---
name: openshift-openshift_versions_changelog_421
title: 4.21 version change log
description: View information of version changes for major, minor, and patch updates that are available for your Red Hat&reg; OpenShift&reg; on IBM Cloud&reg; clusters that run this version. Changes include updates to Red Hat OpenShift, Kubernetes, and IBM Cloud Provider components.
last-updated: 2026-08-13
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/openshift?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# 4.21 version change log
{: #openshift_changelog_421}

View information of version changes for major, minor, and patch updates that are available for your Red Hat&reg; OpenShift&reg; on IBM Cloud&reg; clusters that run this version. Changes include updates to Red Hat OpenShift, Kubernetes, and IBM Cloud Provider components.
{: shortdesc}

## Overview
{: #changelog_overview_421}


Unless otherwise noted in the change logs, the IBM Cloud provider version enables Red Hat OpenShift APIs and features that are at beta. Red Hat OpenShift alpha features are disabled and subject to change.
{: shortdesc}

Check the [Security Bulletins on IBM Cloud Status](https://cloud.ibm.com/status?selected=security){: external} for security vulnerabilities that affect Red Hat OpenShift on IBM Cloud. You can filter the results to view only **Kubernetes Service** security bulletins that are relevant to Red Hat OpenShift on IBM Cloud. Change log entries that address other security vulnerabilities but don't include an IBM security bulletin are for vulnerabilities that are not known to affect Red Hat OpenShift on IBM Cloud in normal usage. If you run privileged containers, run commands on the workers, or execute untrusted code, then you might be at risk.

Master patch updates are applied automatically. Worker node patch updates can be applied by reloading or updating the worker nodes. For more information about major, minor, and patch versions and preparation actions between minor versions, see [Red Hat OpenShift versions](https://cloud.ibm.com/docs/openshift?topic=openshift-openshift_versions&format=markdown).
{: tip}

## Version 4.21
{: #421_components}


### Worker node fix pack 4.21.27_1528_openshift, released 12 August 2026
{: #cl-boms-42127_1528_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.27_1528_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) 5.14.0-687.34.1.el9_8|Resolves the following CVEs: [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/CVE-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/CVE-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/CVE-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/CVE-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/CVE-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/CVE-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/CVE-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/CVE-2026-46209){: external}, [RHSA-2026:49031](https://access.redhat.com/errata/RHSA-2026:49031){: external}, [CVE-2025-10263](https://nvd.nist.gov/vuln/detail/CVE-2025-10263){: external}, [CVE-2025-40026](https://nvd.nist.gov/vuln/detail/CVE-2025-40026){: external}, [CVE-2026-52923](https://nvd.nist.gov/vuln/detail/CVE-2026-52923){: external}, [RHSA-2026:49839](https://access.redhat.com/errata/RHSA-2026:49839){: external}, [CVE-2026-14474](https://nvd.nist.gov/vuln/detail/CVE-2026-14474){: external}, [CVE-2026-14476](https://nvd.nist.gov/vuln/detail/CVE-2026-14476){: external}, [RHSA-2026:48811](https://access.redhat.com/errata/RHSA-2026:48811){: external}, [CVE-2026-48864](https://nvd.nist.gov/vuln/detail/CVE-2026-48864){: external}, [RHSA-2026:49910](https://access.redhat.com/errata/RHSA-2026:49910){: external}, and [CVE-2026-29111](https://nvd.nist.gov/vuln/detail/CVE-2026-29111){: external}.|
|RHEL 9 (Satellite) 5.14.0-687.34.1.el9_8|N/A|
|RHEL 9 (Classic) 5.14.0-687.34.1.el9_8|Resolves the following CVEs: [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/CVE-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/CVE-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/CVE-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/CVE-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/CVE-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/CVE-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/CVE-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/CVE-2026-46209){: external}, [RHSA-2026:49031](https://access.redhat.com/errata/RHSA-2026:49031){: external}, [CVE-2025-10263](https://nvd.nist.gov/vuln/detail/CVE-2025-10263){: external}, [CVE-2025-40026](https://nvd.nist.gov/vuln/detail/CVE-2025-40026){: external}, [CVE-2026-52923](https://nvd.nist.gov/vuln/detail/CVE-2026-52923){: external}, [RHSA-2026:49839](https://access.redhat.com/errata/RHSA-2026:49839){: external}, [CVE-2026-14474](https://nvd.nist.gov/vuln/detail/CVE-2026-14474){: external}, [CVE-2026-14476](https://nvd.nist.gov/vuln/detail/CVE-2026-14476){: external}, [RHSA-2026:48811](https://access.redhat.com/errata/RHSA-2026:48811){: external}, [CVE-2026-48864](https://nvd.nist.gov/vuln/detail/CVE-2026-48864){: external}, [RHSA-2026:49910](https://access.redhat.com/errata/RHSA-2026:49910){: external}, and [CVE-2026-29111](https://nvd.nist.gov/vuln/detail/CVE-2026-29111){: external}.|
|Red Hat OpenShift 4.21.27|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-27_release-notes).|
|Red Hat CoreOS 4.21.27|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-27_release-notes).|
|HAProxy bd7e64ef86b90455535107263466d1825f3e7f9f|Resolves the following CVEs: [CVE-2026-56391](https://nvd.nist.gov/vuln/detail/CVE-2026-56391){: external}, and [CVE-2026-56392](https://nvd.nist.gov/vuln/detail/CVE-2026-56392){: external}.|
{: caption="4.21.27_1528_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42127_1528_openshift_W-component-table}


### Master fix pack 4.21.27_1527_openshift, released 05 August 2026
{: #cl-boms_master-42127_1527_openshift_M}

The following table shows the components that are in the master fix pack 4.21.27_1527_openshift. Master patch updates are applied automatically.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|etcd v3.5.32|See the [etcd release notes](https://github.com/etcd-io/etcd/releases/v3.5.32).|
|IBM Cloud Block Storage driver and plug-in v2.5.27|New version contains updates and security fixes.|
|IBM Cloud Controller Manager v1.34.9-6|New version contains updates and security fixes.|
|IBM Cloud File Storage for Classic plug-in and monitor v456|New version contains updates and security fixes.|
|Key Management Service provider 2.10.28|New version contains updates and security fixes.|
|Red Hat OpenShift on IBM Cloud 4.21.27|See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-27_release-notes).Resolves the following CVEs: [CVE-2026-16242](https://nvd.nist.gov/vuln/detail/CVE-2026-16242){: external}.|
{: caption="4.21.27_1527_openshift fix pack." caption-side="bottom"}
{: #cl-boms_master-42127_1527_openshift_M-component-table}


### Worker node fix pack 4.21.25_1526_openshift, released 28 July 2026
{: #cl-boms-42125_1526_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.25_1526_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) 5.14.0-570.128.1.el9_6|Resolves the following CVEs: [RHSA-2026:38902](https://access.redhat.com/errata/RHSA-2026:38902){: external}, [CVE-2025-68183](https://nvd.nist.gov/vuln/detail/CVE-2025-68183){: external}, [CVE-2026-31408](https://nvd.nist.gov/vuln/detail/CVE-2026-31408){: external}, [CVE-2026-43074](https://nvd.nist.gov/vuln/detail/CVE-2026-43074){: external}, [CVE-2026-43279](https://nvd.nist.gov/vuln/detail/CVE-2026-43279){: external}, [CVE-2026-45984](https://nvd.nist.gov/vuln/detail/CVE-2026-45984){: external}, [CVE-2026-46135](https://nvd.nist.gov/vuln/detail/CVE-2026-46135){: external}, [CVE-2026-46152](https://nvd.nist.gov/vuln/detail/CVE-2026-46152){: external}, [CVE-2026-46189](https://nvd.nist.gov/vuln/detail/CVE-2026-46189){: external}, [CVE-2026-46242](https://nvd.nist.gov/vuln/detail/CVE-2026-46242){: external}, [CVE-2026-46316](https://nvd.nist.gov/vuln/detail/CVE-2026-46316){: external}, [CVE-2026-53359](https://nvd.nist.gov/vuln/detail/CVE-2026-53359){: external}, [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/CVE-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/CVE-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/CVE-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/CVE-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/CVE-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/CVE-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/CVE-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/CVE-2026-46209){: external}, [RHSA-2026:40425](https://access.redhat.com/errata/RHSA-2026:40425){: external}, [CVE-2026-43499](https://nvd.nist.gov/vuln/detail/CVE-2026-43499){: external}, [CVE-2026-53166](https://nvd.nist.gov/vuln/detail/CVE-2026-53166){: external}, and [CVE-2026-64600](https://nvd.nist.gov/vuln/detail/CVE-2026-64600){: external}.|
|RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6|N/A|
|RHEL 9 (Classic) 5.14.0-570.128.1.el9_6|Resolves the following CVEs: [RHSA-2026:38902](https://access.redhat.com/errata/RHSA-2026:38902){: external}, [CVE-2025-68183](https://nvd.nist.gov/vuln/detail/CVE-2025-68183){: external}, [CVE-2026-31408](https://nvd.nist.gov/vuln/detail/CVE-2026-31408){: external}, [CVE-2026-43074](https://nvd.nist.gov/vuln/detail/CVE-2026-43074){: external}, [CVE-2026-43279](https://nvd.nist.gov/vuln/detail/CVE-2026-43279){: external}, [CVE-2026-45984](https://nvd.nist.gov/vuln/detail/CVE-2026-45984){: external}, [CVE-2026-46135](https://nvd.nist.gov/vuln/detail/CVE-2026-46135){: external}, [CVE-2026-46152](https://nvd.nist.gov/vuln/detail/CVE-2026-46152){: external}, [CVE-2026-46189](https://nvd.nist.gov/vuln/detail/CVE-2026-46189){: external}, [CVE-2026-46242](https://nvd.nist.gov/vuln/detail/CVE-2026-46242){: external}, [CVE-2026-46316](https://nvd.nist.gov/vuln/detail/CVE-2026-46316){: external}, [CVE-2026-53359](https://nvd.nist.gov/vuln/detail/CVE-2026-53359){: external}, [RHSA-2026:44385](https://access.redhat.com/errata/RHSA-2026:44385){: external}, [CVE-2024-46738](https://nvd.nist.gov/vuln/detail/CVE-2024-46738){: external}, [CVE-2024-50076](https://nvd.nist.gov/vuln/detail/CVE-2024-50076){: external}, [CVE-2025-39982](https://nvd.nist.gov/vuln/detail/CVE-2025-39982){: external}, [CVE-2026-31488](https://nvd.nist.gov/vuln/detail/CVE-2026-31488){: external}, [CVE-2026-31613](https://nvd.nist.gov/vuln/detail/CVE-2026-31613){: external}, [CVE-2026-31684](https://nvd.nist.gov/vuln/detail/CVE-2026-31684){: external}, [CVE-2026-46116](https://nvd.nist.gov/vuln/detail/CVE-2026-46116){: external}, [CVE-2026-46209](https://nvd.nist.gov/vuln/detail/CVE-2026-46209){: external}, [RHSA-2026:40425](https://access.redhat.com/errata/RHSA-2026:40425){: external}, [CVE-2026-43499](https://nvd.nist.gov/vuln/detail/CVE-2026-43499){: external}, [CVE-2026-53166](https://nvd.nist.gov/vuln/detail/CVE-2026-53166){: external}, and [CVE-2026-64600](https://nvd.nist.gov/vuln/detail/CVE-2026-64600){: external}.|
|Red Hat OpenShift 4.21.25|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-25_release-notes).|
|Red Hat CoreOS 4.21.25|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-25_release-notes).|
|HAProxy 346c7130717ef7cc25d1dfbca7d57ca32396b692|Resolves the following CVEs: [CVE-2026-6238](https://nvd.nist.gov/vuln/detail/CVE-2026-6238){: external}, [CVE-2026-5928](https://nvd.nist.gov/vuln/detail/CVE-2026-5928){: external}, [CVE-2026-48864](https://nvd.nist.gov/vuln/detail/CVE-2026-48864){: external}, [CVE-2026-54370](https://nvd.nist.gov/vuln/detail/CVE-2026-54370){: external}, [CVE-2026-28390](https://nvd.nist.gov/vuln/detail/CVE-2026-28390){: external}, [CVE-2026-5435](https://nvd.nist.gov/vuln/detail/CVE-2026-5435){: external}, [CVE-2025-13151](https://nvd.nist.gov/vuln/detail/CVE-2025-13151){: external}, [CVE-2026-54369](https://nvd.nist.gov/vuln/detail/CVE-2026-54369){: external}, [CVE-2026-58016](https://nvd.nist.gov/vuln/detail/CVE-2026-58016){: external}, and [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/CVE-2025-6170){: external}.|
{: caption="4.21.25_1526_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42125_1526_openshift_W-component-table}


