 August 2026
{: #cl-boms-42127_1528_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.27_1528_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-687.34.1.el9_8
:   Resolves the following CVEs: [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/cve-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/cve-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/cve-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/cve-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/cve-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/cve-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/cve-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/cve-2026-46209){: external}, [RHSA-2026:49031](https://access.redhat.com/errata/RHSA-2026:49031){: external}, [CVE-2025-10263](https://nvd.nist.gov/vuln/detail/cve-2025-10263){: external}, [CVE-2025-40026](https://nvd.nist.gov/vuln/detail/cve-2025-40026){: external}, [CVE-2026-52923](https://nvd.nist.gov/vuln/detail/cve-2026-52923){: external}, [RHSA-2026:49839](https://access.redhat.com/errata/RHSA-2026:49839){: external}, [CVE-2026-14474](https://nvd.nist.gov/vuln/detail/cve-2026-14474){: external}, [CVE-2026-14476](https://nvd.nist.gov/vuln/detail/cve-2026-14476){: external}, [RHSA-2026:48811](https://access.redhat.com/errata/RHSA-2026:48811){: external}, [CVE-2026-48864](https://nvd.nist.gov/vuln/detail/cve-2026-48864){: external}, [RHSA-2026:49910](https://access.redhat.com/errata/RHSA-2026:49910){: external}, and [CVE-2026-29111](https://nvd.nist.gov/vuln/detail/cve-2026-29111){: external}.


RHEL 9 (Satellite) 5.14.0-687.34.1.el9_8
:   


RHEL 9 (Classic) 5.14.0-687.34.1.el9_8
:   Resolves the following CVEs: [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/cve-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/cve-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/cve-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/cve-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/cve-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/cve-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/cve-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/cve-2026-46209){: external}, [RHSA-2026:49031](https://access.redhat.com/errata/RHSA-2026:49031){: external}, [CVE-2025-10263](https://nvd.nist.gov/vuln/detail/cve-2025-10263){: external}, [CVE-2025-40026](https://nvd.nist.gov/vuln/detail/cve-2025-40026){: external}, [CVE-2026-52923](https://nvd.nist.gov/vuln/detail/cve-2026-52923){: external}, [RHSA-2026:49839](https://access.redhat.com/errata/RHSA-2026:49839){: external}, [CVE-2026-14474](https://nvd.nist.gov/vuln/detail/cve-2026-14474){: external}, [CVE-2026-14476](https://nvd.nist.gov/vuln/detail/cve-2026-14476){: external}, [RHSA-2026:48811](https://access.redhat.com/errata/RHSA-2026:48811){: external}, [CVE-2026-48864](https://nvd.nist.gov/vuln/detail/cve-2026-48864){: external}, [RHSA-2026:49910](https://access.redhat.com/errata/RHSA-2026:49910){: external}, and [CVE-2026-29111](https://nvd.nist.gov/vuln/detail/cve-2026-29111){: external}.


Red Hat OpenShift 4.21.27
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-27_release-notes){: external}.


Red Hat CoreOS 4.21.27
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-27_release-notes){: external}.


HAProxy bd7e64ef86b90455535107263466d1825f3e7f9f
:   Resolves the following CVEs: [CVE-2026-56391](https://nvd.nist.gov/vuln/detail/cve-2026-56391){: external}, and [CVE-2026-56392](https://nvd.nist.gov/vuln/detail/cve-2026-56392){: external}.


## Master fix pack 4.21.27_1527_openshift, released 05 August 2026
{: #cl-boms_master-42127_1527_openshift_M}

The following list shows the components that are in the master fix pack 4.21.27_1527_openshift. Master patch updates are applied automatically.
{: shortdesc}

etcd v3.5.32
:   See the [etcd release notes](https://github.com/etcd-io/etcd/releases/v3.5.32){: external}.


IBM Cloud Block Storage driver and plug-in v2.5.27
:   New version contains updates and security fixes.


IBM Cloud Controller Manager v1.34.9-6
:   New version contains updates and security fixes.


IBM Cloud File Storage for Classic plug-in and monitor v456
:   New version contains updates and security fixes.


Key Management Service provider 2.10.28
:   New version contains updates and security fixes.


Red Hat OpenShift on IBM Cloud 4.21.27
:   See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-27_release-notes){: external}.Resolves the following CVEs: [CVE-2026-16242](https://nvd.nist.gov/vuln/detail/cve-2026-16242){: external}.


## Worker node fix pack 4.21.25_1526_openshift, released 28 July 2026
{: #cl-boms-42125_1526_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.25_1526_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-570.128.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:38902](https://access.redhat.com/errata/RHSA-2026:38902){: external}, [CVE-2025-68183](https://nvd.nist.gov/vuln/detail/cve-2025-68183){: external}, [CVE-2026-31408](https://nvd.nist.gov/vuln/detail/cve-2026-31408){: external}, [CVE-2026-43074](https://nvd.nist.gov/vuln/detail/cve-2026-43074){: external}, [CVE-2026-43279](https://nvd.nist.gov/vuln/detail/cve-2026-43279){: external}, [CVE-2026-45984](https://nvd.nist.gov/vuln/detail/cve-2026-45984){: external}, [CVE-2026-46135](https://nvd.nist.gov/vuln/detail/cve-2026-46135){: external}, [CVE-2026-46152](https://nvd.nist.gov/vuln/detail/cve-2026-46152){: external}, [CVE-2026-46189](https://nvd.nist.gov/vuln/detail/cve-2026-46189){: external}, [CVE-2026-46242](https://nvd.nist.gov/vuln/detail/cve-2026-46242){: external}, [CVE-2026-46316](https://nvd.nist.gov/vuln/detail/cve-2026-46316){: external}, [CVE-2026-53359](https://nvd.nist.gov/vuln/detail/cve-2026-53359){: external}, [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/cve-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/cve-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/cve-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/cve-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/cve-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/cve-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/cve-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/cve-2026-46209){: external}, [RHSA-2026:40425](https://access.redhat.com/errata/RHSA-2026:40425){: external}, [CVE-2026-43499](https://nvd.nist.gov/vuln/detail/cve-2026-43499){: external}, [CVE-2026-53166](https://nvd.nist.gov/vuln/detail/cve-2026-53166){: external}, and [CVE-2026-64600](https://nvd.nist.gov/vuln/detail/cve-2026-64600){: external}.


RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6
:   


RHEL 9 (Classic) 5.14.0-570.128.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:38902](https://access.redhat.com/errata/RHSA-2026:38902){: external}, [CVE-2025-68183](https://nvd.nist.gov/vuln/detail/cve-2025-68183){: external}, [CVE-2026-31408](https://nvd.nist.gov/vuln/detail/cve-2026-31408){: external}, [CVE-2026-43074](https://nvd.nist.gov/vuln/detail/cve-2026-43074){: external}, [CVE-2026-43279](https://nvd.nist.gov/vuln/detail/cve-2026-43279){: external}, [CVE-2026-45984](https://nvd.nist.gov/vuln/detail/cve-2026-45984){: external}, [CVE-2026-46135](https://nvd.nist.gov/vuln/detail/cve-2026-46135){: external}, [CVE-2026-46152](https://nvd.nist.gov/vuln/detail/cve-2026-46152){: external}, [CVE-2026-46189](https://nvd.nist.gov/vuln/detail/cve-2026-46189){: external}, [CVE-2026-46242](https://nvd.nist.gov/vuln/detail/cve-2026-46242){: external}, [CVE-2026-46316](https://nvd.nist.gov/vuln/detail/cve-2026-46316){: external}, [CVE-2026-53359](https://nvd.nist.gov/vuln/detail/cve-2026-53359){: external}, [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/cve-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/cve-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/cve-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/cve-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/cve-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/cve-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/cve-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/cve-2026-46209){: external}, [RHSA-2026:40425](https://access.redhat.com/errata/RHSA-2026:40425){: external}, [CVE-2026-43499](https://nvd.nist.gov/vuln/detail/cve-2026-43499){: external}, [CVE-2026-53166](https://nvd.nist.gov/vuln/detail/cve-2026-53166){: external}, and [CVE-2026-64600](https://nvd.nist.gov/vuln/detail/cve-2026-64600){: external}.


Red Hat OpenShift 4.21.25
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-25_release-notes){: external}.


Red Hat CoreOS 4.21.25
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-25_release-notes){: external}.


HAProxy 346c7130717ef7cc25d1dfbca7d57ca32396b692
:   Resolves the following CVEs: [CVE-2026-6238](https://nvd.nist.gov/vuln/detail/cve-2026-6238){: external}, [CVE-2026-5928](https://nvd.nist.gov/vuln/detail/cve-2026-5928){: external}, [CVE-2026-48864](https://nvd.nist.gov/vuln/detail/cve-2026-48864){: external}, [CVE-2026-54370](https://nvd.nist.gov/vuln/detail/cve-2026-54370){: external}, [CVE-2026-28390](https://nvd.nist.gov/vuln/detail/cve-2026-28390){: external}, [CVE-2026-5435](https://nvd.nist.gov/vuln/detail/cve-2026-5435){: external}, [CVE-2025-13151](https://nvd.nist.gov/vuln/detail/cve-2025-13151){: external}, [CVE-2026-54369](https://nvd.nist.gov/vuln/detail/cve-2026-54369){: external}, [CVE-2026-58016](https://nvd.nist.gov/vuln/detail/cve-2026-58016){: external}, and [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/cve-2025-6170){: external}.


## Master fix pack 4.21.19_1525_openshift, released 28 July 2026
{: #cl-boms_master-42119_1525_openshift_M}

The following list shows the components that are in the master fix pack 4.21.19_1525_openshift. Master patch updates are applied automatically.
{: shortdesc}

Cluster health image v1.6.17
:   New version contains updates and security fixes.


etcd v3.5.30
:   See the [etcd release notes](https://github.com/etcd-io/etcd/releases/v3.5.30){: external}.


IBM Cloud Block Storage driver and plug-in v2.5.26
:   New version contains updates and security fixes.


IBM Cloud Controller Manager v1.34.9-4
:   New version contains updates and security fixes.


IBM Cloud File Storage for Classic plug-in and monitor v455
:   New version contains updates and security fixes.