### Master fix pack 4.21.19_1525_openshift, released 28 July 2026
{: #cl-boms_master-42119_1525_openshift_M}

The following table shows the components that are in the master fix pack 4.21.19_1525_openshift. Master patch updates are applied automatically.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|Cluster health image v1.6.17|New version contains updates and security fixes.|
|etcd v3.5.30|See the [etcd release notes](https://github.com/etcd-io/etcd/releases/v3.5.30).|
|IBM Cloud Block Storage driver and plug-in v2.5.26|New version contains updates and security fixes.|
|IBM Cloud Controller Manager v1.34.9-4|New version contains updates and security fixes.|
|IBM Cloud File Storage for Classic plug-in and monitor v455|New version contains updates and security fixes.|
|IBM Cloud RBAC Operator 92ba7dd|New version contains updates and security fixes.|
|Key Management Service provider 2.10.27|New version contains updates and security fixes.|
|Portieris admission controller v0.14.2|See the [Portieris admission controller release notes](https://github.com/IBM/portieris/releases/tag/v0.14.2)|
|Red Hat OpenShift on IBM Cloud 4.21.19|See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-19_release-notes).|
{: caption="4.21.19_1525_openshift fix pack." caption-side="bottom"}
{: #cl-boms_master-42119_1525_openshift_M-component-table}


### Worker node fix pack 4.21.22_1524_openshift, released 13 July 2026
{: #cl-boms-42122_1524_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.22_1524_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) 5.14.0-570.125.1.el9_6|Resolves the following CVEs: [RHSA-2026:30004](https://access.redhat.com/errata/RHSA-2026:30004){: external}, [CVE-2026-33845](https://nvd.nist.gov/vuln/detail/CVE-2026-33845){: external}, [CVE-2026-33846](https://nvd.nist.gov/vuln/detail/CVE-2026-33846){: external}, [CVE-2026-3833](https://nvd.nist.gov/vuln/detail/CVE-2026-3833){: external}, [CVE-2026-42009](https://nvd.nist.gov/vuln/detail/CVE-2026-42009){: external}, [CVE-2026-42010](https://nvd.nist.gov/vuln/detail/CVE-2026-42010){: external}, [CVE-2026-42011](https://nvd.nist.gov/vuln/detail/CVE-2026-42011){: external}, [CVE-2026-42012](https://nvd.nist.gov/vuln/detail/CVE-2026-42012){: external}, [CVE-2026-42013](https://nvd.nist.gov/vuln/detail/CVE-2026-42013){: external}, [CVE-2026-42014](https://nvd.nist.gov/vuln/detail/CVE-2026-42014){: external}, [CVE-2026-42015](https://nvd.nist.gov/vuln/detail/CVE-2026-42015){: external}, [CVE-2026-5260](https://nvd.nist.gov/vuln/detail/CVE-2026-5260){: external}, [CVE-2026-5419](https://nvd.nist.gov/vuln/detail/CVE-2026-5419){: external}, [RHSA-2026:34094](https://access.redhat.com/errata/RHSA-2026:34094){: external}, [CVE-2025-21648](https://nvd.nist.gov/vuln/detail/CVE-2025-21648){: external}, [CVE-2025-21691](https://nvd.nist.gov/vuln/detail/CVE-2025-21691){: external}, [CVE-2026-23191](https://nvd.nist.gov/vuln/detail/CVE-2026-23191){: external}, [CVE-2026-31669](https://nvd.nist.gov/vuln/detail/CVE-2026-31669){: external}, [CVE-2026-43027](https://nvd.nist.gov/vuln/detail/CVE-2026-43027){: external}, [CVE-2026-43125](https://nvd.nist.gov/vuln/detail/CVE-2026-43125){: external}, [CVE-2026-43128](https://nvd.nist.gov/vuln/detail/CVE-2026-43128){: external}, [CVE-2026-43198](https://nvd.nist.gov/vuln/detail/CVE-2026-43198){: external}, [CVE-2026-43329](https://nvd.nist.gov/vuln/detail/CVE-2026-43329){: external}, [CVE-2026-43414](https://nvd.nist.gov/vuln/detail/CVE-2026-43414){: external}, [CVE-2026-43501](https://nvd.nist.gov/vuln/detail/CVE-2026-43501){: external}, [CVE-2026-45852](https://nvd.nist.gov/vuln/detail/CVE-2026-45852){: external}, [CVE-2026-46090](https://nvd.nist.gov/vuln/detail/CVE-2026-46090){: external}, [CVE-2026-46173](https://nvd.nist.gov/vuln/detail/CVE-2026-46173){: external}, [CVE-2026-46176](https://nvd.nist.gov/vuln/detail/CVE-2026-46176){: external}, [CVE-2026-46181](https://nvd.nist.gov/vuln/detail/CVE-2026-46181){: external}, [CVE-2026-46227](https://nvd.nist.gov/vuln/detail/CVE-2026-46227){: external}, [CVE-2026-46244](https://nvd.nist.gov/vuln/detail/CVE-2026-46244){: external}, [RHSA-2026:28147](https://access.redhat.com/errata/RHSA-2026:28147){: external}, [CVE-2026-28847](https://nvd.nist.gov/vuln/detail/CVE-2026-28847){: external}, [CVE-2026-28883](https://nvd.nist.gov/vuln/detail/CVE-2026-28883){: external}, [CVE-2026-28901](https://nvd.nist.gov/vuln/detail/CVE-2026-28901){: external}, [CVE-2026-28902](https://nvd.nist.gov/vuln/detail/CVE-2026-28902){: external}, [CVE-2026-28903](https://nvd.nist.gov/vuln/detail/CVE-2026-28903){: external}, [CVE-2026-28904](https://nvd.nist.gov/vuln/detail/CVE-2026-28904){: external}, [CVE-2026-28905](https://nvd.nist.gov/vuln/detail/CVE-2026-28905){: external}, [CVE-2026-28907](https://nvd.nist.gov/vuln/detail/CVE-2026-28907){: external}, [CVE-2026-28942](https://nvd.nist.gov/vuln/detail/CVE-2026-28942){: external}, [CVE-2026-28946](https://nvd.nist.gov/vuln/detail/CVE-2026-28946){: external}, [CVE-2026-28947](https://nvd.nist.gov/vuln/detail/CVE-2026-28947){: external}, [CVE-2026-28953](https://nvd.nist.gov/vuln/detail/CVE-2026-28953){: external}, [CVE-2026-28955](https://nvd.nist.gov/vuln/detail/CVE-2026-28955){: external}, [CVE-2026-28958](https://nvd.nist.gov/vuln/detail/CVE-2026-28958){: external}, [CVE-2026-43658](https://nvd.nist.gov/vuln/detail/CVE-2026-43658){: external}, [CVE-2026-43660](https://nvd.nist.gov/vuln/detail/CVE-2026-43660){: external}, [RHSA-2026:33634](https://access.redhat.com/errata/RHSA-2026:33634){: external}, [CVE-2024-34459](https://nvd.nist.gov/vuln/detail/CVE-2024-34459){: external}, [RHSA-2026:33230](https://access.redhat.com/errata/RHSA-2026:33230){: external}, [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/CVE-2026-5450){: external}, [RHSA-2026:28832](https://access.redhat.com/errata/RHSA-2026:28832){: external}, and [CVE-2026-31790](https://nvd.nist.gov/vuln/detail/CVE-2026-31790){: external}.|
|RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6|N/A|
|RHEL 9 (Classic) 5.14.0-570.125.1.el9_6|Resolves the following CVEs: [RHSA-2026:30004](https://access.redhat.com/errata/RHSA-2026:30004){: external}, [CVE-2026-33845](https://nvd.nist.gov/vuln/detail/CVE-2026-33845){: external}, [CVE-2026-33846](https://nvd.nist.gov/vuln/detail/CVE-2026-33846){: external}, [CVE-2026-3833](https://nvd.nist.gov/vuln/detail/CVE-2026-3833){: external}, [CVE-2026-42009](https://nvd.nist.gov/vuln/detail/CVE-2026-42009){: external}, [CVE-2026-42010](https://nvd.nist.gov/vuln/detail/CVE-2026-42010){: external}, [CVE-2026-42011](https://nvd.nist.gov/vuln/detail/CVE-2026-42011){: external}, [CVE-2026-42012](https://nvd.nist.gov/vuln/detail/CVE-2026-42012){: external}, [CVE-2026-42013](https://nvd.nist.gov/vuln/detail/CVE-2026-42013){: external}, [CVE-2026-42014](https://nvd.nist.gov/vuln/detail/CVE-2026-42014){: external}, [CVE-2026-42015](https://nvd.nist.gov/vuln/detail/CVE-2026-42015){: external}, [CVE-2026-5260](https://nvd.nist.gov/vuln/detail/CVE-2026-5260){: external}, [CVE-2026-5419](https://nvd.nist.gov/vuln/detail/CVE-2026-5419){: external}, [RHSA-2026:34094](https://access.redhat.com/errata/RHSA-2026:34094){: external}, [CVE-2025-21648](https://nvd.nist.gov/vuln/detail/CVE-2025-21648){: external}, [CVE-2025-21691](https://nvd.nist.gov/vuln/detail/CVE-2025-21691){: external}, [CVE-2026-23191](https://nvd.nist.gov/vuln/detail/CVE-2026-23191){: external}, [CVE-2026-31669](https://nvd.nist.gov/vuln/detail/CVE-2026-31669){: external}, [CVE-2026-43027](https://nvd.nist.gov/vuln/detail/CVE-2026-43027){: external}, [CVE-2026-43125](https://nvd.nist.gov/vuln/detail/CVE-2026-43125){: external}, [CVE-2026-43128](https://nvd.nist.gov/vuln/detail/CVE-2026-43128){: external}, [CVE-2026-43198](https://nvd.nist.gov/vuln/detail/CVE-2026-43198){: external}, [CVE-2026-43329](https://nvd.nist.gov/vuln/detail/CVE-2026-43329){: external}, [CVE-2026-43414](https://nvd.nist.gov/vuln/detail/CVE-2026-43414){: external}, [CVE-2026-43501](https://nvd.nist.gov/vuln/detail/CVE-2026-43501){: external}, [CVE-2026-45852](https://nvd.nist.gov/vuln/detail/CVE-2026-45852){: external}, [CVE-2026-46090](https://nvd.nist.gov/vuln/detail/CVE-2026-46090){: external}, [CVE-2026-46173](https://nvd.nist.gov/vuln/detail/CVE-2026-46173){: external}, [CVE-2026-46176](https://nvd.nist.gov/vuln/detail/CVE-2026-46176){: external}, [CVE-2026-46181](https://nvd.nist.gov/vuln/detail/CVE-2026-46181){: external}, [CVE-2026-46227](https://nvd.nist.gov/vuln/detail/CVE-2026-46227){: external}, [CVE-2026-46244](https://nvd.nist.gov/vuln/detail/CVE-2026-46244){: external}, [RHSA-2026:28147](https://access.redhat.com/errata/RHSA-2026:28147){: external}, [CVE-2026-28847](https://nvd.nist.gov/vuln/detail/CVE-2026-28847){: external}, [CVE-2026-28883](https://nvd.nist.gov/vuln/detail/CVE-2026-28883){: external}, [CVE-2026-28901](https://nvd.nist.gov/vuln/detail/CVE-2026-28901){: external}, [CVE-2026-28902](https://nvd.nist.gov/vuln/detail/CVE-2026-28902){: external}, [CVE-2026-28903](https://nvd.nist.gov/vuln/detail/CVE-2026-28903){: external}, [CVE-2026-28904](https://nvd.nist.gov/vuln/detail/CVE-2026-28904){: external}, [CVE-2026-28905](https://nvd.nist.gov/vuln/detail/CVE-2026-28905){: external}, [CVE-2026-28907](https://nvd.nist.gov/vuln/detail/CVE-2026-28907){: external}, [CVE-2026-28942](https://nvd.nist.gov/vuln/detail/CVE-2026-28942){: external}, [CVE-2026-28946](https://nvd.nist.gov/vuln/detail/CVE-2026-28946){: external}, [CVE-2026-28947](https://nvd.nist.gov/vuln/detail/CVE-2026-28947){: external}, [CVE-2026-28953](https://nvd.nist.gov/vuln/detail/CVE-2026-28953){: external}, [CVE-2026-28955](https://nvd.nist.gov/vuln/detail/CVE-2026-28955){: external}, [CVE-2026-28958](https://nvd.nist.gov/vuln/detail/CVE-2026-28958){: external}, [CVE-2026-43658](https://nvd.nist.gov/vuln/detail/CVE-2026-43658){: external}, [CVE-2026-43660](https://nvd.nist.gov/vuln/detail/CVE-2026-43660){: external}, [RHSA-2026:33634](https://access.redhat.com/errata/RHSA-2026:33634){: external}, [CVE-2024-34459](https://nvd.nist.gov/vuln/detail/CVE-2024-34459){: external}, [RHSA-2026:33230](https://access.redhat.com/errata/RHSA-2026:33230){: external}, [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/CVE-2026-5450){: external}, [RHSA-2026:28832](https://access.redhat.com/errata/RHSA-2026:28832){: external}, and [CVE-2026-31790](https://nvd.nist.gov/vuln/detail/CVE-2026-31790){: external}.|
|Red Hat OpenShift 4.21.22|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-22_release-notes).|
|Red Hat CoreOS 4.21.22|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-22_release-notes).|
|HAProxy 27f76d0c7626993cde6e1ff90fa42253718cc5fa|Resolves the following CVEs: [CVE-2026-5450](https://nvd.nist.gov/vuln/detail/CVE-2026-5450){: external}.|
{: caption="4.21.22_1524_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42122_1524_openshift_W-component-table}


### Worker node fix pack 4.21.21_1522_openshift, released 01 July 2026
{: #cl-boms-42121_1522_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.21_1522_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) 5.14.0-570.123.1.el9_6|Resolves the following CVEs: [RHSA-2026:24500](https://access.redhat.com/errata/RHSA-2026:24500){: external}, [CVE-2026-1519](https://nvd.nist.gov/vuln/detail/CVE-2026-1519){: external}, [RHSA-2026:23224](https://access.redhat.com/errata/RHSA-2026:23224){: external}, [CVE-2025-38653](https://nvd.nist.gov/vuln/detail/CVE-2025-38653){: external}, [CVE-2025-39766](https://nvd.nist.gov/vuln/detail/CVE-2025-39766){: external}, [CVE-2025-68366](https://nvd.nist.gov/vuln/detail/CVE-2025-68366){: external}, [CVE-2026-23210](https://nvd.nist.gov/vuln/detail/CVE-2026-23210){: external}, [CVE-2026-23270](https://nvd.nist.gov/vuln/detail/CVE-2026-23270){: external}, [CVE-2026-23392](https://nvd.nist.gov/vuln/detail/CVE-2026-23392){: external}, [CVE-2026-31419](https://nvd.nist.gov/vuln/detail/CVE-2026-31419){: external}, [CVE-2026-31607](https://nvd.nist.gov/vuln/detail/CVE-2026-31607){: external}, [CVE-2026-31685](https://nvd.nist.gov/vuln/detail/CVE-2026-31685){: external}, [CVE-2026-31709](https://nvd.nist.gov/vuln/detail/CVE-2026-31709){: external}, [CVE-2026-43037](https://nvd.nist.gov/vuln/detail/CVE-2026-43037){: external}, [CVE-2026-43038](https://nvd.nist.gov/vuln/detail/CVE-2026-43038){: external}, [CVE-2026-43163](https://nvd.nist.gov/vuln/detail/CVE-2026-43163){: external}, [RHSA-2026:25218](https://access.redhat.com/errata/RHSA-2026:25218){: external}, [CVE-2025-40135](https://nvd.nist.gov/vuln/detail/CVE-2025-40135){: external}, [CVE-2025-40158](https://nvd.nist.gov/vuln/detail/CVE-2025-40158){: external}, [CVE-2025-40170](https://nvd.nist.gov/vuln/detail/CVE-2025-40170){: external}, [CVE-2025-68724](https://nvd.nist.gov/vuln/detail/CVE-2025-68724){: external}, [CVE-2025-71089](https://nvd.nist.gov/vuln/detail/CVE-2025-71089){: external}, [CVE-2025-71116](https://nvd.nist.gov/vuln/detail/CVE-2025-71116){: external}, [CVE-2026-22984](https://nvd.nist.gov/vuln/detail/CVE-2026-22984){: external}, [CVE-2026-22990](https://nvd.nist.gov/vuln/detail/CVE-2026-22990){: external}, [CVE-2026-23216](https://nvd.nist.gov/vuln/detail/CVE-2026-23216){: external}, [CVE-2026-23455](https://nvd.nist.gov/vuln/detail/CVE-2026-23455){: external}, [CVE-2026-31508](https://nvd.nist.gov/vuln/detail/CVE-2026-31508){: external}, [CVE-2026-43110](https://nvd.nist.gov/vuln/detail/CVE-2026-43110){: external}, [CVE-2026-43190](https://nvd.nist.gov/vuln/detail/CVE-2026-43190){: external}, [RHSA-2026:27708](https://access.redhat.com/errata/RHSA-2026:27708){: external}, [CVE-2025-40064](https://nvd.nist.gov/vuln/detail/CVE-2025-40064){: external}, [CVE-2025-40168](https://nvd.nist.gov/vuln/detail/CVE-2025-40168){: external}, [CVE-2026-23136](https://nvd.nist.gov/vuln/detail/CVE-2026-23136){: external}, [CVE-2026-43116](https://nvd.nist.gov/vuln/detail/CVE-2026-43116){: external}, [CVE-2026-43158](https://nvd.nist.gov/vuln/detail/CVE-2026-43158){: external}, [CVE-2026-43303](https://nvd.nist.gov/vuln/detail/CVE-2026-43303){: external}, [CVE-2026-45898](https://nvd.nist.gov/vuln/detail/CVE-2026-45898){: external}, [CVE-2026-46125](https://nvd.nist.gov/vuln/detail/CVE-2026-46125){: external}, [CVE-2026-46166](https://nvd.nist.gov/vuln/detail/CVE-2026-46166){: external}, [CVE-2026-46243](https://nvd.nist.gov/vuln/detail/CVE-2026-46243){: external}, [CVE-2026-46323](https://nvd.nist.gov/vuln/detail/CVE-2026-46323){: external}, [CVE-2026-46331](https://nvd.nist.gov/vuln/detail/CVE-2026-46331){: external}, [RHSA-2026:24683](https://access.redhat.com/errata/RHSA-2026:24683){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/CVE-2026-40356){: external}, [RHSA-2026:24337](https://access.redhat.com/errata/RHSA-2026:24337){: external}, [CVE-2026-32280](https://nvd.nist.gov/vuln/detail/CVE-2026-32280){: external}, [CVE-2026-32281](https://nvd.nist.gov/vuln/detail/CVE-2026-32281){: external}, [CVE-2026-32282](https://nvd.nist.gov/vuln/detail/CVE-2026-32282){: external}, [CVE-2026-32283](https://nvd.nist.gov/vuln/detail/CVE-2026-32283){: external}, [RHSA-2026:25979](https://access.redhat.com/errata/RHSA-2026:25979){: external}, [CVE-2026-1933](https://nvd.nist.gov/vuln/detail/CVE-2026-1933){: external}, [CVE-2026-2340](https://nvd.nist.gov/vuln/detail/CVE-2026-2340){: external}, [CVE-2026-3012](https://nvd.nist.gov/vuln/detail/CVE-2026-3012){: external}, [CVE-2026-4408](https://nvd.nist.gov/vuln/detail/CVE-2026-4408){: external}, [CVE-2026-4480](https://nvd.nist.gov/vuln/detail/CVE-2026-4480){: external}, [RHSA-2026:28050](https://access.redhat.com/errata/RHSA-2026:28050){: external}, [CVE-2026-34982](https://nvd.nist.gov/vuln/detail/CVE-2026-34982){: external}, [CVE-2026-35177](https://nvd.nist.gov/vuln/detail/CVE-2026-35177){: external}, [CVE-2026-41411](https://nvd.nist.gov/vuln/detail/CVE-2026-41411){: external}, and [CVE-2026-46483](https://nvd.nist.gov/vuln/detail/CVE-2026-46483){: external}.|
|RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6|N/A|
|RHEL 9 (Classic) 5.14.0-570.123.1.el9_6|Resolves the following CVEs: [RHSA-2026:24500](https://access.redhat.com/errata/RHSA-2026:24500){: external}, [CVE-2026-1519](https://nvd.nist.gov/vuln/detail/CVE-2026-1519){: external}, [RHSA-2026:23224](https://access.redhat.com/errata/RHSA-2026:23224){: external}, [CVE-2025-38653](https://nvd.nist.gov/vuln/detail/CVE-2025-38653){: external}, [CVE-2025-39766](https://nvd.nist.gov/vuln/detail/CVE-2025-39766){: external}, [CVE-2025-68366](https://nvd.nist.gov/vuln/detail/CVE-2025-68366){: external}, [CVE-2026-23210](https://nvd.nist.gov/vuln/detail/CVE-2026-23210){: external}, [CVE-2026-23270](https://nvd.nist.gov/vuln/detail/CVE-2026-23270){: external}, [CVE-2026-23392](https://nvd.nist.gov/vuln/detail/CVE-2026-23392){: external}, [CVE-2026-31419](https://nvd.nist.gov/vuln/detail/CVE-2026-31419){: external}, [CVE-2026-31607](https://nvd.nist.gov/vuln/detail/CVE-2026-31607){: external}, [CVE-2026-31685](https://nvd.nist.gov/vuln/detail/CVE-2026-31685){: external}, [CVE-2026-31709](https://nvd.nist.gov/vuln/detail/CVE-2026-31709){: external}, [CVE-2026-43037](https://nvd.nist.gov/vuln/detail/CVE-2026-43037){: external}, [CVE-2026-43038](https://nvd.nist.gov/vuln/detail/CVE-2026-43038){: external}, [CVE-2026-43163](https://nvd.nist.gov/vuln/detail/CVE-2026-43163){: external}, [RHSA-2026:25218](https://access.redhat.com/errata/RHSA-2026:25218){: external}, [CVE-2025-40135](https://nvd.nist.gov/vuln/detail/CVE-2025-40135){: external}, [CVE-2025-40158](https://nvd.nist.gov/vuln/detail/CVE-2025-40158){: external}, [CVE-2025-40170](https://nvd.nist.gov/vuln/detail/CVE-2025-40170){: external}, [CVE-2025-68724](https://nvd.nist.gov/vuln/detail/CVE-2025-68724){: external}, [CVE-2025-71089](https://nvd.nist.gov/vuln/detail/CVE-2025-71089){: external}, [CVE-2025-71116](https://nvd.nist.gov/vuln/detail/CVE-2025-71116){: external}, [CVE-2026-22984](https://nvd.nist.gov/vuln/detail/CVE-2026-22984){: external}, [CVE-2026-22990](https://nvd.nist.gov/vuln/detail/CVE-2026-22990){: external}, [CVE-2026-23216](https://nvd.nist.gov/vuln/detail/CVE-2026-23216){: external}, [CVE-2026-23455](https://nvd.nist.gov/vuln/detail/CVE-2026-23455){: external}, [CVE-2026-31508](https://nvd.nist.gov/vuln/detail/CVE-2026-31508){: external}, [CVE-2026-43110](https://nvd.nist.gov/vuln/detail/CVE-2026-43110){: external}, [CVE-2026-43190](https://nvd.nist.gov/vuln/detail/CVE-2026-43190){: external}, [RHSA-2026:27708](https://access.redhat.com/errata/RHSA-2026:27708){: external}, [CVE-2025-40064](https://nvd.nist.gov/vuln/detail/CVE-2025-40064){: external}, [CVE-2025-40168](https://nvd.nist.gov/vuln/detail/CVE-2025-40168){: external}, [CVE-2026-23136](https://nvd.nist.gov/vuln/detail/CVE-2026-23136){: external}, [CVE-2026-43116](https://nvd.nist.gov/vuln/detail/CVE-2026-43116){: external}, [CVE-2026-43158](https://nvd.nist.gov/vuln/detail/CVE-2026-43158){: external}, [CVE-2026-43303](https://nvd.nist.gov/vuln/detail/CVE-2026-43303){: external}, [CVE-2026-45898](https://nvd.nist.gov/vuln/detail/CVE-2026-45898){: external}, [CVE-2026-46125](https://nvd.nist.gov/vuln/detail/CVE-2026-46125){: external}, [CVE-2026-46166](https://nvd.nist.gov/vuln/detail/CVE-2026-46166){: external}, [CVE-2026-46243](https://nvd.nist.gov/vuln/detail/CVE-2026-46243){: external}, [CVE-2026-46323](https://nvd.nist.gov/vuln/detail/CVE-2026-46323){: external}, [CVE-2026-46331](https://nvd.nist.gov/vuln/detail/CVE-2026-46331){: external}, [RHSA-2026:24683](https://access.redhat.com/errata/RHSA-2026:24683){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/CVE-2026-40356){: external}, [RHSA-2026:24337](https://access.redhat.com/errata/RHSA-2026:24337){: external}, [CVE-2026-32280](https://nvd.nist.gov/vuln/detail/CVE-2026-32280){: external}, [CVE-2026-32281](https://nvd.nist.gov/vuln/detail/CVE-2026-32281){: external}, [CVE-2026-32282](https://nvd.nist.gov/vuln/detail/CVE-2026-32282){: external}, [CVE-2026-32283](https://nvd.nist.gov/vuln/detail/CVE-2026-32283){: external}, [RHSA-2026:25979](https://access.redhat.com/errata/RHSA-2026:25979){: external}, [CVE-2026-1933](https://nvd.nist.gov/vuln/detail/CVE-2026-1933){: external}, [CVE-2026-2340](https://nvd.nist.gov/vuln/detail/CVE-2026-2340){: external}, [CVE-2026-3012](https://nvd.nist.gov/vuln/detail/CVE-2026-3012){: external}, [CVE-2026-4408](https://nvd.nist.gov/vuln/detail/CVE-2026-4408){: external}, [CVE-2026-4480](https://nvd.nist.gov/vuln/detail/CVE-2026-4480){: external}, [RHSA-2026:28050](https://access.redhat.com/errata/RHSA-2026:28050){: external}, [CVE-2026-34982](https://nvd.nist.gov/vuln/detail/CVE-2026-34982){: external}, [CVE-2026-35177](https://nvd.nist.gov/vuln/detail/CVE-2026-35177){: external}, [CVE-2026-41411](https://nvd.nist.gov/vuln/detail/CVE-2026-41411){: external}, and [CVE-2026-46483](https://nvd.nist.gov/vuln/detail/CVE-2026-46483){: external}.|
|Red Hat OpenShift 4.21.21|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-21_release-notes).|
|Red Hat CoreOS 4.21.21|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-21_release-notes).|
|HAProxy 119de539a7da3c92449b38e1531722802988e50c|Resolves the following CVEs: [CVE-2026-45447](https://nvd.nist.gov/vuln/detail/CVE-2026-45447){: external}, [CVE-2024-4741](https://nvd.nist.gov/vuln/detail/CVE-2024-4741){: external}, and [CVE-2024-34459](https://nvd.nist.gov/vuln/detail/CVE-2024-34459){: external}.|
{: caption="4.21.21_1522_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42121_1522_openshift_W-component-table}