IBM Cloud RBAC Operator 92ba7dd
:   New version contains updates and security fixes.


Key Management Service provider 2.10.27
:   New version contains updates and security fixes.


Portieris admission controller v0.14.2
:   See the [Portieris admission controller release notes](https://github.com/IBM/portieris/releases/tag/v0.14.2){: external}


Red Hat OpenShift on IBM Cloud 4.21.19
:   See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-19_release-notes){: external}.


## Worker node fix pack 4.21.22_1524_openshift, released 13 July 2026
{: #cl-boms-42122_1524_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.22_1524_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-570.125.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:30004](https://access.redhat.com/errata/RHSA-2026:30004){: external}, [CVE-2026-33845](https://nvd.nist.gov/vuln/detail/cve-2026-33845){: external}, [CVE-2026-33846](https://nvd.nist.gov/vuln/detail/cve-2026-33846){: external}, [CVE-2026-3833](https://nvd.nist.gov/vuln/detail/cve-2026-3833){: external}, [CVE-2026-42009](https://nvd.nist.gov/vuln/detail/cve-2026-42009){: external}, [CVE-2026-42010](https://nvd.nist.gov/vuln/detail/cve-2026-42010){: external}, [CVE-2026-42011](https://nvd.nist.gov/vuln/detail/cve-2026-42011){: external}, [CVE-2026-42012](https://nvd.nist.gov/vuln/detail/cve-2026-42012){: external}, [CVE-2026-42013](https://nvd.nist.gov/vuln/detail/cve-2026-42013){: external}, [CVE-2026-42014](https://nvd.nist.gov/vuln/detail/cve-2026-42014){: external}, [CVE-2026-42015](https://nvd.nist.gov/vuln/detail/cve-2026-42015){: external}, [CVE-2026-5260](https://nvd.nist.gov/vuln/detail/cve-2026-5260){: external}, [CVE-2026-5419](https://nvd.nist.gov/vuln/detail/cve-2026-5419){: external}, [RHSA-2026:34094](https://access.redhat.com/errata/RHSA-2026:34094){: external}, [CVE-2025-21648](https://nvd.nist.gov/vuln/detail/cve-2025-21648){: external}, [CVE-2025-21691](https://nvd.nist.gov/vuln/detail/cve-2025-21691){: external}, [CVE-2026-23191](https://nvd.nist.gov/vuln/detail/cve-2026-23191){: external}, [CVE-2026-31669](https://nvd.nist.gov/vuln/detail/cve-2026-31669){: external}, [CVE-2026-43027](https://nvd.nist.gov/vuln/detail/cve-2026-43027){: external}, [CVE-2026-43125](https://nvd.nist.gov/vuln/detail/cve-2026-43125){: external}, [CVE-2026-43128](https://nvd.nist.gov/vuln/detail/cve-2026-43128){: external}, [CVE-2026-43198](https://nvd.nist.gov/vuln/detail/cve-2026-43198){: external}, [CVE-2026-43329](https://nvd.nist.gov/vuln/detail/cve-2026-43329){: external}, [CVE-2026-43414](https://nvd.nist.gov/vuln/detail/cve-2026-43414){: external}, [CVE-2026-43501](https://nvd.nist.gov/vuln/detail/cve-2026-43501){: external}, [CVE-2026-45852](https://nvd.nist.gov/vuln/detail/cve-2026-45852){: external}, [CVE-2026-46090](https://nvd.nist.gov/vuln/detail/cve-2026-46090){: external}, [CVE-2026-46173](https://nvd.nist.gov/vuln/detail/cve-2026-46173){: external}, [CVE-2026-46176](https://nvd.nist.gov/vuln/detail/cve-2026-46176){: external}, [CVE-2026-46181](https://nvd.nist.gov/vuln/detail/cve-2026-46181){: external}, [CVE-2026-46227](https://nvd.nist.gov/vuln/detail/cve-2026-46227){: external}, [CVE-2026-46244](https://nvd.nist.gov/vuln/detail/cve-2026-46244){: external}, [RHSA-2026:28147](https://access.redhat.com/errata/RHSA-2026:28147){: external}, [CVE-2026-28847](https://nvd.nist.gov/vuln/detail/cve-2026-28847){: external}, [CVE-2026-28883](https://nvd.nist.gov/vuln/detail/cve-2026-28883){: external}, [CVE-2026-28901](https://nvd.nist.gov/vuln/detail/cve-2026-28901){: external}, [CVE-2026-28902](https://nvd.nist.gov/vuln/detail/cve-2026-28902){: external}, [CVE-2026-28903](https://nvd.nist.gov/vuln/detail/cve-2026-28903){: external}, [CVE-2026-28904](https://nvd.nist.gov/vuln/detail/cve-2026-28904){: external}, [CVE-2026-28905](https://nvd.nist.gov/vuln/detail/cve-2026-28905){: external}, [CVE-2026-28907](https://nvd.nist.gov/vuln/detail/cve-2026-28907){: external}, [CVE-2026-28942](https://nvd.nist.gov/vuln/detail/cve-2026-28942){: external}, [CVE-2026-28946](https://nvd.nist.gov/vuln/detail/cve-2026-28946){: external}, [CVE-2026-28947](https://nvd.nist.gov/vuln/detail/cve-2026-28947){: external}, [CVE-2026-28953](https://nvd.nist.gov/vuln/detail/cve-2026-28953){: external}, [CVE-2026-28955](https://nvd.nist.gov/vuln/detail/cve-2026-28955){: external}, [CVE-2026-28958](https://nvd.nist.gov/vuln/detail/cve-2026-28958){: external}, [CVE-2026-43658](https://nvd.nist.gov/vuln/detail/cve-2026-43658){: external}, [CVE-2026-43660](https://nvd.nist.gov/vuln/detail/cve-2026-43660){: external}, [RHSA-2026:33634](https://access.redhat.com/errata/RHSA-2026:33634){: external}, [CVE-2024-34459](https://nvd.nist.gov/vuln/detail/cve-2024-34459){: external}, [RHSA-2026:33230](https://access.redhat.com/errata/RHSA-2026:33230){: external}, [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/cve-2026-5450){: external}, [RHSA-2026:28832](https://access.redhat.com/errata/RHSA-2026:28832){: external}, and [CVE-2026-31790](https://nvd.nist.gov/vuln/detail/cve-2026-31790){: external}.


RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6
:   


RHEL 9 (Classic) 5.14.0-570.125.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:30004](https://access.redhat.com/errata/RHSA-2026:30004){: external}, [CVE-2026-33845](https://nvd.nist.gov/vuln/detail/cve-2026-33845){: external}, [CVE-2026-33846](https://nvd.nist.gov/vuln/detail/cve-2026-33846){: external}, [CVE-2026-3833](https://nvd.nist.gov/vuln/detail/cve-2026-3833){: external}, [CVE-2026-42009](https://nvd.nist.gov/vuln/detail/cve-2026-42009){: external}, [CVE-2026-42010](https://nvd.nist.gov/vuln/detail/cve-2026-42010){: external}, [CVE-2026-42011](https://nvd.nist.gov/vuln/detail/cve-2026-42011){: external}, [CVE-2026-42012](https://nvd.nist.gov/vuln/detail/cve-2026-42012){: external}, [CVE-2026-42013](https://nvd.nist.gov/vuln/detail/cve-2026-42013){: external}, [CVE-2026-42014](https://nvd.nist.gov/vuln/detail/cve-2026-42014){: external}, [CVE-2026-42015](https://nvd.nist.gov/vuln/detail/cve-2026-42015){: external}, [CVE-2026-5260](https://nvd.nist.gov/vuln/detail/cve-2026-5260){: external}, [CVE-2026-5419](https://nvd.nist.gov/vuln/detail/cve-2026-5419){: external}, [RHSA-2026:34094](https://access.redhat.com/errata/RHSA-2026:34094){: external}, [CVE-2025-21648](https://nvd.nist.gov/vuln/detail/cve-2025-21648){: external}, [CVE-2025-21691](https://nvd.nist.gov/vuln/detail/cve-2025-21691){: external}, [CVE-2026-23191](https://nvd.nist.gov/vuln/detail/cve-2026-23191){: external}, [CVE-2026-31669](https://nvd.nist.gov/vuln/detail/cve-2026-31669){: external}, [CVE-2026-43027](https://nvd.nist.gov/vuln/detail/cve-2026-43027){: external}, [CVE-2026-43125](https://nvd.nist.gov/vuln/detail/cve-2026-43125){: external}, [CVE-2026-43128](https://nvd.nist.gov/vuln/detail/cve-2026-43128){: external}, [CVE-2026-43198](https://nvd.nist.gov/vuln/detail/cve-2026-43198){: external}, [CVE-2026-43329](https://nvd.nist.gov/vuln/detail/cve-2026-43329){: external}, [CVE-2026-43414](https://nvd.nist.gov/vuln/detail/cve-2026-43414){: external}, [CVE-2026-43501](https://nvd.nist.gov/vuln/detail/cve-2026-43501){: external}, [CVE-2026-45852](https://nvd.nist.gov/vuln/detail/cve-2026-45852){: external}, [CVE-2026-46090](https://nvd.nist.gov/vuln/detail/cve-2026-46090){: external}, [CVE-2026-46173](https://nvd.nist.gov/vuln/detail/cve-2026-46173){: external}, [CVE-2026-46176](https://nvd.nist.gov/vuln/detail/cve-2026-46176){: external}, [CVE-2026-46181](https://nvd.nist.gov/vuln/detail/cve-2026-46181){: external}, [CVE-2026-46227](https://nvd.nist.gov/vuln/detail/cve-2026-46227){: external}, [CVE-2026-46244](https://nvd.nist.gov/vuln/detail/cve-2026-46244){: external}, [RHSA-2026:28147](https://access.redhat.com/errata/RHSA-2026:28147){: external}, [CVE-2026-28847](https://nvd.nist.gov/vuln/detail/cve-2026-28847){: external}, [CVE-2026-28883](https://nvd.nist.gov/vuln/detail/cve-2026-28883){: external}, [CVE-2026-28901](https://nvd.nist.gov/vuln/detail/cve-2026-28901){: external}, [CVE-2026-28902](https://nvd.nist.gov/vuln/detail/cve-2026-28902){: external}, [CVE-2026-28903](https://nvd.nist.gov/vuln/detail/cve-2026-28903){: external}, [CVE-2026-28904](https://nvd.nist.gov/vuln/detail/cve-2026-28904){: external}, [CVE-2026-28905](https://nvd.nist.gov/vuln/detail/cve-2026-28905){: external}, [CVE-2026-28907](https://nvd.nist.gov/vuln/detail/cve-2026-28907){: external}, [CVE-2026-28942](https://nvd.nist.gov/vuln/detail/cve-2026-28942){: external}, [CVE-2026-28946](https://nvd.nist.gov/vuln/detail/cve-2026-28946){: external}, [CVE-2026-28947](https://nvd.nist.gov/vuln/detail/cve-2026-28947){: external}, [CVE-2026-28953](https://nvd.nist.gov/vuln/detail/cve-2026-28953){: external}, [CVE-2026-28955](https://nvd.nist.gov/vuln/detail/cve-2026-28955){: external}, [CVE-2026-28958](https://nvd.nist.gov/vuln/detail/cve-2026-28958){: external}, [CVE-2026-43658](https://nvd.nist.gov/vuln/detail/cve-2026-43658){: external}, [CVE-2026-43660](https://nvd.nist.gov/vuln/detail/cve-2026-43660){: external}, [RHSA-2026:33634](https://access.redhat.com/errata/RHSA-2026:33634){: external}, [CVE-2024-34459](https://nvd.nist.gov/vuln/detail/cve-2024-34459){: external}, [RHSA-2026:33230](https://access.redhat.com/errata/RHSA-2026:33230){: external}, [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/cve-2026-5450){: external}, [RHSA-2026:28832](https://access.redhat.com/errata/RHSA-2026:28832){: external}, and [CVE-2026-31790](https://nvd.nist.gov/vuln/detail/cve-2026-31790){: external}.