### Master fix pack 4.21.18_1520_openshift, released 26 June 2026
{: #cl-boms_master-42118_1520_openshift_M}

The following table shows the components that are in the master fix pack 4.21.18_1520_openshift. Master patch updates are applied automatically.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|Cluster health image v1.6.16|New version contains updates and security fixes.|
|etcd v3.5.30|See the [etcd release notes](https://github.com/etcd-io/etcd/releases/v3.5.30).|
|IBM Cloud Block Storage driver and plug-in v2.5.26|New version contains updates and security fixes.|
|IBM Cloud Controller Manager v1.34.8-2|New version contains updates and security fixes.|
|IBM Cloud File Storage for Classic plug-in and monitor v455|New version contains updates and security fixes.|
|Key Management Service provider 2.10.25|New version contains updates and security fixes.|
|Portieris admission controller v0.14.0|See the [Portieris admission controller release notes](https://github.com/IBM/portieris/releases/tag/v0.14.0)|
|Red Hat OpenShift on IBM Cloud 4.21.18|See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-18_release-notes).|
{: caption="4.21.18_1520_openshift fix pack." caption-side="bottom"}
{: #cl-boms_master-42118_1520_openshift_M-component-table}


### Worker node fix pack 4.21.19_1521_openshift, released 15 June 2026
{: #cl-boms-42119_1521_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.19_1521_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) 5.14.0-570.116.1.el9_6|Resolves the following CVEs: [CVE-2026-5119](https://nvd.nist.gov/vuln/detail/CVE-2026-5119){: external}.|
|RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6|N/A|
|RHEL 9 (Classic) 5.14.0-570.116.1.el9_6|N/A|
|Red Hat OpenShift 4.21.19|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes).|
|Red Hat CoreOS 4.21.19|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes).|
|HAProxy d4656f400ca14059e1b5b8ef8078b4903290791a|Resolves the following CVEs: [CVE-2026-45186](https://nvd.nist.gov/vuln/detail/CVE-2026-45186){: external}.|
{: caption="4.21.19_1521_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42119_1521_openshift_W-component-table}


### Worker node fix pack 4.21.17_1519_openshift, released 03 June 2026
{: #cl-boms-42117_1519_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.17_1519_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) 5.14.0-570.116.1.el9_6|Resolves the following CVEs: [RHSA-2026:21392](https://access.redhat.com/errata/RHSA-2026:21392){: external}, [CVE-2026-4802](https://nvd.nist.gov/vuln/detail/CVE-2026-4802){: external}, [RHSA-2026:18042](https://access.redhat.com/errata/RHSA-2026:18042){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/CVE-2026-39979){: external}, [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/CVE-2026-40164){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/CVE-2026-43284){: external}, [RHSA-2026:20129](https://access.redhat.com/errata/RHSA-2026:20129){: external}, [CVE-2026-46300](https://nvd.nist.gov/vuln/detail/CVE-2026-46300){: external}, [CVE-2026-46333](https://nvd.nist.gov/vuln/detail/CVE-2026-46333){: external}, [RHSA-2026:19458](https://access.redhat.com/errata/RHSA-2026:19458){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/CVE-2026-4878){: external}, [RHSA-2026:18031](https://access.redhat.com/errata/RHSA-2026:18031){: external}, [CVE-2026-41651](https://nvd.nist.gov/vuln/detail/CVE-2026-41651){: external}, [RHSA-2026:19576](https://access.redhat.com/errata/RHSA-2026:19576){: external}, [CVE-2026-4786](https://nvd.nist.gov/vuln/detail/CVE-2026-4786){: external}, [CVE-2026-6100](https://nvd.nist.gov/vuln/detail/CVE-2026-6100){: external}, [RHSA-2026:20603](https://access.redhat.com/errata/RHSA-2026:20603){: external}, [CVE-2024-12086](https://nvd.nist.gov/vuln/detail/CVE-2024-12086){: external}, [CVE-2025-10158](https://nvd.nist.gov/vuln/detail/CVE-2025-10158){: external}, [CVE-2026-41035](https://nvd.nist.gov/vuln/detail/CVE-2026-41035){: external}, [RHSA-2026:19457](https://access.redhat.com/errata/RHSA-2026:19457){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/CVE-2025-14087){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/CVE-2025-14512){: external}, [RHSA-2026:20548](https://access.redhat.com/errata/RHSA-2026:20548){: external}, and [CVE-2026-33416](https://nvd.nist.gov/vuln/detail/CVE-2026-33416){: external}.|
|RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6|N/A|
|RHEL 9 (Classic) 5.14.0-570.116.1.el9_6|Resolves the following CVEs: [RHSA-2026:18042](https://access.redhat.com/errata/RHSA-2026:18042){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/CVE-2026-39979){: external}, [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/CVE-2026-40164){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/CVE-2026-43284){: external}, [RHSA-2026:20129](https://access.redhat.com/errata/RHSA-2026:20129){: external}, [CVE-2026-46300](https://nvd.nist.gov/vuln/detail/CVE-2026-46300){: external}, [CVE-2026-46333](https://nvd.nist.gov/vuln/detail/CVE-2026-46333){: external}, [RHSA-2026:19458](https://access.redhat.com/errata/RHSA-2026:19458){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/CVE-2026-4878){: external}, [RHSA-2026:19576](https://access.redhat.com/errata/RHSA-2026:19576){: external}, [CVE-2026-4786](https://nvd.nist.gov/vuln/detail/CVE-2026-4786){: external}, [CVE-2026-6100](https://nvd.nist.gov/vuln/detail/CVE-2026-6100){: external}, [RHSA-2026:19457](https://access.redhat.com/errata/RHSA-2026:19457){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/CVE-2025-14087){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/CVE-2025-14512){: external}, [RHSA-2026:20548](https://access.redhat.com/errata/RHSA-2026:20548){: external}, and [CVE-2026-33416](https://nvd.nist.gov/vuln/detail/CVE-2026-33416){: external}.|
|Red Hat OpenShift 4.21.17|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes).|
|Red Hat CoreOS 4.21.17|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-17_release-notes).|
|HAProxy 0e0730588ba21878845cdb0bee615a371a489a02|Resolves the following CVEs: [CVE-2026-4046](https://nvd.nist.gov/vuln/detail/CVE-2026-4046){: external}, [CVE-2026-33846](https://nvd.nist.gov/vuln/detail/CVE-2026-33846){: external}, [CVE-2026-42010](https://nvd.nist.gov/vuln/detail/CVE-2026-42010){: external}, [CVE-2026-5260](https://nvd.nist.gov/vuln/detail/CVE-2026-5260){: external}, [CVE-2026-42014](https://nvd.nist.gov/vuln/detail/CVE-2026-42014){: external}, [CVE-2026-3833](https://nvd.nist.gov/vuln/detail/CVE-2026-3833){: external}, [CVE-2026-42015](https://nvd.nist.gov/vuln/detail/CVE-2026-42015){: external}, [CVE-2026-33845](https://nvd.nist.gov/vuln/detail/CVE-2026-33845){: external}, [CVE-2026-42011](https://nvd.nist.gov/vuln/detail/CVE-2026-42011){: external}, [CVE-2026-42009](https://nvd.nist.gov/vuln/detail/CVE-2026-42009){: external}, [CVE-2026-42013](https://nvd.nist.gov/vuln/detail/CVE-2026-42013){: external}, and [CVE-2026-42012](https://nvd.nist.gov/vuln/detail/CVE-2026-42012){: external}.|
{: caption="4.21.17_1519_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42117_1519_openshift_W-component-table}


### Master fix pack 4.21.15_1517_openshift, released 22 May 2026
{: #cl-boms_master-42115_1517_openshift_M}

The following table shows the components that are in the master fix pack 4.21.15_1517_openshift. Master patch updates are applied automatically.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|IBM Cloud Controller Manager v1.34.7-4|New version contains updates and security fixes.|
|Key Management Service provider 2.10.24|New version contains updates and security fixes.|
|Kubernetes feature gates configuration |RotateKubeletServerCertificate=true,BuildCSIVolumes=true,NetworkLiveMigration=true,OpenShiftPodSecurityAdmission=false,AdminNetworkPolicy=true,KMSv1=false,ExternalOIDC=true,NetworkDiagnosticsConfig=true,ManagedBootImages=true,TranslateStreamCloseWebsocketRequests=false,NewOLM=false,DisableNodeKubeProxyVersion=false,ServiceAccountTokenNodeBinding=true,AdditionalRoutingCapabilities=true,CPMSMachineNamePrefix=true,ConsolePluginContentSecurityPolicy=true,GatewayAPI=true,GatewayAPIController=true,MetricsCollectionProfiles=true,NetworkSegmentation=true,RouteExternalCertificate=true,HighlyAvailableArbiter=true,ImageVolume=true,MachineConfigNodes=true,PinnedImages=true,ProcMountType=true,RouteAdvertisements=true,SigstoreImageVerification=true,StoragePerformantSecurityPolicy=true,UpgradeStatus=true,UserNamespacesPodSecurityStandards=true,UserNamespacesSupport=true,ExternalOIDCWithUIDAndExtraClaimMappings=true,HyperShiftOnlyDynamicResourceAllocation=true,ImageStreamImportMode=true,ManagedBootImagesvSphere=true,PreconfiguredUDNAddresses=true,SigstoreImageVerificationPKI=true,VolumeAttributesClass=true. For more information, see [Kubernetes docs](https://kubernetes.io/docs/home/)|
|Portieris admission controller v0.13.38|See the [Portieris admission controller release notes](https://github.com/IBM/portieris/releases/tag/v0.13.38)|
|Red Hat OpenShift on IBM Cloud 4.21.15|See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-15_release-notes).|
{: caption="4.21.15_1517_openshift fix pack." caption-side="bottom"}
{: #cl-boms_master-42115_1517_openshift_M-component-table}