Red Hat OpenShift 4.21.22
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-22_release-notes){: external}.


Red Hat CoreOS 4.21.22
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-22_release-notes){: external}.


HAProxy 27f76d0c7626993cde6e1ff90fa42253718cc5fa
:   Resolves the following CVEs: [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/cve-2026-5450){: external}.


## Worker node fix pack 4.21.21_1522_openshift, released 01 July 2026
{: #cl-boms-42121_1522_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.21_1522_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-570.123.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:24500](https://access.redhat.com/errata/RHSA-2026:24500){: external}, [CVE-2026-1519](https://nvd.nist.gov/vuln/detail/cve-2026-1519){: external}, [RHSA-2026:23224](https://access.redhat.com/errata/RHSA-2026:23224){: external}, [CVE-2025-38653](https://nvd.nist.gov/vuln/detail/cve-2025-38653){: external}, [CVE-2025-39766](https://nvd.nist.gov/vuln/detail/cve-2025-39766){: external}, [CVE-2025-68366](https://nvd.nist.gov/vuln/detail/cve-2025-68366){: external}, [CVE-2026-23210](https://nvd.nist.gov/vuln/detail/cve-2026-23210){: external}, [CVE-2026-23270](https://nvd.nist.gov/vuln/detail/cve-2026-23270){: external}, [CVE-2026-23392](https://nvd.nist.gov/vuln/detail/cve-2026-23392){: external}, [CVE-2026-31419](https://nvd.nist.gov/vuln/detail/cve-2026-31419){: external}, [CVE-2026-31607](https://nvd.nist.gov/vuln/detail/cve-2026-31607){: external}, [CVE-2026-31685](https://nvd.nist.gov/vuln/detail/cve-2026-31685){: external}, [CVE-2026-31709](https://nvd.nist.gov/vuln/detail/cve-2026-31709){: external}, [CVE-2026-43037](https://nvd.nist.gov/vuln/detail/cve-2026-43037){: external}, [CVE-2026-43038](https://nvd.nist.gov/vuln/detail/cve-2026-43038){: external}, [CVE-2026-43163](https://nvd.nist.gov/vuln/detail/cve-2026-43163){: external}, [RHSA-2026:25218](https://access.redhat.com/errata/RHSA-2026:25218){: external}, [CVE-2025-40135](https://nvd.nist.gov/vuln/detail/cve-2025-40135){: external}, [CVE-2025-40158](https://nvd.nist.gov/vuln/detail/cve-2025-40158){: external}, [CVE-2025-40170](https://nvd.nist.gov/vuln/detail/cve-2025-40170){: external}, [CVE-2025-68724](https://nvd.nist.gov/vuln/detail/cve-2025-68724){: external}, [CVE-2025-71089](https://nvd.nist.gov/vuln/detail/cve-2025-71089){: external}, [CVE-2025-71116](https://nvd.nist.gov/vuln/detail/cve-2025-71116){: external}, [CVE-2026-22984](https://nvd.nist.gov/vuln/detail/cve-2026-22984){: external}, [CVE-2026-22990](https://nvd.nist.gov/vuln/detail/cve-2026-22990){: external}, [CVE-2026-23216](https://nvd.nist.gov/vuln/detail/cve-2026-23216){: external}, [CVE-2026-23455](https://nvd.nist.gov/vuln/detail/cve-2026-23455){: external}, [CVE-2026-31508](https://nvd.nist.gov/vuln/detail/cve-2026-31508){: external}, [CVE-2026-43110](https://nvd.nist.gov/vuln/detail/cve-2026-43110){: external}, [CVE-2026-43190](https://nvd.nist.gov/vuln/detail/cve-2026-43190){: external}, [RHSA-2026:27708](https://access.redhat.com/errata/RHSA-2026:27708){: external}, [CVE-2025-40064](https://nvd.nist.gov/vuln/detail/cve-2025-40064){: external}, [CVE-2025-40168](https://nvd.nist.gov/vuln/detail/cve-2025-40168){: external}, [CVE-2026-23136](https://nvd.nist.gov/vuln/detail/cve-2026-23136){: external}, [CVE-2026-43116](https://nvd.nist.gov/vuln/detail/cve-2026-43116){: external}, [CVE-2026-43158](https://nvd.nist.gov/vuln/detail/cve-2026-43158){: external}, [CVE-2026-43303](https://nvd.nist.gov/vuln/detail/cve-2026-43303){: external}, [CVE-2026-45898](https://nvd.nist.gov/vuln/detail/cve-2026-45898){: external}, [CVE-2026-46125](https://nvd.nist.gov/vuln/detail/cve-2026-46125){: external}, [CVE-2026-46166](https://nvd.nist.gov/vuln/detail/cve-2026-46166){: external}, [CVE-2026-46243](https://nvd.nist.gov/vuln/detail/cve-2026-46243){: external}, [CVE-2026-46323](https://nvd.nist.gov/vuln/detail/cve-2026-46323){: external}, [CVE-2026-46331](https://nvd.nist.gov/vuln/detail/cve-2026-46331){: external}, [RHSA-2026:24683](https://access.redhat.com/errata/RHSA-2026:24683){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/cve-2026-40356){: external}, [RHSA-2026:24337](https://access.redhat.com/errata/RHSA-2026:24337){: external}, [CVE-2026-32280](https://nvd.nist.gov/vuln/detail/cve-2026-32280){: external}, [CVE-2026-32281](https://nvd.nist.gov/vuln/detail/cve-2026-32281){: external}, [CVE-2026-32282](https://nvd.nist.gov/vuln/detail/cve-2026-32282){: external}, [CVE-2026-32283](https://nvd.nist.gov/vuln/detail/cve-2026-32283){: external}, [RHSA-2026:25979](https://access.redhat.com/errata/RHSA-2026:25979){: external}, [CVE-2026-1933](https://nvd.nist.gov/vuln/detail/cve-2026-1933){: external}, [CVE-2026-2340](https://nvd.nist.gov/vuln/detail/cve-2026-2340){: external}, [CVE-2026-3012](https://nvd.nist.gov/vuln/detail/cve-2026-3012){: external}, [CVE-2026-4408](https://nvd.nist.gov/vuln/detail/cve-2026-4408){: external}, [CVE-2026-4480](https://nvd.nist.gov/vuln/detail/cve-2026-4480){: external}, [RHSA-2026:28050](https://access.redhat.com/errata/RHSA-2026:28050){: external}, [CVE-2026-34982](https://nvd.nist.gov/vuln/detail/cve-2026-34982){: external}, [CVE-2026-35177](https://nvd.nist.gov/vuln/detail/cve-2026-35177){: external}, [CVE-2026-41411](https://nvd.nist.gov/vuln/detail/cve-2026-41411){: external}, and [CVE-2026-46483](https://nvd.nist.gov/vuln/detail/cve-2026-46483){: external}.


RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6
:   


RHEL 9 (Classic) 5.14.0-570.123.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:24500](https://access.redhat.com/errata/RHSA-2026:24500){: external}, [CVE-2026-1519](https://nvd.nist.gov/vuln/detail/cve-2026-1519){: external}, [RHSA-2026:23224](https://access.redhat.com/errata/RHSA-2026:23224){: external}, [CVE-2025-38653](https://nvd.nist.gov/vuln/detail/cve-2025-38653){: external}, [CVE-2025-39766](https://nvd.nist.gov/vuln/detail/cve-2025-39766){: external}, [CVE-2025-68366](https://nvd.nist.gov/vuln/detail/cve-2025-68366){: external}, [CVE-2026-23210](https://nvd.nist.gov/vuln/detail/cve-2026-23210){: external}, [CVE-2026-23270](https://nvd.nist.gov/vuln/detail/cve-2026-23270){: external}, [CVE-2026-23392](https://nvd.nist.gov/vuln/detail/cve-2026-23392){: external}, [CVE-2026-31419](https://nvd.nist.gov/vuln/detail/cve-2026-31419){: external}, [CVE-2026-31607](https://nvd.nist.gov/vuln/detail/cve-2026-31607){: external}, [CVE-2026-31685](https://nvd.nist.gov/vuln/detail/cve-2026-31685){: external}, [CVE-2026-31709](https://nvd.nist.gov/vuln/detail/cve-2026-31709){: external}, [CVE-2026-43037](https://nvd.nist.gov/vuln/detail/cve-2026-43037){: external}, [CVE-2026-43038](https://nvd.nist.gov/vuln/detail/cve-2026-43038){: external}, [CVE-2026-43163](https://nvd.nist.gov/vuln/detail/cve-2026-43163){: external}, [RHSA-2026:25218](https://access.redhat.com/errata/RHSA-2026:25218){: external}, [CVE-2025-40135](https://nvd.nist.gov/vuln/detail/cve-2025-40135){: external}, [CVE-2025-40158](https://nvd.nist.gov/vuln/detail/cve-2025-40158){: external}, [CVE-2025-40170](https://nvd.nist.gov/vuln/detail/cve-2025-40170){: external}, [CVE-2025-68724](https://nvd.nist.gov/vuln/detail/cve-2025-68724){: external}, [CVE-2025-71089](https://nvd.nist.gov/vuln/detail/cve-2025-71089){: external}, [CVE-2025-71116](https://nvd.nist.gov/vuln/detail/cve-2025-71116){: external}, [CVE-2026-22984](https://nvd.nist.gov/vuln/detail/cve-2026-22984){: external}, [CVE-2026-22990](https://nvd.nist.gov/vuln/detail/cve-2026-22990){: external}, [CVE-2026-23216](https://nvd.nist.gov/vuln/detail/cve-2026-23216){: external}, [CVE-2026-23455](https://nvd.nist.gov/vuln/detail/cve-2026-23455){: external}, [CVE-2026-31508](https://nvd.nist.gov/vuln/detail/cve-2026-31508){: external}, [CVE-2026-43110](https://nvd.nist.gov/vuln/detail/cve-2026-43110){: external}, [CVE-2026-43190](https://nvd.nist.gov/vuln/detail/cve-2026-43190){: external}, [RHSA-2026:27708](https://access.redhat.com/errata/RHSA-2026:27708){: external}, [CVE-2025-40064](https://nvd.nist.gov/vuln/detail/cve-2025-40064){: external}, [CVE-2025-40168](https://nvd.nist.gov/vuln/detail/cve-2025-40168){: external}, [CVE-2026-23136](https://nvd.nist.gov/vuln/detail/cve-2026-23136){: external}, [CVE-2026-43116](https://nvd.nist.gov/vuln/detail/cve-2026-43116){: external}, [CVE-2026-43158](https://nvd.nist.gov/vuln/detail/cve-2026-43158){: external}, [CVE-2026-43303](https://nvd.nist.gov/vuln/detail/cve-2026-43303){: external}, [CVE-2026-45898](https://nvd.nist.gov/vuln/detail/cve-2026-45898){: external}, [CVE-2026-46125](https://nvd.nist.gov/vuln/detail/cve-2026-46125){: external}, [CVE-2026-46166](https://nvd.nist.gov/vuln/detail/cve-2026-46166){: external}, [CVE-2026-46243](https://nvd.nist.gov/vuln/detail/cve-2026-46243){: external}, [CVE-2026-46323](https://nvd.nist.gov/vuln/detail/cve-2026-46323){: external}, [CVE-2026-46331](https://nvd.nist.gov/vuln/detail/cve-2026-46331){: external}, [RHSA-2026:24683](https://access.redhat.com/errata/RHSA-2026:24683){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/cve-2026-40356){: external}, [RHSA-2026:24337](https://access.redhat.com/errata/RHSA-2026:24337){: external}, [CVE-2026-32280](https://nvd.nist.gov/vuln/detail/cve-2026-32280){: external}, [CVE-2026-32281](https://nvd.nist.gov/vuln/detail/cve-2026-32281){: external}, [CVE-2026-32282](https://nvd.nist.gov/vuln/detail/cve-2026-32282){: external}, [CVE-2026-32283](https://nvd.nist.gov/vuln/detail/cve-2026-32283){: external}, [RHSA-2026:25979](https://access.redhat.com/errata/RHSA-2026:25979){: external}, [CVE-2026-1933](https://nvd.nist.gov/vuln/detail/cve-2026-1933){: external}, [CVE-2026-2340](https://nvd.nist.gov/vuln/detail/cve-2026-2340){: external}, [CVE-2026-3012](https://nvd.nist.gov/vuln/detail/cve-2026-3012){: external}, [CVE-2026-4408](https://nvd.nist.gov/vuln/detail/cve-2026-4408){: external}, [CVE-2026-4480](https://nvd.nist.gov/vuln/detail/cve-2026-4480){: external}, [RHSA-2026:28050](https://access.redhat.com/errata/RHSA-2026:28050){: external}, [CVE-2026-34982](https://nvd.nist.gov/vuln/detail/cve-2026-34982){: external}, [CVE-2026-35177](https://nvd.nist.gov/vuln/detail/cve-2026-35177){: external}, [CVE-2026-41411](https://nvd.nist.gov/vuln/detail/cve-2026-41411){: external}, and [CVE-2026-46483](https://nvd.nist.gov/vuln/detail/cve-2026-46483){: external}.


Red Hat OpenShift 4.21.21
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-21_release-notes){: external}.


Red Hat CoreOS 4.21.21
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-21_release-notes){: external}.


HAProxy 119de539a7da3c92449b38e1531722802988e50c
:   Resolves the following CVEs: [CVE-2026-45447](https://nvd.nist.gov/vuln/detail/cve-2026-45447){: external}, [CVE-2024-4741](https://nvd.nist.gov/vuln/detail/cve-2024-4741){: external}, and [CVE-2024-34459](https://nvd.nist.gov/vuln/detail/cve-2024-34459){: external}.


## Master fix pack 4.21.18_1520_openshift, released 26 June 2026
{: #cl-boms_master-42118_1520_openshift_M}

The following list shows the components that are in the master fix pack 4.21.18_1520_openshift. Master patch updates are applied automatically.
{: shortdesc}

Cluster health image v1.6.16
:   New version contains updates and security fixes.


etcd v3.5.30
:   See the [etcd release notes](https://github.com/etcd-io/etcd/releases/v3.5.30){: external}.


IBM Cloud Block Storage driver and plug-in v2.5.26
:   New version contains updates and security fixes.


IBM Cloud Controller Manager v1.34.8-2
:   New version contains updates and security fixes.


IBM Cloud File Storage for Classic plug-in and monitor v455
:   New version contains updates and security fixes.


Key Management Service provider 2.10.25
:   New version contains updates and security fixes.


Portieris admission controller v0.14.0
:   See the [Portieris admission controller release notes](https://github.com/IBM/portieris/releases/tag/v0.14.0){: external}


Red Hat OpenShift on IBM Cloud 4.21.18
:   See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-18_release-notes){: external}.


## Worker node fix pack 4.21.19_1521_openshift, released 15 June 2026
{: #cl-boms-42119_1521_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.19_1521_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-570.116.1.el9_6
:   Resolves the following CVEs: [CVE-2026-5119](https://nvd.nist.gov/vuln/detail/cve-2026-5119){: external}.


RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6
:   


RHEL 9 (Classic) 5.14.0-570.116.1.el9_6
:   


Red Hat OpenShift 4.21.19
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes){: external}.


Red Hat CoreOS 4.21.19
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes){: external}.


HAProxy d4656f400ca14059e1b5b8ef8078b4903290791a
:   Resolves the following CVEs: [CVE-2026-45186](https://nvd.nist.gov/vuln/detail/cve-2026-45186){: external}.


## Worker node fix pack 4.21.17_1519_openshift, released 03 June 2026
{: #cl-boms-42117_1519_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.17_1519_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) 5.14.0-570.116.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:21392](https://access.redhat.com/errata/RHSA-2026:21392){: external}, [CVE-2026-4802](https://nvd.nist.gov/vuln/detail/cve-2026-4802){: external}, [RHSA-2026:18042](https://access.redhat.com/errata/RHSA-2026:18042){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/cve-2026-39979){: external}, [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/cve-2026-40164){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/cve-2026-43284){: external}, [RHSA-2026:20129](https://access.redhat.com/errata/RHSA-2026:20129){: external}, [CVE-2026-46300](https://nvd.nist.gov/vuln/detail/cve-2026-46300){: external}, [CVE-2026-46333](https://nvd.nist.gov/vuln/detail/cve-2026-46333){: external}, [RHSA-2026:19458](https://access.redhat.com/errata/RHSA-2026:19458){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/cve-2026-4878){: external}, [RHSA-2026:18031](https://access.redhat.com/errata/RHSA-2026:18031){: external}, [CVE-2026-41651](https://nvd.nist.gov/vuln/detail/cve-2026-41651){: external}, [RHSA-2026:19576](https://access.redhat.com/errata/RHSA-2026:19576){: external}, [CVE-2026-4786](https://nvd.nist.gov/vuln/detail/cve-2026-4786){: external}, [CVE-2026-6100](https://nvd.nist.gov/vuln/detail/cve-2026-6100){: external}, [RHSA-2026:20603](https://access.redhat.com/errata/RHSA-2026:20603){: external}, [CVE-2024-12086](https://nvd.nist.gov/vuln/detail/cve-2024-12086){: external}, [CVE-2025-10158](https://nvd.nist.gov/vuln/detail/cve-2025-10158){: external}, [CVE-2026-41035](https://nvd.nist.gov/vuln/detail/cve-2026-41035){: external}, [RHSA-2026:19457](https://access.redhat.com/errata/RHSA-2026:19457){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/cve-2025-14087){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/cve-2025-14512){: external}, [RHSA-2026:20548](https://access.redhat.com/errata/RHSA-2026:20548){: external}, and [CVE-2026-33416](https://nvd.nist.gov/vuln/detail/cve-2026-33416){: external}.


RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6
:   


RHEL 9 (Classic) 5.14.0-570.116.1.el9_6
:   Resolves the following CVEs: [RHSA-2026:18042](https://access.redhat.com/errata/RHSA-2026:18042){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/cve-2026-39979){: external}, [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/cve-2026-40164){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/cve-2026-43284){: external}, [RHSA-2026:20129](https://access.redhat.com/errata/RHSA-2026:20129){: external}, [CVE-2026-46300](https://nvd.nist.gov/vuln/detail/cve-2026-46300){: external}, [CVE-2026-46333](https://nvd.nist.gov/vuln/detail/cve-2026-46333){: external}, [RHSA-2026:19458](https://access.redhat.com/errata/RHSA-2026:19458){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/cve-2026-4878){: external}, [RHSA-2026:19576](https://access.redhat.com/errata/RHSA-2026:19576){: external}, [CVE-2026-4786](https://nvd.nist.gov/vuln/detail/cve-2026-4786){: external}, [CVE-2026-6100](https://nvd.nist.gov/vuln/detail/cve-2026-6100){: external}, [RHSA-2026:19457](https://access.redhat.com/errata/RHSA-2026:19457){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/cve-2025-14087){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/cve-2025-14512){: external}, [RHSA-2026:20548](https://access.redhat.com/errata/RHSA-2026:20548){: external}, and [CVE-2026-33416](https://nvd.nist.gov/vuln/detail/cve-2026-33416){: external}.


Red Hat OpenShift 4.21.17
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes){: external}.


Red Hat CoreOS 4.21.17
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes){: external}.


HAProxy 0e0730588ba21878845cdb0bee615a371a489a02
:   Resolves the following CVEs: [CVE-2026-4046](https://nvd.nist.gov/vuln/detail/cve-2026-4046){: external}, [CVE-2026-33846](https://nvd.nist.gov/vuln/detail/cve-2026-33846){: external}, [CVE-2026-42010](https://nvd.nist.gov/vuln/detail/cve-2026-42010){: external}, [CVE-2026-5260](https://nvd.nist.gov/vuln/detail/cve-2026-5260){: external}, [CVE-2026-42014](https://nvd.nist.gov/vuln/detail/cve-2026-42014){: external}, [CVE-2026-3833](https://nvd.nist.gov/vuln/detail/cve-2026-3833){: external}, [CVE-2026-42015](https://nvd.nist.gov/vuln/detail/cve-2026-42015){: external}, [CVE-2026-33845](https://nvd.nist.gov/vuln/detail/cve-2026-33845){: external}, [CVE-2026-42011](https://nvd.nist.gov/vuln/detail/cve-2026-42011){: external}, [CVE-2026-42009](https://nvd.nist.gov/vuln/detail/cve-2026-42009){: external}, [CVE-2026-42013](https://nvd.nist.gov/vuln/detail/cve-2026-42013){: external}, and [CVE-2026-42012](https://nvd.nist.gov/vuln/detail/cve-2026-42012){: external}.


## Master fix pack 4.21.15_1517_openshift, released 22 May 2026
{: #cl-boms_master-42115_1517_openshift_M}

The following list shows the components that are in the master fix pack 4.21.15_1517_openshift. Master patch updates are applied automatically.
{: shortdesc}

IBM Cloud Controller Manager v1.34.7-4
:   New version contains updates and security fixes.


Key Management Service provider 2.10.24
:   New version contains updates and security fixes.


Kubernetes feature gates configuration 
:   RotateKubeletServerCertificate=true,BuildCSIVolumes=true,NetworkLiveMigration=true,OpenShiftPodSecurityAdmission=false,AdminNetworkPolicy=true,KMSv1=false,ExternalOIDC=true,NetworkDiagnosticsConfig=true,ManagedBootImages=true,TranslateStreamCloseWebsocketRequests=false,NewOLM=false,DisableNodeKubeProxyVersion=false,ServiceAccountTokenNodeBinding=true,AdditionalRoutingCapabilities=true,CPMSMachineNamePrefix=true,ConsolePluginContentSecurityPolicy=true,GatewayAPI=true,GatewayAPIController=true,MetricsCollectionProfiles=true,NetworkSegmentation=true,RouteExternalCertificate=true,HighlyAvailableArbiter=true,ImageVolume=true,MachineConfigNodes=true,PinnedImages=true,ProcMountType=true,RouteAdvertisements=true,SigstoreImageVerification=true,StoragePerformantSecurityPolicy=true,UpgradeStatus=true,UserNamespacesPodSecurityStandards=true,UserNamespacesSupport=true,ExternalOIDCWithUIDAndExtraClaimMappings=true,HyperShiftOnlyDynamicResourceAllocation=true,ImageStreamImportMode=true,ManagedBootImagesvSphere=true,PreconfiguredUDNAddresses=true,SigstoreImageVerificationPKI=true,VolumeAttributesClass=true. For more information, see [Kubernetes docs](https://kubernetes.io/docs/home/){: external}


Portieris admission controller v0.13.38
:   See the [Portieris admission controller release notes](https://github.com/IBM/portieris/releases/tag/v0.13.38){: external}


Red Hat OpenShift on IBM Cloud 4.21.15
:   See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-15_release-notes){: external}.


## Worker node fix pack 4.21.15_1518_openshift, released 20 May 2026
{: #cl-boms-42115_1518_openshift_W}

The following list shows the components included in the worker node fix pack 4.21.15_1518_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