### Worker node fix pack 4.21.15_1518_openshift, released 20 May 2026
{: #cl-boms-42115_1518_openshift_W}

The following table shows the components included in the worker node fix pack 4.21.15_1518_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Description |
| ---- | ---- |
|RHEL 9 (VPC) [5.14.0-570.112.1.el9_6](https://cloud.ibm.com/docs/openshift?topic=openshift-openshift-relnotes&format=markdown#openshift-may2126)|Resolves the following CVEs: [RHSA-2025:22392](https://access.redhat.com/errata/RHSA-2025:22392){: external}, [CVE-2025-38724](https://nvd.nist.gov/vuln/detail/CVE-2025-38724){: external}, [CVE-2025-39864](https://nvd.nist.gov/vuln/detail/CVE-2025-39864){: external}, [CVE-2025-39881](https://nvd.nist.gov/vuln/detail/CVE-2025-39881){: external}, [CVE-2025-39883](https://nvd.nist.gov/vuln/detail/CVE-2025-39883){: external}, [CVE-2025-39918](https://nvd.nist.gov/vuln/detail/CVE-2025-39918){: external}, [CVE-2025-39955](https://nvd.nist.gov/vuln/detail/CVE-2025-39955){: external}, [CVE-2025-40186](https://nvd.nist.gov/vuln/detail/CVE-2025-40186){: external}, [RHSA-2026:0457](https://access.redhat.com/errata/RHSA-2026:0457){: external}, [CVE-2025-23142](https://nvd.nist.gov/vuln/detail/CVE-2025-23142){: external}, [CVE-2025-39806](https://nvd.nist.gov/vuln/detail/CVE-2025-39806){: external}, [CVE-2025-39981](https://nvd.nist.gov/vuln/detail/CVE-2025-39981){: external}, [CVE-2025-39983](https://nvd.nist.gov/vuln/detail/CVE-2025-39983){: external}, [CVE-2025-40176](https://nvd.nist.gov/vuln/detail/CVE-2025-40176){: external}, [CVE-2025-68287](https://nvd.nist.gov/vuln/detail/CVE-2025-68287){: external}, [RHSA-2026:0804](https://access.redhat.com/errata/RHSA-2026:0804){: external}, [CVE-2025-21795](https://nvd.nist.gov/vuln/detail/CVE-2025-21795){: external}, [CVE-2025-37849](https://nvd.nist.gov/vuln/detail/CVE-2025-37849){: external}, [CVE-2025-37891](https://nvd.nist.gov/vuln/detail/CVE-2025-37891){: external}, [CVE-2025-39697](https://nvd.nist.gov/vuln/detail/CVE-2025-39697){: external}, [CVE-2025-40154](https://nvd.nist.gov/vuln/detail/CVE-2025-40154){: external}, [CVE-2025-68285](https://nvd.nist.gov/vuln/detail/CVE-2025-68285){: external}, [RHSA-2026:14339](https://access.redhat.com/errata/RHSA-2026:14339){: external}, [CVE-2024-53216](https://nvd.nist.gov/vuln/detail/CVE-2024-53216){: external}, [CVE-2025-68741](https://nvd.nist.gov/vuln/detail/CVE-2025-68741){: external}, [CVE-2026-23243](https://nvd.nist.gov/vuln/detail/CVE-2026-23243){: external}, [CVE-2026-23401](https://nvd.nist.gov/vuln/detail/CVE-2026-23401){: external}, [CVE-2026-31431](https://nvd.nist.gov/vuln/detail/CVE-2026-31431){: external}, [CVE-2026-31532](https://nvd.nist.gov/vuln/detail/CVE-2026-31532){: external}, [CVE-2026-43077](https://nvd.nist.gov/vuln/detail/CVE-2026-43077){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/CVE-2026-43284){: external}, [RHSA-2026:1703](https://access.redhat.com/errata/RHSA-2026:1703){: external}, [CVE-2025-21863](https://nvd.nist.gov/vuln/detail/CVE-2025-21863){: external}, [CVE-2025-40248](https://nvd.nist.gov/vuln/detail/CVE-2025-40248){: external}, [CVE-2025-68301](https://nvd.nist.gov/vuln/detail/CVE-2025-68301){: external}, [RHSA-2026:16059](https://access.redhat.com/errata/RHSA-2026:16059){: external}, [CVE-2026-35385](https://nvd.nist.gov/vuln/detail/CVE-2026-35385){: external}, [CVE-2026-35386](https://nvd.nist.gov/vuln/detail/CVE-2026-35386){: external}, [CVE-2026-35387](https://nvd.nist.gov/vuln/detail/CVE-2026-35387){: external}, [CVE-2026-35388](https://nvd.nist.gov/vuln/detail/CVE-2026-35388){: external}, [CVE-2026-35414](https://nvd.nist.gov/vuln/detail/CVE-2026-35414){: external}, [RHSA-2026:13889](https://access.redhat.com/errata/RHSA-2026:13889){: external}, [CVE-2026-35535](https://nvd.nist.gov/vuln/detail/CVE-2026-35535){: external}, [RHSA-2025:21563](https://access.redhat.com/errata/RHSA-2025:21563){: external}, [CVE-2024-56690](https://nvd.nist.gov/vuln/detail/CVE-2024-56690){: external}, [RHSA-2025:21933](https://access.redhat.com/errata/RHSA-2025:21933){: external}, [CVE-2025-39898](https://nvd.nist.gov/vuln/detail/CVE-2025-39898){: external}, [CVE-2025-39971](https://nvd.nist.gov/vuln/detail/CVE-2025-39971){: external}, [CVE-2025-39973](https://nvd.nist.gov/vuln/detail/CVE-2025-39973){: external}, [CVE-2025-40047](https://nvd.nist.gov/vuln/detail/CVE-2025-40047){: external}, [RHSA-2025:22802](https://access.redhat.com/errata/RHSA-2025:22802){: external}, [CVE-2025-39966](https://nvd.nist.gov/vuln/detail/CVE-2025-39966){: external}, [RHSA-2025:23789](https://access.redhat.com/errata/RHSA-2025:23789){: external}, [CVE-2025-39843](https://nvd.nist.gov/vuln/detail/CVE-2025-39843){: external}, [CVE-2025-39925](https://nvd.nist.gov/vuln/detail/CVE-2025-39925){: external}, [RHSA-2026:11313](https://access.redhat.com/errata/RHSA-2026:11313){: external}, [CVE-2026-23097](https://nvd.nist.gov/vuln/detail/CVE-2026-23097){: external}, [CVE-2026-31402](https://nvd.nist.gov/vuln/detail/CVE-2026-31402){: external}, [RHSA-2026:1194](https://access.redhat.com/errata/RHSA-2026:1194){: external}, [CVE-2023-53034](https://nvd.nist.gov/vuln/detail/CVE-2023-53034){: external}, [CVE-2025-37761](https://nvd.nist.gov/vuln/detail/CVE-2025-37761){: external}, [CVE-2025-37789](https://nvd.nist.gov/vuln/detail/CVE-2025-37789){: external}, [CVE-2025-37819](https://nvd.nist.gov/vuln/detail/CVE-2025-37819){: external}, [CVE-2025-37869](https://nvd.nist.gov/vuln/detail/CVE-2025-37869){: external}, [CVE-2025-38289](https://nvd.nist.gov/vuln/detail/CVE-2025-38289){: external}, [CVE-2025-40141](https://nvd.nist.gov/vuln/detail/CVE-2025-40141){: external}, [CVE-2025-40251](https://nvd.nist.gov/vuln/detail/CVE-2025-40251){: external}, [CVE-2025-40258](https://nvd.nist.gov/vuln/detail/CVE-2025-40258){: external}, [CVE-2025-40277](https://nvd.nist.gov/vuln/detail/CVE-2025-40277){: external}, [CVE-2025-40318](https://nvd.nist.gov/vuln/detail/CVE-2025-40318){: external}, [RHSA-2026:2352](https://access.redhat.com/errata/RHSA-2026:2352){: external}, [CVE-2024-54456](https://nvd.nist.gov/vuln/detail/CVE-2024-54456){: external}, [CVE-2025-21647](https://nvd.nist.gov/vuln/detail/CVE-2025-21647){: external}, [CVE-2025-21786](https://nvd.nist.gov/vuln/detail/CVE-2025-21786){: external}, [CVE-2025-21791](https://nvd.nist.gov/vuln/detail/CVE-2025-21791){: external}, [CVE-2025-38022](https://nvd.nist.gov/vuln/detail/CVE-2025-38022){: external}, [CVE-2025-38051](https://nvd.nist.gov/vuln/detail/CVE-2025-38051){: external}, [CVE-2025-38568](https://nvd.nist.gov/vuln/detail/CVE-2025-38568){: external}, [CVE-2025-40294](https://nvd.nist.gov/vuln/detail/CVE-2025-40294){: external}, [CVE-2025-40322](https://nvd.nist.gov/vuln/detail/CVE-2025-40322){: external}, [CVE-2025-68349](https://nvd.nist.gov/vuln/detail/CVE-2025-68349){: external}, [RHSA-2026:2759](https://access.redhat.com/errata/RHSA-2026:2759){: external}, [CVE-2025-37882](https://nvd.nist.gov/vuln/detail/CVE-2025-37882){: external}, [CVE-2025-38349](https://nvd.nist.gov/vuln/detail/CVE-2025-38349){: external}, [CVE-2025-38730](https://nvd.nist.gov/vuln/detail/CVE-2025-38730){: external}, [CVE-2025-39760](https://nvd.nist.gov/vuln/detail/CVE-2025-39760){: external}, [CVE-2025-39933](https://nvd.nist.gov/vuln/detail/CVE-2025-39933){: external}, [CVE-2025-40269](https://nvd.nist.gov/vuln/detail/CVE-2025-40269){: external}, [CVE-2025-40271](https://nvd.nist.gov/vuln/detail/CVE-2025-40271){: external}, [CVE-2025-40304](https://nvd.nist.gov/vuln/detail/CVE-2025-40304){: external}, [RHSA-2026:3088](https://access.redhat.com/errata/RHSA-2026:3088){: external}, [CVE-2025-37861](https://nvd.nist.gov/vuln/detail/CVE-2025-37861){: external}, [CVE-2025-38106](https://nvd.nist.gov/vuln/detail/CVE-2025-38106){: external}, [CVE-2025-38415](https://nvd.nist.gov/vuln/detail/CVE-2025-38415){: external}, [RHSA-2026:3520](https://access.redhat.com/errata/RHSA-2026:3520){: external}, [CVE-2025-38154](https://nvd.nist.gov/vuln/detail/CVE-2025-38154){: external}, [RHSA-2026:4011](https://access.redhat.com/errata/RHSA-2026:4011){: external}, [CVE-2024-47727](https://nvd.nist.gov/vuln/detail/CVE-2024-47727){: external}, [CVE-2024-56603](https://nvd.nist.gov/vuln/detail/CVE-2024-56603){: external}, [CVE-2025-22056](https://nvd.nist.gov/vuln/detail/CVE-2025-22056){: external}, [CVE-2025-38024](https://nvd.nist.gov/vuln/detail/CVE-2025-38024){: external}, [CVE-2025-38129](https://nvd.nist.gov/vuln/detail/CVE-2025-38129){: external}, [CVE-2025-38141](https://nvd.nist.gov/vuln/detail/CVE-2025-38141){: external}, [CVE-2025-38703](https://nvd.nist.gov/vuln/detail/CVE-2025-38703){: external}, [RHSA-2026:4745](https://access.redhat.com/errata/RHSA-2026:4745){: external}, [CVE-2024-53229](https://nvd.nist.gov/vuln/detail/CVE-2024-53229){: external}, [CVE-2025-38206](https://nvd.nist.gov/vuln/detail/CVE-2025-38206){: external}, [CVE-2025-40240](https://nvd.nist.gov/vuln/detail/CVE-2025-40240){: external}, [CVE-2025-68811](https://nvd.nist.gov/vuln/detail/CVE-2025-68811){: external}, [CVE-2025-71085](https://nvd.nist.gov/vuln/detail/CVE-2025-71085){: external}, [RHSA-2026:5197](https://access.redhat.com/errata/RHSA-2026:5197){: external}, [CVE-2025-38248](https://nvd.nist.gov/vuln/detail/CVE-2025-38248){: external}, [CVE-2026-23001](https://nvd.nist.gov/vuln/detail/CVE-2026-23001){: external}, [RHSA-2026:6164](https://access.redhat.com/errata/RHSA-2026:6164){: external}, [CVE-2024-56645](https://nvd.nist.gov/vuln/detail/CVE-2024-56645){: external}, [CVE-2025-40096](https://nvd.nist.gov/vuln/detail/CVE-2025-40096){: external}, [CVE-2025-68800](https://nvd.nist.gov/vuln/detail/CVE-2025-68800){: external}, [CVE-2026-23209](https://nvd.nist.gov/vuln/detail/CVE-2026-23209){: external}, [RHSA-2026:6940](https://access.redhat.com/errata/RHSA-2026:6940){: external}, [CVE-2025-38180](https://nvd.nist.gov/vuln/detail/CVE-2025-38180){: external}, [CVE-2026-23231](https://nvd.nist.gov/vuln/detail/CVE-2026-23231){: external}, [RHSA-2026:9112](https://access.redhat.com/errata/RHSA-2026:9112){: external}, [CVE-2026-23066](https://nvd.nist.gov/vuln/detail/CVE-2026-23066){: external}, [CVE-2026-23111](https://nvd.nist.gov/vuln/detail/CVE-2026-23111){: external}, [CVE-2026-23144](https://nvd.nist.gov/vuln/detail/CVE-2026-23144){: external}, [CVE-2026-23171](https://nvd.nist.gov/vuln/detail/CVE-2026-23171){: external}, [CVE-2026-23193](https://nvd.nist.gov/vuln/detail/CVE-2026-23193){: external}, [CVE-2026-23204](https://nvd.nist.gov/vuln/detail/CVE-2026-23204){: external}, [RHSA-2026:17524](https://access.redhat.com/errata/RHSA-2026:17524){: external}, and [CVE-2026-33636](https://nvd.nist.gov/vuln/detail/CVE-2026-33636){: external}.|
|RHEL 9 (Classic) [5.14.0-570.112.1.el9_6](https://cloud.ibm.com/docs/openshift?topic=openshift-openshift-relnotes&format=markdown#openshift-may2126)|Resolves the following CVEs: [RHSA-2026:2229](https://access.redhat.com/errata/RHSA-2026:2229){: external}, [CVE-2025-6176](https://nvd.nist.gov/vuln/detail/CVE-2025-6176){: external}, [RHSA-2025:21773](https://access.redhat.com/errata/RHSA-2025:21773){: external}, [CVE-2025-59375](https://nvd.nist.gov/vuln/detail/CVE-2025-59375){: external}, [RHSA-2026:1229](https://access.redhat.com/errata/RHSA-2026:1229){: external}, [CVE-2025-68973](https://nvd.nist.gov/vuln/detail/CVE-2025-68973){: external}, [RHSA-2026:18042](https://access.redhat.com/errata/RHSA-2026:18042){: external}, [CVE-2026-39979](https://nvd.nist.gov/vuln/detail/CVE-2026-39979){: external}, [CVE-2026-40164](https://nvd.nist.gov/vuln/detail/CVE-2026-40164){: external}, [RHSA-2025:22392](https://access.redhat.com/errata/RHSA-2025:22392){: external}, [CVE-2025-38724](https://nvd.nist.gov/vuln/detail/CVE-2025-38724){: external}, [CVE-2025-39864](https://nvd.nist.gov/vuln/detail/CVE-2025-39864){: external}, [CVE-2025-39881](https://nvd.nist.gov/vuln/detail/CVE-2025-39881){: external}, [CVE-2025-39883](https://nvd.nist.gov/vuln/detail/CVE-2025-39883){: external}, [CVE-2025-39918](https://nvd.nist.gov/vuln/detail/CVE-2025-39918){: external}, [CVE-2025-39955](https://nvd.nist.gov/vuln/detail/CVE-2025-39955){: external}, [CVE-2025-40186](https://nvd.nist.gov/vuln/detail/CVE-2025-40186){: external}, [RHSA-2026:0457](https://access.redhat.com/errata/RHSA-2026:0457){: external}, [CVE-2025-23142](https://nvd.nist.gov/vuln/detail/CVE-2025-23142){: external}, [CVE-2025-39806](https://nvd.nist.gov/vuln/detail/CVE-2025-39806){: external}, [CVE-2025-39981](https://nvd.nist.gov/vuln/detail/CVE-2025-39981){: external}, [CVE-2025-39983](https://nvd.nist.gov/vuln/detail/CVE-2025-39983){: external}, [CVE-2025-40176](https://nvd.nist.gov/vuln/detail/CVE-2025-40176){: external}, [CVE-2025-68287](https://nvd.nist.gov/vuln/detail/CVE-2025-68287){: external}, [RHSA-2026:0804](https://access.redhat.com/errata/RHSA-2026:0804){: external}, [CVE-2025-21795](https://nvd.nist.gov/vuln/detail/CVE-2025-21795){: external}, [CVE-2025-37849](https://nvd.nist.gov/vuln/detail/CVE-2025-37849){: external}, [CVE-2025-37891](https://nvd.nist.gov/vuln/detail/CVE-2025-37891){: external}, [CVE-2025-39697](https://nvd.nist.gov/vuln/detail/CVE-2025-39697){: external}, [CVE-2025-40154](https://nvd.nist.gov/vuln/detail/CVE-2025-40154){: external}, [CVE-2025-68285](https://nvd.nist.gov/vuln/detail/CVE-2025-68285){: external}, [RHSA-2026:14339](https://access.redhat.com/errata/RHSA-2026:14339){: external}, [CVE-2024-53216](https://nvd.nist.gov/vuln/detail/CVE-2024-53216){: external}, [CVE-2025-68741](https://nvd.nist.gov/vuln/detail/CVE-2025-68741){: external}, [CVE-2026-23243](https://nvd.nist.gov/vuln/detail/CVE-2026-23243){: external}, [CVE-2026-23401](https://nvd.nist.gov/vuln/detail/CVE-2026-23401){: external}, [CVE-2026-31431](https://nvd.nist.gov/vuln/detail/CVE-2026-31431){: external}, [CVE-2026-31532](https://nvd.nist.gov/vuln/detail/CVE-2026-31532){: external}, [CVE-2026-43077](https://nvd.nist.gov/vuln/detail/CVE-2026-43077){: external}, [RHSA-2026:16312](https://access.redhat.com/errata/RHSA-2026:16312){: external}, [CVE-2026-43284](https://nvd.nist.gov/vuln/detail/CVE-2026-43284){: external}, [RHSA-2026:1703](https://access.redhat.com/errata/RHSA-2026:1703){: external}, [CVE-2025-21863](https://nvd.nist.gov/vuln/detail/CVE-2025-21863){: external}, [CVE-2025-40248](https://nvd.nist.gov/vuln/detail/CVE-2025-40248){: external}, [CVE-2025-68301](https://nvd.nist.gov/vuln/detail/CVE-2025-68301){: external}, [RHSA-2026:7105](https://access.redhat.com/errata/RHSA-2026:7105){: external}, [CVE-2026-4111](https://nvd.nist.gov/vuln/detail/CVE-2026-4111){: external}, [RHSA-2026:8866](https://access.redhat.com/errata/RHSA-2026:8866){: external}, [CVE-2026-4424](https://nvd.nist.gov/vuln/detail/CVE-2026-4424){: external}, [CVE-2026-5121](https://nvd.nist.gov/vuln/detail/CVE-2026-5121){: external}, [RHSA-2026:19458](https://access.redhat.com/errata/RHSA-2026:19458){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/CVE-2026-4878){: external}, [RHSA-2026:0210](https://access.redhat.com/errata/RHSA-2026:0210){: external}, [CVE-2025-64720](https://nvd.nist.gov/vuln/detail/CVE-2025-64720){: external}, [CVE-2025-65018](https://nvd.nist.gov/vuln/detail/CVE-2025-65018){: external}, [CVE-2025-66293](https://nvd.nist.gov/vuln/detail/CVE-2025-66293){: external}, [RHSA-2026:3576](https://access.redhat.com/errata/RHSA-2026:3576){: external}, [CVE-2026-22695](https://nvd.nist.gov/vuln/detail/CVE-2026-22695){: external}, [CVE-2026-22801](https://nvd.nist.gov/vuln/detail/CVE-2026-22801){: external}, [CVE-2026-25646](https://nvd.nist.gov/vuln/detail/CVE-2026-25646){: external}, [RHSA-2026:8548](https://access.redhat.com/errata/RHSA-2026:8548){: external}, [CVE-2026-27135](https://nvd.nist.gov/vuln/detail/CVE-2026-27135){: external}, [RHSA-2026:16059](https://access.redhat.com/errata/RHSA-2026:16059){: external}, [CVE-2026-35385](https://nvd.nist.gov/vuln/detail/CVE-2026-35385){: external}, [CVE-2026-35386](https://nvd.nist.gov/vuln/detail/CVE-2026-35386){: external}, [CVE-2026-35387](https://nvd.nist.gov/vuln/detail/CVE-2026-35387){: external}, [CVE-2026-35388](https://nvd.nist.gov/vuln/detail/CVE-2026-35388){: external}, [CVE-2026-35414](https://nvd.nist.gov/vuln/detail/CVE-2026-35414){: external}, [RHSA-2026:9415](https://access.redhat.com/errata/RHSA-2026:9415){: external}, [CVE-2026-3497](https://nvd.nist.gov/vuln/detail/CVE-2026-3497){: external}, [RHSA-2026:1503](https://access.redhat.com/errata/RHSA-2026:1503){: external}, [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/CVE-2025-15467){: external}, [CVE-2025-69419](https://nvd.nist.gov/vuln/detail/CVE-2025-69419){: external}, [RHSA-2026:1729](https://access.redhat.com/errata/RHSA-2026:1729){: external}, [CVE-2025-66418](https://nvd.nist.gov/vuln/detail/CVE-2025-66418){: external}, [CVE-2025-66471](https://nvd.nist.gov/vuln/detail/CVE-2025-66471){: external}, [CVE-2026-21441](https://nvd.nist.gov/vuln/detail/CVE-2026-21441){: external}, [RHSA-2026:9354](https://access.redhat.com/errata/RHSA-2026:9354){: external}, [CVE-2026-4519](https://nvd.nist.gov/vuln/detail/CVE-2026-4519){: external}, [RHSA-2025:21067](https://access.redhat.com/errata/RHSA-2025:21067){: external}, [CVE-2025-11561](https://nvd.nist.gov/vuln/detail/CVE-2025-11561){: external}, [RHSA-2026:13889](https://access.redhat.com/errata/RHSA-2026:13889){: external}, [CVE-2026-35535](https://nvd.nist.gov/vuln/detail/CVE-2026-35535){: external}, [RHSA-2026:6539](https://access.redhat.com/errata/RHSA-2026:6539){: external}, [CVE-2026-25749](https://nvd.nist.gov/vuln/detail/CVE-2026-25749){: external}, [CVE-2026-28417](https://nvd.nist.gov/vuln/detail/CVE-2026-28417){: external}, [CVE-2026-28421](https://nvd.nist.gov/vuln/detail/CVE-2026-28421){: external}, [CVE-2026-33412](https://nvd.nist.gov/vuln/detail/CVE-2026-33412){: external}, [RHSA-2025:23400](https://access.redhat.com/errata/RHSA-2025:23400){: external}, [CVE-2025-11083](https://nvd.nist.gov/vuln/detail/CVE-2025-11083){: external}, [RHSA-2025:23043](https://access.redhat.com/errata/RHSA-2025:23043){: external}, [CVE-2025-9086](https://nvd.nist.gov/vuln/detail/CVE-2025-9086){: external}, [RHSA-2026:1465](https://access.redhat.com/errata/RHSA-2026:1465){: external}, [CVE-2025-13601](https://nvd.nist.gov/vuln/detail/CVE-2025-13601){: external}, [RHSA-2026:19457](https://access.redhat.com/errata/RHSA-2026:19457){: external}, [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/CVE-2025-14087){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/CVE-2025-14512){: external}, [RHSA-2026:6630](https://access.redhat.com/errata/RHSA-2026:6630){: external}, [CVE-2025-14831](https://nvd.nist.gov/vuln/detail/CVE-2025-14831){: external}, [RHSA-2026:4823](https://access.redhat.com/errata/RHSA-2026:4823){: external}, [CVE-2025-61662](https://nvd.nist.gov/vuln/detail/CVE-2025-61662){: external}, [RHSA-2025:21563](https://access.redhat.com/errata/RHSA-2025:21563){: external}, [CVE-2024-56690](https://nvd.nist.gov/vuln/detail/CVE-2024-56690){: external}, [RHSA-2025:21933](https://access.redhat.com/errata/RHSA-2025:21933){: external}, [CVE-2025-39898](https://nvd.nist.gov/vuln/detail/CVE-2025-39898){: external}, [CVE-2025-39971](https://nvd.nist.gov/vuln/detail/CVE-2025-39971){: external}, [CVE-2025-39973](https://nvd.nist.gov/vuln/detail/CVE-2025-39973){: external}, [CVE-2025-40047](https://nvd.nist.gov/vuln/detail/CVE-2025-40047){: external}, [RHSA-2025:22802](https://access.redhat.com/errata/RHSA-2025:22802){: external}, [CVE-2025-39966](https://nvd.nist.gov/vuln/detail/CVE-2025-39966){: external}, [RHSA-2025:23789](https://access.redhat.com/errata/RHSA-2025:23789){: external}, [CVE-2025-39843](https://nvd.nist.gov/vuln/detail/CVE-2025-39843){: external}, [CVE-2025-39925](https://nvd.nist.gov/vuln/detail/CVE-2025-39925){: external}, [RHSA-2026:11313](https://access.redhat.com/errata/RHSA-2026:11313){: external}, [CVE-2026-23097](https://nvd.nist.gov/vuln/detail/CVE-2026-23097){: external}, [CVE-2026-31402](https://nvd.nist.gov/vuln/detail/CVE-2026-31402){: external}, [RHSA-2026:1194](https://access.redhat.com/errata/RHSA-2026:1194){: external}, [CVE-2023-53034](https://nvd.nist.gov/vuln/detail/CVE-2023-53034){: external}, [CVE-2025-37761](https://nvd.nist.gov/vuln/detail/CVE-2025-37761){: external}, [CVE-2025-37789](https://nvd.nist.gov/vuln/detail/CVE-2025-37789){: external}, [CVE-2025-37819](https://nvd.nist.gov/vuln/detail/CVE-2025-37819){: external}, [CVE-2025-37869](https://nvd.nist.gov/vuln/detail/CVE-2025-37869){: external}, [CVE-2025-38289](https://nvd.nist.gov/vuln/detail/CVE-2025-38289){: external}, [CVE-2025-40141](https://nvd.nist.gov/vuln/detail/CVE-2025-40141){: external}, [CVE-2025-40251](https://nvd.nist.gov/vuln/detail/CVE-2025-40251){: external}, [CVE-2025-40258](https://nvd.nist.gov/vuln/detail/CVE-2025-40258){: external}, [CVE-2025-40277](https://nvd.nist.gov/vuln/detail/CVE-2025-40277){: external}, [CVE-2025-40318](https://nvd.nist.gov/vuln/detail/CVE-2025-40318){: external}, [RHSA-2026:2352](https://access.redhat.com/errata/RHSA-2026:2352){: external}, [CVE-2024-54456](https://nvd.nist.gov/vuln/detail/CVE-2024-54456){: external}, [CVE-2025-21647](https://nvd.nist.gov/vuln/detail/CVE-2025-21647){: external}, [CVE-2025-21786](https://nvd.nist.gov/vuln/detail/CVE-2025-21786){: external}, [CVE-2025-21791](https://nvd.nist.gov/vuln/detail/CVE-2025-21791){: external}, [CVE-2025-38022](https://nvd.nist.gov/vuln/detail/CVE-2025-38022){: external}, [CVE-2025-38051](https://nvd.nist.gov/vuln/detail/CVE-2025-38051){: external}, [CVE-2025-38568](https://nvd.nist.gov/vuln/detail/CVE-2025-38568){: external}, [CVE-2025-40294](https://nvd.nist.gov/vuln/detail/CVE-2025-40294){: external}, [CVE-2025-40322](https://nvd.nist.gov/vuln/detail/CVE-2025-40322){: external}, [CVE-2025-68349](https://nvd.nist.gov/vuln/detail/CVE-2025-68349){: external}, [RHSA-2026:2759](https://access.redhat.com/errata/RHSA-2026:2759){: external}, [CVE-2025-37882](https://nvd.nist.gov/vuln/detail/CVE-2025-37882){: external}, [CVE-2025-38349](https://nvd.nist.gov/vuln/detail/CVE-2025-38349){: external}, [CVE-2025-38730](https://nvd.nist.gov/vuln/detail/CVE-2025-38730){: external}, [CVE-2025-39760](https://nvd.nist.gov/vuln/detail/CVE-2025-39760){: external}, [CVE-2025-39933](https://nvd.nist.gov/vuln/detail/CVE-2025-39933){: external}, [CVE-2025-40269](https://nvd.nist.gov/vuln/detail/CVE-2025-40269){: external}, [CVE-2025-40271](https://nvd.nist.gov/vuln/detail/CVE-2025-40271){: external}, [CVE-2025-40304](https://nvd.nist.gov/vuln/detail/CVE-2025-40304){: external}, [RHSA-2026:3088](https://access.redhat.com/errata/RHSA-2026:3088){: external}, [CVE-2025-37861](https://nvd.nist.gov/vuln/detail/CVE-2025-37861){: external}, [CVE-2025-38106](https://nvd.nist.gov/vuln/detail/CVE-2025-38106){: external}, [CVE-2025-38415](https://nvd.nist.gov/vuln/detail/CVE-2025-38415){: external}, [RHSA-2026:3520](https://access.redhat.com/errata/RHSA-2026:3520){: external}, [CVE-2025-38154](https://nvd.nist.gov/vuln/detail/CVE-2025-38154){: external}, [RHSA-2026:4011](https://access.redhat.com/errata/RHSA-2026:4011){: external}, [CVE-2024-47727](https://nvd.nist.gov/vuln/detail/CVE-2024-47727){: external}, [CVE-2024-56603](https://nvd.nist.gov/vuln/detail/CVE-2024-56603){: external}, [CVE-2025-22056](https://nvd.nist.gov/vuln/detail/CVE-2025-22056){: external}, [CVE-2025-38024](https://nvd.nist.gov/vuln/detail/CVE-2025-38024){: external}, [CVE-2025-38129](https://nvd.nist.gov/vuln/detail/CVE-2025-38129){: external}, [CVE-2025-38141](https://nvd.nist.gov/vuln/detail/CVE-2025-38141){: external}, [CVE-2025-38703](https://nvd.nist.gov/vuln/detail/CVE-2025-38703){: external}, [RHSA-2026:4745](https://access.redhat.com/errata/RHSA-2026:4745){: external}, [CVE-2024-53229](https://nvd.nist.gov/vuln/detail/CVE-2024-53229){: external}, [CVE-2025-38206](https://nvd.nist.gov/vuln/detail/CVE-2025-38206){: external}, [CVE-2025-40240](https://nvd.nist.gov/vuln/detail/CVE-2025-40240){: external}, [CVE-2025-68811](https://nvd.nist.gov/vuln/detail/CVE-2025-68811){: external}, [CVE-2025-71085](https://nvd.nist.gov/vuln/detail/CVE-2025-71085){: external}, [RHSA-2026:5197](https://access.redhat.com/errata/RHSA-2026:5197){: external}, [CVE-2025-38248](https://nvd.nist.gov/vuln/detail/CVE-2025-38248){: external}, [CVE-2026-23001](https://nvd.nist.gov/vuln/detail/CVE-2026-23001){: external}, [RHSA-2026:6164](https://access.redhat.com/errata/RHSA-2026:6164){: external}, [CVE-2024-56645](https://nvd.nist.gov/vuln/detail/CVE-2024-56645){: external}, [CVE-2025-40096](https://nvd.nist.gov/vuln/detail/CVE-2025-40096){: external}, [CVE-2025-68800](https://nvd.nist.gov/vuln/detail/CVE-2025-68800){: external}, [CVE-2026-23209](https://nvd.nist.gov/vuln/detail/CVE-2026-23209){: external}, [RHSA-2026:6940](https://access.redhat.com/errata/RHSA-2026:6940){: external}, [CVE-2025-38180](https://nvd.nist.gov/vuln/detail/CVE-2025-38180){: external}, [CVE-2026-23231](https://nvd.nist.gov/vuln/detail/CVE-2026-23231){: external}, [RHSA-2026:9112](https://access.redhat.com/errata/RHSA-2026:9112){: external}, [CVE-2026-23066](https://nvd.nist.gov/vuln/detail/CVE-2026-23066){: external}, [CVE-2026-23111](https://nvd.nist.gov/vuln/detail/CVE-2026-23111){: external}, [CVE-2026-23144](https://nvd.nist.gov/vuln/detail/CVE-2026-23144){: external}, [CVE-2026-23171](https://nvd.nist.gov/vuln/detail/CVE-2026-23171){: external}, [CVE-2026-23193](https://nvd.nist.gov/vuln/detail/CVE-2026-23193){: external}, [CVE-2026-23204](https://nvd.nist.gov/vuln/detail/CVE-2026-23204){: external}, [RHSA-2026:17524](https://access.redhat.com/errata/RHSA-2026:17524){: external}, [CVE-2026-33636](https://nvd.nist.gov/vuln/detail/CVE-2026-33636){: external}, [RHSA-2026:0428](https://access.redhat.com/errata/RHSA-2026:0428){: external}, [CVE-2025-5987](https://nvd.nist.gov/vuln/detail/CVE-2025-5987){: external}, [RHSA-2025:22377](https://access.redhat.com/errata/RHSA-2025:22377){: external}, [CVE-2025-9714](https://nvd.nist.gov/vuln/detail/CVE-2025-9714){: external}, [RHSA-2026:3941](https://access.redhat.com/errata/RHSA-2026:3941){: external}, [CVE-2025-12801](https://nvd.nist.gov/vuln/detail/CVE-2025-12801){: external}, [RHSA-2026:0693](https://access.redhat.com/errata/RHSA-2026:0693){: external}, [CVE-2025-61984](https://nvd.nist.gov/vuln/detail/CVE-2025-61984){: external}, [CVE-2025-61985](https://nvd.nist.gov/vuln/detail/CVE-2025-61985){: external}, [RHSA-2025:21174](https://access.redhat.com/errata/RHSA-2025:21174){: external}, [CVE-2025-9230](https://nvd.nist.gov/vuln/detail/CVE-2025-9230){: external}, [RHSA-2026:2275](https://access.redhat.com/errata/RHSA-2026:2275){: external}, [CVE-2025-12084](https://nvd.nist.gov/vuln/detail/CVE-2025-12084){: external}, [RHSA-2026:5218](https://access.redhat.com/errata/RHSA-2026:5218){: external}, [CVE-2025-15366](https://nvd.nist.gov/vuln/detail/CVE-2025-15366){: external}, [CVE-2025-15367](https://nvd.nist.gov/vuln/detail/CVE-2025-15367){: external}, [CVE-2026-1299](https://nvd.nist.gov/vuln/detail/CVE-2026-1299){: external}, [RHSA-2026:0435](https://access.redhat.com/errata/RHSA-2026:0435){: external}, and [CVE-2025-45582](https://nvd.nist.gov/vuln/detail/CVE-2025-45582){: external}.|
|RHEL 9 (Satellite) 5.14.0-570.62.1.el9_6|N/A|
|Red Hat OpenShift 4.21.15|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-15_release-notes).|
|Red Hat CoreOS 4.21.15|For more information, see the [change logs](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes.html#ocp-4-21-15_release-notes).|
|HAProxy 6ba93946d8bd08ba581321189c719ab548cadf01|Resolves the following CVEs: [CVE-2025-9714](https://nvd.nist.gov/vuln/detail/CVE-2025-9714){: external}, [CVE-2026-4424](https://nvd.nist.gov/vuln/detail/CVE-2026-4424){: external}, [CVE-2026-40356](https://nvd.nist.gov/vuln/detail/CVE-2026-40356){: external}, [CVE-2025-14512](https://nvd.nist.gov/vuln/detail/CVE-2025-14512){: external}, [CVE-2026-4878](https://nvd.nist.gov/vuln/detail/CVE-2026-4878){: external}, [CVE-2026-40355](https://nvd.nist.gov/vuln/detail/CVE-2026-40355){: external}, [CVE-2026-5121](https://nvd.nist.gov/vuln/detail/CVE-2026-5121){: external}, and [CVE-2025-14087](https://nvd.nist.gov/vuln/detail/CVE-2025-14087){: external}.|
{: caption="4.21.15_1518_openshift fix pack." caption-side="bottom"}
{: #cl-boms-42115_1518_openshift_W-component-table}


### Change log for master fix pack 4.21.13_1516_openshift, released 13 May 2026
{: #42113_1516_openshift_M}

The following table shows the changes that are in the master fix pack 4.21.13_1516_openshift. Master patch updates are applied automatically.
{: shortdesc}

| Component | Previous | Current | Description |
| --- | --- | --- | --- |
| IBM Cloud Controller Manager | v1.33.10-2 | v1.34.7-1 | New version contains updates and security fixes. |
| Kubernetes pause container | 3.10.1 | 3.10.2 | New version contains updates and security fixes. |
| Red Hat OpenShift | 4.20.18 | 4.21.13 | See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-13_release-notes){: external}. |
{: caption="Changes since master version 4.20.18_1545_openshift" caption-side="bottom"}


### Change log for worker node fix pack 4.21.10_1514_openshift, released 13 May 2026
{: #42110_1514_openshift_W}

The following table shows the changes that are in the worker node fix pack 4.21.10_1514_openshift. Worker node patch updates can be applied by updating, reloading (in classic infrastructure), or replacing (in VPC infrastructure) the worker node.
{: shortdesc}

| Component | Previous | Current | Description |
| --- | --- | --- | --- |
| Red Hat OpenShift | 4.20.15 | 4.21.10 | See the [Red Hat OpenShift on IBM Cloud release notes](https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes#ocp-4-21-10_release-notes){: external}. |
{: caption="Changes since worker node version 4.20.15_1544_openshift" caption-side="bottom"}