RHEL 9 (VPC) [5.14.0-570.112.1.el9_6](https://cloud.ibm.com/docs/openshift?topic=openshift-openshift-relnotes&format=markdown#openshift-may2126)
:   Resolves the following CVEs: [RHSA-2025:22392](https://access.redhat.com/errata/RHSA-2025:22392){: external}, [CVE-2025-38724](https://nvd.nist.gov/vuln/detail/cve-2025-38724){: external}, [CVE-2025-39864](https://nvd.nist.gov/vuln/detail/cve-2025-39864){: external}, [CVE-2025-39881](https://nvd.nist.gov/vuln/detail/cve-2025-39881){: external}, [CVE-2025-39883](https://nvd.nist.gov/vuln/detail/cve-2025-39883){: external}, [CVE-2025-39918](https://nvd.nist.gov/vuln/detail/cve-2025-39918){: external}, [CVE-2025-39955](https://nvd.nist.gov/vuln/detail/cve-2025-39955){: external}, [CVE-2025-40186](https://nvd.nist.gov/vuln/detail/cve-2025-40186){: external}, [RHSA-2026:0457](https://access.redhat.com/errata/RHSA-2026:0457){: external}, [CVE-2025-23142](https://nvd.nist.gov/vuln/detail/cve-2025-23142){: external}, [CVE-2025-39806](https://nvd.nist.gov/vuln/detail/cve-2025-39806){: external}, [CVE-2025-39981](https://nvd.nist.gov/vuln/detail/cve-2025-39981){: external}, [CVE-2025-39983](https://nvd.nist.gov/vuln/detail/cve-2025-39983){: external}, [CVE-2025-40176](https://nvd.nist.gov/vuln/detail/cve-2025-40176){: external}, [CVE-2025-68287](https://nvd.nist.gov/vuln/detail/cve-2025-68287){: external}, [RHSA-2026:0804](https://access.redhat.com/errata/RHSA-2026:0804){: external}, [CVE-2025-21795](https://nvd.nist.gov/vuln/detail/cve-2025-21795){: external}, [CVE-2025-37849](https://nvd.nist.gov/vuln/detail/cve-2025-37849){: external}, [CVE-2025-37891](https://nvd.nist.gov/vuln/detail/cve-2025-37891){: external}, [CVE-2025-39697](https://nvd.nist.gov/vuln/detail/cve-2025-39697){: external}, [CVE-2025-40154](https://nvd.nist.gov/vuln/detail/cve-2025-40154){: external}, [CVE-2025-68285](https://nvd.nist.gov/vuln/detail/cve-2025-68285){: external}, [RHSA-2026:14339](https://access.redhat.com/errata/RHSA-2026:14339){: external}, [CVE-2024-53216](https://nvd.nist.gov/vuln/detail/cve-2024-53216){: external}, [CVE-2025-68741](https://nvd.nist.gov/vuln/detail/cve-2025-68741){: external}, [CVE-2026-23243](https://nvd.nist.gov/vuln/detail/cve-2026-23243){: external}, [CVE-2026-23401](https://nvd.nist.gov/vuln/detail/cve-2026-23401){: external}, [CVE-2026-31431](https://nvd.nist.gov/vuln/detail/cve-2026-31431){: external}, [CVE-2026-31532](https://nvd.nist.gov/vuln/detail/cve-2026-31532){: external}, [CVE-2026-43077](https://nvd.nist.gov/vuln/detail/cve-2026-43077){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/cve-2026-43284){: external}, [RHSA-2026:1703](https://access.redhat.com/errata/RHSA-2026:1703){: external}, [CVE-2025-21863](https://nvd.nist.gov/vuln/detail/cve-2025-21863){: external}, [CVE-2025-40248](https://nvd.nist.gov/vuln/detail/cve-2025-40248){: external}, [CVE-2025-68301](https://nvd.nist.gov/vuln/detail/cve-2025-68301){: external}, [RHSA-2026:16059](https://access.redhat.com/errata/RHSA-2026:16059){: external}, [CVE-2026-35385](https://nvd.nist.gov/vuln/detail/cve-2026-35385){: external}, [CVE-2026-35386](https://nvd.nist.gov/vuln/detail/cve-2026-35386){: external}, [CVE-2026-35387](https://nvd.nist.gov/vuln/detail/cve-2026-35387){: external}, [CVE-2026-35388](https://nvd.nist.gov/vuln/detail/cve-2026-35388){: external}, [CVE-2026-35414](https://nvd.nist.gov/vuln/detail/cve-2026-35414){: external}, [RHSA-2026:13889](https://access.redhat.com/errata/RHSA-2026:13889){: external}, [CVE-2026-35535](https://nvd.nist.gov/vuln/detail/cve-2026-35535){: external}, [RHSA-2025:21563](https://access.redhat.com/errata/RHSA-2025:21563){: external}, [CVE-2024-56690](https://nvd.nist.gov/vuln/detail/cve-2024-56690){: external}, [RHSA-2025:21933](https://access.redhat.com/errata/RHSA-2025:21933){: external}, [CVE-2025-39898](https://nvd.nist.gov/vuln/detail/cve-2025-39898){: external}, [CVE-2025-39971](https://nvd.nist.gov/vuln/detail/cve-2025-39971){: external}, [CVE-2025-39973](https://nvd.nist.gov/vuln/detail/cve-2025-39973){: external}, [CVE-2025-40047](https://nvd.nist.gov/vuln/detail/cve-2025-40047){: external}, [RHSA-2025:22802](https://access.redhat.com/errata/RHSA-2025:22802){: external}, [CVE-2025-39966](https://nvd.nist.gov/vuln/detail/cve-2025-39966){: external}, [RHSA-2025:23789](https://access.redhat.com/errata/RHSA-2025:23789){: external}, [CVE-2025-39843](https://nvd.nist.gov/vuln/detail/cve-2025-39843){: external}, [CVE-2025-39925](https://nvd.nist.gov/vuln/detail/cve-2025-39925){: external}, [RHSA-2026:11313](https://access.redhat.com/errata/RHSA-2026:11313){: external}, [CVE-2026-23097](https://nvd.nist.gov/vuln/detail/cve-2026-23097){: external}, [CVE-2026-31402](https://nvd.nist.gov/vuln/detail/cve-2026-31402){: external}, [RHSA-2026:1194](https://access.redhat.com/errata/RHSA-2026:1194){: external}, [CVE-2023-53034](https://nvd.nist.gov/vuln/detail/cve-2023-53034){: external}, [CVE-2025-37761](https://nvd.nist.gov/vuln/detail/cve-2025-37761){: external}, [CVE-2025-37789](https://nvd.nist.gov/vuln/detail/cve-2025-37789){: external}, [CVE-2025-37819](https://nvd.nist.gov/vuln/detail/cve-2025-37819){: external}, [CVE-2025-37869](https://nvd.nist.gov/vuln/detail/cve-2025-37869){: external}, [CVE-2025-38289](https://nvd.nist.gov/vuln/detail/cve-2025-38289){: external}, [CVE-2025-40141](https://nvd.nist.gov/vuln/detail/cve-2025-40141){: external}, [CVE-2025-40251](https://nvd.nist.gov/vuln/detail/cve-2025-40251){: external}, [CVE-2025-40258](https://nvd.nist.gov/vuln/detail/cve-2025-40258){: external}, [CVE-2025-40277](https://nvd.nist.gov/vuln/detail/cve-2025-40277){: external}, [CVE-2025-40318](https://nvd.nist.gov/vuln/detail/cve-2025-40318){: external}, [RHSA-2026:2352](https://access.redhat.com/errata/RHSA-2026:2352){: external}, [CVE-2024-54456](https://nvd.nist.gov/vuln/detail/cve-2024-54456){: external}, [CVE-2025-21647](https://nvd.nist.gov/vuln/detail/cve-2025-21647){: external}, [CVE-2025-21786](https://nvd.nist.gov/vuln/detail/cve-2025-21786){: external}, [CVE-2025-21791](https://nvd.nist.gov/vuln/detail/cve-2025-21791){: external}, [CVE-2025-38022](https://nvd.nist.gov/vuln/detail/cve-2025-38022){: external}, [CVE-2025-38051](https://nvd.nist.gov/vuln/detail/cve-2025-38051){: external}, [CVE-2025-38568](https://nvd.nist.gov/vuln/detail/cve-2025-38568){: external}, [CVE-2025-40294](https://nvd.nist.gov/vuln/detail/cve-2025-40294){: external}, [CVE-2025-40322](https://nvd.nist.gov/vuln/detail/cve-2025-40322){: external}, [CVE-2025-68349](https://nvd.nist.gov/vuln/detail/cve-2025-68349){: external}, [RHSA-2026:2759](https://access.redhat.com/errata/RHSA-2026:2759){: external}, [CVE-2025-37882](https://nvd.nist.gov/vuln/detail/cve-2025-37882){: external}, [CVE-2025-38349](https://nvd.nist.gov/vuln/detail/cve-2025-38349){: external}, [CVE-2025-38730](https://nvd.nist.gov/vuln/detail/cve-2025-38730){: external}, [CVE-2025-39760](https://nvd.nist.gov/vuln/detail/cve-2025-39760){: external}, [CVE-2025-39933](https://nvd.nist.gov/vuln/detail/cve-2025-39933){: external}, [CVE-2025-40269](https://nvd.nist.gov/vuln/detail/cve-2025-40269){: external}, [CVE-2025-40271](https://nvd.nist.gov/vuln/detail/cve-2025-40271){: external}, [CVE-2025-40304](https://nvd.nist.gov/vuln/detail/cve-2025-40304){: external}, [RHSA-2026:3088](https://access.redhat.com/errata/RHSA-2026:3088){: external}, [CVE-2025-37861](https://nvd.nist.gov/vuln/detail/cve-2025-37861){: external}, [CVE-2025-38106](https://nvd.nist.gov/vuln/detail/cve-2025-38106){: external}, [CVE-2025-38415](https://nvd.nist.gov/vuln/detail/cve-2025-38415){: external}, [RHSA-2026:3520](https://access.redhat.com/errata/RHSA-2026:3520){: external}, [CVE-2025-38154](https://nvd.nist.gov/vuln/detail/cve-2025-38154){: external}, [RHSA-2026:4011](https://access.redhat.com/errata/RHSA-2026:4011){: external}, [CVE-2024-47727](https://nvd.nist.gov/vuln/detail/cve-2024-47727){: external}, [CVE-2024-56603](https://nvd.nist.gov/vuln/detail/cve-2024-56603){: external}, [CVE-2025-22056](https://nvd.nist.gov/vuln/detail/cve-2025-22056){: external}, [CVE-2025-38024](https://nvd.nist.gov/vuln/detail/cve-2025-38024){: external}, [CVE-2025-38129](https://nvd.nist.gov/vuln/detail/cve-2025-38129){: external}, [CVE-2025-38141](https://nvd.nist.gov/vuln/detail/cve-2025-38141){: external}, [CVE-2025-38703](https://nvd.nist.gov/vuln/detail/cve-2025-38703){: external}, [RHSA-2026:4745](https://access.redhat.com/errata/RHSA-2026:4745){: external}, [CVE-2024-53229](https://nvd.nist.gov/vuln/detail/cve-2024-53229){: external}, [CVE-2025-38206](https://nvd.nist.gov/vuln/detail/cve-2025-38206){: external}, [CVE-2025-40240](https://nvd.nist.gov/vuln/detail/cve-2025-40240){: external}, [CVE-2025-68811](https://nvd.nist.gov/vuln/detail/cve-2025-68811){: external}, [CVE-2025-71085](https://nvd.nist.gov/vuln/detail/cve-2025-71085){: external}, [RHSA-2026:5197](https://access.redhat.com/errata/RHSA-2026:5197){: external}, [CVE-2025-38248](https://nvd.nist.gov/vuln/detail/cve-2025-38248){: external}, [CVE-2026-23001](https://nvd.nist.gov/vuln/detail/cve-2026-23001){: external}, [RHSA-2026:6164](https://access.redhat.com/errata/RHSA-2026:6164){: external}, [CVE-2024-56645](https://nvd.nist.gov/vuln/detail/cve-2024-56645){: external}, [CVE-2025-40096](https://nvd.nist.gov/vuln/detail/cve-2025-40096){: external}, [CVE-2025-68800](https://nvd.nist.gov/vuln/detail/cve-2025-68800){: external}, [CVE-2026-23209](https://nvd.nist.gov/vuln/detail/cve-2026-23209){: external}, [RHSA-2026:6940](https://access.redhat.com/errata/RHSA-2026:6940){: external}, [CVE-2025-38180](https://nvd.nist.gov/vuln/detail/cve-2025-38180){: external}, [CVE-2026-23231](https://nvd.nist.gov/vuln/detail/cve-2026-23231){: external}, [RHSA-2026:9112](https://access.redhat.com/errata/RHSA-2026:9112){: external}, [CVE-2026-23066](https://nvd.nist.gov/vuln/detail/cve-2026-23066){: external}, [CVE-2026-23111](https://nvd.nist.gov/vuln/detail/cve-2026-23111){: external}, [CVE-2026-23144](https://nvd.nist.gov/vuln/detail/cve-2026-23144){: external}, [CVE-2026-23171](https://nvd.nist.gov/vuln/detail/cve-2026-23171){: external}, [CVE-2026-23193](https://nvd.nist.gov/vuln/detail/cve-2026-23193){: external}, [CVE-2026-23204](https://nvd.nist.gov/vuln/detail/cve-2026-23204){: external}, [RHSA-2026:17524](https://access.redhat.com/errata/RHSA-2026:17524){: external}, and [CVE-2026-33636](https://nvd.nist.gov/vuln/detail/cve-2026-33636){: external}.


RHEL 9 (Classic) [5.14.0-570.112.1.el9_6](https://cloud.ibm.com/docs/openshift?topic=openshift-openshift-relnotes&format=markdown#openshift-may2126)
:   Resolves the following CVEs: [RHSA-2026:2229](https://access.redhat.com/errata/RHSA-2026:2229){: external}, [CVE-2025-6176](https://nvd.nist.gov/vuln/detail/cve-2025-6176){: external}, [RHSA-2025:21773](https://access.redhat.com/errata/RHSA-2025:21773){: external}, [CVE-2025-59375](https://nvd.nist.gov/vuln/detail/cve-2025-59375){: external}, [RHSA-2026:1229](https://access.redhat.com/errata/RHSA-2026:1229){: external}, [CVE-2025-68973](https://nvd.nist.gov/vuln/detail/cve-2025-68973){: external}, [RHSA-2026:18042](https://access.redhat.com/errata/RHSA-2026:18042){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/cve-2026-39979){: external}, [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/cve-2026-40164){: external}, [RHSA-2025:22392](https://access.redhat.com/errata/RHSA-2025:22392){: external}, [CVE-2025-38724](https://nvd.nist.gov/vuln/detail/cve-2025-38724){: external}, [CVE-2025-39864](https://nvd.nist.gov/vuln/detail/cve-2025-39864){: external}, [CVE-2025-39881](https://nvd.nist.gov/vuln/detail/cve-2025-39881){: external}, [CVE-2025-39883](https://nvd.nist.gov/vuln/detail/cve-2025-39883){: external}, [CVE-2025-39918](https://nvd.nist.gov/vuln/detail/cve-2025-39918){: external}, [CVE-2025-39955](https://nvd.nist.gov/vuln/detail/cve-2025-39955){: external}, [CVE-2025-40186](https://nvd.nist.gov/vuln/detail/cve-2025-40186){: external}, [RHSA-2026:0457](https://access.redhat.com/errata/RHSA-2026:0457){: external}, [CVE-2025-23142](https://nvd.nist.gov/vuln/detail/cve-2025-23142){: external}, [CVE-2025-39806](https://nvd.nist.gov/vuln/detail/cve-2025-39806){: external}, [CVE-2025-39981](https://nvd.nist.gov/vuln/detail/cve-2025-39981){: external}, [CVE-2025-39983](https://nvd.nist.gov/vuln/detail/cve-2025-39983){: external}, [CVE-2025-40176](https://nvd.nist.gov/vuln/detail/cve-2025-40176){: external}, [CVE-2025-68287](https://nvd.nist.gov/vuln/detail/cve-2025-68287){: external}, [RHSA-2026:0804](https://access.redhat.com/errata/RHSA-2026:0804){: external}, [CVE-2025-21795](https://nvd.nist.gov/vuln/detail/cve-2025-21795){: external}, [CVE-2025-37849](https://nvd.nist.gov/vuln/detail/cve-2025-37849){: external}, [CVE-2025-37891](https://nvd.nist.gov/vuln/detail/cve-2025-37891){: external}, [CVE-2025-39697](https://nvd.nist.gov/vuln/detail/cve-2025-39697){: external}, [CVE-2025-40154](https://nvd.nist.gov/vuln/detail/cve-2025-40154){: external}, [CVE-2025-68285](https://nvd.nist.gov/vuln/detail/cve-2025-68285){: external}, [RHSA-2026:14339](https://access.redhat.com/errata/RHSA-2026:14339){: external}, [CVE-2024-53216](https://nvd.nist.gov/vuln/detail/cve-2024-53216){: external}, [CVE-2025-68741](https://nvd.nist.gov/vuln/detail/cve-2025-68741){: external}, [CVE-2026-23243](https://nvd.nist.gov/vuln/detail/cve-2026-23243){: external}, [CVE-2026-23401](https://nvd.nist.gov/vuln/detail/cve-2026-23401){: external}, [CVE-2026-31431](https://nvd.nist.gov/vuln/detail/cve-2026-31431){: external}, [CVE-2026-31532](https://nvd.nist.gov/vuln/detail/cve-2026-31532){: external}, [CVE-2026-43077](https://nvd.nist.gov/vuln/detail/cve-2026-43077){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/cve-2026-43284){: external}, [RHSA-2026:1703](https://access.redhat.com/errata/RHSA-2026:1703){: external}, [CVE-2025-21863](https://nvd.nist.gov/vuln/detail/cve-2025-21863){: external}, [CVE-2025-40248](https://nvd.nist.gov/vuln/detail/cve-2025-40248){: external}, [CVE-2025-68301](https://nvd.nist.gov/vuln/detail/cve-2025-68301){: external}, [RHSA-2026:7105](https://access.redhat.com/errata/RHSA-2026:7105){: external}, [CVE-2026-4111](https://nvd.nist.gov/vuln/detail/cve-2026-4111){: external}, [RHSA-2026:8866](https://access.redhat.com/errata/RHSA-2026:8866){: external}, [CVE-2026-4424](https://nvd.nist.gov/vuln/detail/cve-2026-4424){: external}, [CVE-2026-5121](https://nvd.nist.gov/vuln/detail/cve-2026-5121){: external}, [RHSA-2026:19458](https://access.redhat.com/errata/RHSA-2026:19458){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/cve-2026-4878){: external}, [RHSA-2026:0210](https://access.redhat.com/errata/RHSA-2026:0210){: external}, [CVE-2025-64720](https://nvd.nist.gov/vuln/detail/cve-2025-64720){: external}, [CVE-2025-65018](https://nvd.nist.gov/vuln/detail/cve-2025-65018){: external}, [CVE-2025-66293](https://nvd.nist.gov/vuln/detail/cve-2025-66293){: external}, [RHSA-2026:3576](https://access.redhat.com/errata/RHSA-2026:3576){: external}, [CVE-2026-22695](https://nvd.nist.gov/vuln/detail/cve-2026-22695){: external}, [CVE-2026-22801](https://nvd.nist.gov/vuln/detail/cve-2026-22801){: external}, [CVE-2026-25646](https://nvd.nist.gov/vuln/detail/cve-2026-25646){: external}, [RHSA-2026:8548](https://access.redhat.com/errata/RHSA-2026:8548){: external}, [CVE-2026-27135](https://nvd.nist.gov/vuln/detail/cve-2026-27135){: external}, [RHSA-2026:16059](https://access.redhat.com/errata/RHSA-2026:16059){: external}, [CVE-2026-35385](https://nvd.nist.gov/vuln/detail/cve-2026-35385){: external}, [CVE-2026-35386](https://nvd.nist.gov/vuln/detail/cve-2026-35386){: external}, [CVE-2026-35387](https://nvd.nist.gov/vuln/detail/cve-2026-35387){: external}, [CVE-2026-35388](https://nvd.nist.gov/vuln/detail/cve-2026-35388){: external}, [CVE-2026-35414](https://nvd.nist.gov/vuln/detail/cve-2026-35414){: external}, [RHSA-2026:9415](https://access.redhat.com/errata/RHSA-2026:9415){: external}, [CVE-2026-3497](https://nvd.nist.gov/vuln/detail/cve-2026-3497){: external}, [RHSA-2026:1503](https://access.redhat.com/errata/RHSA-2026:1503){: external}, [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/cve-2025-15467){: external}, [CVE-2025-69419](https://nvd.nist.gov/vuln/detail/cve-2025-69419){: external}, [RHSA-2026:1729](https://access.redhat.com/errata/RHSA-2026:1729){: external}, [CVE-2025-66418](https://nvd.nist.gov/vuln/detail/cve-2025-66418){: external}, [CVE-2025-66471](https://nvd.nist.gov/vuln/detail/cve-2025-66471){: external}, [CVE-2026-21441](https://nvd.nist.gov/vuln/detail/cve-2026-21441){: external}, [RHSA-2026:9354](https://access.redhat.com/errata/RHSA-2026:9354){: external}, [CVE-2026-4519](https://nvd.nist.gov/vuln/detail/cve-2026-4519){: external}, [RHSA-2025:21067](https://access.redhat.com/errata/RHSA-2025:21067){: external}, [CVE-2025-11561](https://nvd.nist.gov/vuln/detail/cve-2025-11561){: external}, [RHSA-2026:13889](https://access.redhat.com/errata/RHSA-2026:13889){: external}, [CVE-2026-35535](https://nvd.nist.gov/vuln/detail/cve-2026-35535){: external}, [RHSA-2026:6539](https://access.redhat.com/errata/RHSA-2026:6539){: external}, [CVE-2026-25749](https://nvd.nist.gov/vuln/detail/cve-2026-25749){: external}, [CVE-2026-28417](https://nvd.nist.gov/vuln/detail/cve-2026-28417){: external}, [CVE-2026-28421](https://nvd.nist.gov/vuln/detail/cve-2026-28421){: external}, [CVE-2026-33412](https://nvd.nist.gov/vuln/detail/cve-2026-33412){: external}, [RHSA-2025:23400](https://access.redhat.com/errata/RHSA-2025:23400){: external}, [CVE-2025-11083](https://nvd.nist.gov/vuln/detail/cve-2025-11083){: external}, [RHSA-2025:23043](https://access.redhat.com/errata/RHSA-2025:23043){: external}, [CVE-2025-9086](https://nvd.nist.gov/vuln/detail/cve-2025-9086){: external}, [RHSA-2026:1465](https://access.redhat.com/errata/RHSA-2026:1465){: external}, [CVE-2025-13601](https://nvd.nist.gov/vuln/detail/cve-2025-13601){: external}, [RHSA-2026:19457](https://access.redhat.com/errata/RHSA-2026:19457){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/cve-2025-14087){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/cve-2025-14512){: external}, [RHSA-2026:6630](https://access.redhat.com/errata/RHSA-2026:6630){: external}, [CVE-2025-14831](https://nvd.nist.gov/vuln/detail/cve-2025-14831){: external}, [RHSA-2026:4823](https://access.redhat.com/errata/RHSA-2026:4823){: external}, [CVE-2025-61662](https://nvd.nist.gov/vuln/detail/cve-2025-61662){: external}, [RHSA-2025:21563](https://access.redhat.com/errata/RHSA-2025:21563){: external}, [CVE-2024-56690](https://nvd.nist.gov/vuln/detail/cve-2024-56690){: external}, [RHSA-2025:21933](https://access.redhat.com/errata/RHSA-2025:21933){: external}, [CVE-2025-39898](https://nvd.nist.gov/vuln/detail/cve-2025-39898){: external}, [CVE-2025-39971](https://nvd.nist.gov/vuln/detail/cve-2025-39971){: external}, [CVE-2025-39973](https://nvd.nist.gov/vuln/detail/cve-2025-39973){: external}, [CVE-2025-40047](https://nvd.nist.gov/vuln/detail/cve-2025-40047){: external}, [RHSA-2025:22802](https://access.redhat.com/errata/RHSA-2025:22802){: external}, [CVE-2025-39966](https://nvd.nist.gov/vuln/detail/cve-2025-39966){: external}, [RHSA-2025:23789](https://access.redhat.com/errata/RHSA-2025:23789){: external}, [CVE-2025-39843](https://nvd.nist.gov/vuln/detail/cve-2025-39843){: external}, [CVE-2025-39925](https://nvd.nist.gov/vuln/detail/cve-2025-39925){: external}, [RHSA-2026:11313](https://access.redhat.com/errata/RHSA-2026:11313){: external}, [CVE-2026-23097](https://nvd.nist.gov/vuln/detail/cve-2026-23097){: external}, [CVE-2026-31402](https://nvd.nist.gov/vuln/detail/cve-2026-31402){: external}, [RHSA-2026:1194](https://access.redhat.com/errata/RHSA-2026:1194){: external}, [CVE-2023-53034](https://nvd.nist.gov/vuln/detail/cve-2023-53034){: external}, [CVE-2025-37761](https://nvd.nist.gov/vuln/detail/cve-2025-37761){: external}, [CVE-2025-37789](https://nvd.nist.gov/vuln/detail/cve-2025-37789){: external}, [CVE-2025-37819](https://nvd.nist.gov/vuln/detail/cve-2025-37819){: external}, [CVE-2025-37869](https://nvd.nist.gov/vuln/detail/cve-2025-37869){: external}, [CVE-2025-38289](https://nvd.nist.gov/vuln/detail/cve-2025-38289){: external}, [CVE-2025-40141](https://nvd.nist.gov/vuln/detail/cve-2025-40141){: external}, [CVE-2025-40251](https://nvd.nist.gov/vuln/detail/cve-2025-40251){: external}, [CVE-2025-40258](https://nvd.nist.gov/vuln/detail/cve-2025-40258){: external}, [CVE-2025-40277](https://nvd.nist.gov/vuln/detail/cve-2025-40277){: external}, [CVE-2025-40318](https://nvd.nist.gov/vuln/detail/cve-2025-40318){: external}, [RHSA-2026:2352](https://access.redhat.com/errata/RHSA-2026:2352){: external}, [CVE-2024-54456](https://nvd.nist.gov/vuln/detail/cve-2024-54456){: external}, [CVE-2025-21647](https://nvd.nist.gov/vuln/detail/cve-2025-21647){: external}, [CVE-2025-21786](https://nvd.nist.gov/vuln/detail/cve-2025-21786){: external}, [CVE-2025-21791](https://nvd.nist.gov/vuln/detail/cve-2025-21791){: external}, [CVE-2025-38022](https://nvd.nist.gov/vuln/detail/cve-2025-38022){: external}, [CVE-2025-38051](https://nvd.nist.gov/vuln/detail/cve-2025-38051){: external}, [CVE-2025-38568](https://nvd.nist.gov/vuln/detail/cve-2025-38568){: external}, [CVE-2025-40294](https://nvd.nist.gov/vuln/detail/cve-2025-40294){: external}, [CVE-2025-40322](https://nvd.nist.gov/vuln/detail/cve-2025-40322){: external}, [CVE-2025-68349](https://nvd.nist.gov/vuln/detail/cve-2025-68349){: external}, [RHSA-2026:2759](https://access.redhat.com/errata/RHSA-2026:2759){: external}, [CVE-2025-37882](https://nvd.nist.gov/vuln/detail/cve-2025-37882){: external}, [CVE-2025-38349](https://nvd.nist.gov/vuln/detail/cve-2025-38349){: external}, [CVE-2025-38730](https://nvd.nist.gov/vuln/detail/cve-2025-38730){: external}, [CVE-2025-39760](https://nvd.nist.gov/vuln/detail/cve-2025-39760){: external}, [CVE-2025-39933](https://nvd.nist.gov/vuln/detail/cve-2025-39933){: external}, [CVE-2025-40269](https://nvd.nist.gov/vuln/detail/cve-2025-40269){: external}, [CVE-2025-40271](https://nvd.nist.gov/vuln/detail/cve-2025-40271){: external}, [CVE-2025-40304](https://nvd.nist.gov/vuln/detail/cve-2025-40304){: external}, [RHSA-2026:3088](https://access.redhat.com/errata/RHSA-2026:3088){: external}, [CVE-2025-37861](https://nvd.nist.gov/vuln/detail/cve-2025-37861){: external}, [CVE-2025-38106](https://nvd.nist.gov/vuln/detail/cve-2025-38106){: external}, [CVE-2025-38415](https://nvd.nist.gov/vuln/detail/cve-2025-38415){: external}, [RHSA-2026:3520](https://access.redhat.com/errata/RHSA-2026:3520){: external}, [CVE-2025-38154](https://nvd.nist.gov/vuln/detail/cve-2025-38154){: external}, [RHSA-2026:4011](https://access.redhat.com/errata/RHSA-2026:4011){: external}, [CVE-2024-47727](https://nvd.nist.gov/vuln/detail/cve-2024-47727){: external}, [CVE-2024-56603](https://nvd.nist.gov/vuln/detail/cve-2024-56603){: external}, [CVE-2025-22056](https://nvd.nist.gov/vuln/detail/cve-2025-22056){: external}, [CVE-2025-38024](https://nvd.nist.gov/vuln/detail/cve-2025-38024){: external}, [CVE-2025-38129](https://nvd.nist.gov/vuln/detail/cve-2025-38129){: external}, [CVE-2025-38141](https://nvd.nist.gov/vuln/detail/cve-2025-38141){: external}, [CVE-2025-38703](https://nvd.nist.gov/vuln/detail/cve-2025-38703){: external}, [RHSA-2026:4745](https://access.redhat.com/errata/RHSA-2026:4745){: external}, [CVE-2024-53229](https://nvd.nist.gov/vuln/detail/cve-2024-53229){: external}, [CVE-2025-38206](https://nvd.nist.gov/vuln/detail/cve-2025-38206){: external}, [CVE-2025-40240](https://nvd.nist.gov/vuln/detail/cve-2025-40240){: external}, [CVE-2025-68811](https://nvd.nist.gov/vuln/detail/cve-2025-68811){: external}, [CVE-2025-71085](https://nvd.nist.gov/vuln/detail/cve-2025-71085){: external}, [RHSA-2026:5197](https://access.redhat.com/errata/RHSA-2026:5197){: external}, [CVE-2025-38248](https://nvd.nist.gov/vuln/detail/cve-2025-38248){: external}, [CVE-2026-23001](https://nvd.nist.gov/vuln/detail/cve-2026-23001){: external}, [RHSA-2026:6164](https://access.redhat.com/errata/RHSA-2026:6164){: external}, [CVE-2024-56645](https://nvd.nist.gov/vuln/detail/cve-2024-56645){: external}, [CVE-2025-40096](https://nvd.nist.gov/vuln/detail/cve-2025-40096){: external}, [CVE-2025-68800](https://nvd.nist.gov/vuln/detail/cve-2025-68800){: external}, [CVE-2026-23209](https://nvd.nist.gov/vuln/detail/cve-2026-23209){: external}, [RHSA-2026:6940](https://access.redhat.com/errata/RHSA-2026:6940){: external}, [CVE-2025-38180](https://nvd.nist.gov/vuln/detail/cve-2025-38180){: external}, [CVE-2026-23231](https://nvd.nist.gov/vuln/detail/cve-2026-23231){: external}, [RHSA-2026:9112](https://access.redhat.com/errata/RHSA-2026:9112){: external}, [CVE-2026-23066](https://nvd.nist.gov/vuln/detail/cve-2026-23066){: external}, [CVE-2026-23111](https://nvd.nist.gov/vuln/detail/cve-2026-23111){: external}, [CVE-2026-23144](https://nvd.nist.gov/vuln/detail/cve-2026-23144){: external}, [CVE-2026-23171](https://nvd.nist.gov/vuln/detail/cve-2026-23171){: external}, [CVE-2026-23193](https://nvd.nist.gov/vuln/detail/cve-2026-23193){: external}, [CVE-2026-23204](https://nvd.nist.gov/vuln/detail/cve-2026-23204){: external}, [RHSA-2026:17524](https://access.redhat.com/errata/RHSA-2026:17524){: external}, [CVE-2026-33636](https://nvd.nist.gov/vuln/detail/cve-2026-33636){: external}, [RHSA-2026:0428](https://access.redhat.com/errata/RHSA-2026:0428){: external}, [CVE-2025-5987](https://nvd.nist.gov/vuln/detail/cve-2025-5987){: external}, [RHSA-2025:22377](https://access.redhat.com/errata/RHSA-2025:22377){: external}, [CVE-2025-9714](https://nvd.nist.gov/vuln/detail/cve-2025-9714){: external}, [RHSA-2026:3941](https://access.redhat.com/errata/RHSA-2026:3941){: external}, [CVE-2025-12801](https://nvd.nist.gov/vuln/detail/cve-2025-12801){: external}, [RHSA-2026:0693](https://access.redhat.com/errata/RHSA-2026:0693){: external}, [CVE-2025-61984](https://nvd.nist.gov/vuln/detail/cve-2025-61984){: external}, [CVE-2025-61985](https://nvd.nist.gov/vuln/detail/cve-2025-61985){: external}, [RHSA-2025:21174](https://access.redhat.com/errata/RHSA-2025:21174){: external}, [CVE-2025-9230](https://nvd.nist.gov/vuln/detail/cve-2025-9230){: external}, [RHSA-2026:2275](https://access.redhat.com/errata/RHSA-2026:2275){: external}, [CVE-2025-12084](https://nvd.nist.gov/vuln/detail/cve-2025-12084){: external}, [RHSA-2026:5218](https://access.redhat.com/errata/RHSA-2026:5218){: external}, [CVE-2025-15366](https://nvd.nist.gov/vuln/detail/cve-2025-15366){: external}, [CVE-2025-15367](https://nvd.nist.gov/vuln/detail/cve-2025-15367){: external}, [CVE-2026-1299](https://nvd.nist.gov/vuln/detail/cve-2026-1299){: external}, [RHSA-2026:0435](https://access.redhat.com/errata/RHSA-2026:0435){: external}, and [CVE-2025-45582](https://nvd.nist.gov/vuln/detail/cve-2025-45582){: external}.


RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6
:   


Red Hat OpenShift 4.21.15
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-15_release-notes){: external}.


Red Hat CoreOS 4.21.15
:   For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-15_release-notes){: external}.


HAProxy 6ba93946d8bd08ba581321189c719ab548cadf01
:   Resolves the following CVEs: [CVE-2025-9714](https://nvd.nist.gov/vuln/detail/cve-2025-9714){: external}, [CVE-2026-4424](https://nvd.nist.gov/vuln/detail/cve-2026-4424){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/cve-2026-40356){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/cve-2025-14512){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/cve-2026-4878){: external}, [CVE-2026-40355](https://nvd.nist.gov/vuln/detail/cve-2026-40355){: external}, [CVE-2026-5121](https://nvd.nist.gov/vuln/detail/cve-2026-5121){: external}, and [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/cve-2025-14087){: external}.