📖 ~4 min read • Source: Red Hat advisory RHSA RHSA-2026:3875
Related CVEs: CVE-2025-58183 CVE-2025-61726 CVE-2025-65637
Table of contents
Symptom & Impact
openshift runs when an image is pulled, unpacked, inspected or a container is started, so a defect here is normally reached through untrusted image content or a registry response rather than inbound traffic to a listening port. On Red Hat Enterprise Linux 9 that shows up as escapes from the container’s namespaces, files written outside the intended root during buildah or podman build, mount and capability handling that grants more than was requested, and images produced before the update carrying the defect onward to every host that pulls them. openshift is container tooling — command-line binaries invoked per operation, though a node runtime such as cri-o does run as a unit — so restart steps apply to that runtime and to containers still running the old code, not to openshift itself.
Environment & Reproduction
Reproduction targets Red Hat Enterprise Linux 9. Confirm release and the installed package:
cat /etc/redhat-release
cat /etc/os-release
sudo subscription-manager status
sudo subscription-manager repos --list-enabled
rpm -q openshift
dnf info openshift | head -20
Exercise the workload that uses openshift while collecting:
sudo needs-restarting -u # --useronly: restrict to the invoking user's processes (useful on shared/app hosts)
sudo lsof -n +L1 # link count < 1 = file deleted but still open/mmap'd; this is the ground truth after an RPM replaces a .so (package: lsof)
sudo lsof -n +L1 2>/dev/null | awk 'NR>1 {print $1, $2}' | sort -u # condensed COMMAND + PID list of every process still running old code
sudo journalctl -xe --no-pager | tail -200
sudo tail -200 /var/log/dnf.log
sudo tail -200 /var/log/audit/audit.log
# For an evidence bundle bundle with sosreport:
sudo sosreport --batch
Root Cause Analysis
Root cause is documented in Red Hat advisory RHSA RHSA-2026:3875. Red Hat maintainers shipped fixes in the corresponding openshift update for Red Hat Enterprise Linux 9; running an outdated build leaves the host exposed to the failure modes described in the advisory. Correlate dnf history with system logs:
sudo dnf history | head
sudo dnf history list openshift
sudo dnf history info <id>
sudo ausearch -m AVC,USER_AVC -ts today | tail -100
cat /proc/sys/kernel/tainted # non-zero = tainted kernel / out-of-tree modules
Quick Triage
Run these on Red Hat Enterprise Linux 9 to capture the current state of openshift:
rpm -q openshift # installed NVR
rpm -V openshift # verify shipped files
sudo dnf check-update --security
sudo dnf updateinfo list cves
systemctl --failed --no-pager
sudo firewall-cmd --list-all
getenforce && sestatus
dnf repoquery -l openshift 2>/dev/null | grep -E '/lib/systemd/system/.*\.(service|socket|timer)$' # same check WITHOUT installing (EL7/Amazon Linux 2: yum install yum-utils, then: repoquery -l openshift)
systemctl show --no-pager -p Type,RemainAfterExit <UNIT> # Type=oneshot (often paired with a .timer) means a one-shot job, NOT a daemon -- do not 'restart' it, let the timer fire
Step-by-Step Diagnosis
-
List failed systemd units.
systemctl --failed --no-pager -
Tail the journal for
openshiftand the system bus.sudo journalctl -xe -f --no-pager -
Inspect firewall posture.
sudo firewall-cmd --list-all-zones --permanent sudo nft list ruleset 2>/dev/null | head -50 -
Surface SELinux denials and author a local policy module if needed.
sudo ausearch -m AVC,USER_AVC -ts today sudo ausearch -m AVC -ts today | audit2allow -a -M /tmp/local-fix sudo semodule -i /tmp/local-fix.pp -
Verify
openshiftintegrity and reinstall if anything is altered.sudo rpm -V openshift sudo dnf reinstall openshift -
Correlate findings with
/var/log/dnf.log,dnf history, and Red Hat advisory RHSA RHSA-2026:3875 to pin the change that introduced the regression.
Solution – Primary Fix
Apply the corrective dnf transaction referenced by Red Hat advisory RHSA RHSA-2026:3875, then reload affected systemd units:
sudo dnf -y makecache
sudo dnf -y upgrade --security # apply ALL security errata (recommended)
# Or target a single package:
sudo dnf -y upgrade openshift
sudo systemctl daemon-reload
# Unit name may differ from pkg name; check first:
readelf -p .comment /path/to/binary 2>/dev/null | grep -o 'GCC:.*' # ELF .comment records the exact compiler that produced the file (package: binutils); absent if the build stripped it
annocheck /path/to/binary # RHEL-native: reports the build-time compiler and hardening flags (package: annobin-annocheck on RHEL/Alma/Rocky 9-10, annobin on RHEL 8)
go version -m /path/to/binary # prints the Go toolchain and module versions baked into a Go binary -- rebuild anything below the patched go version
rpm -q openshift # confirm new NVR
For kernel / glibc / systemd / openssl advisories a reboot is required (or kpatch where licensed):
sudo needs-restarting -r # report whether reboot needed
sudo systemctl reboot # or: sudo shutdown -r now
# kpatch (Red Hat / Oracle) avoids reboot for many kernel CVEs:
sudo dnf install -y kpatch kpatch-dnf
sudo dnf kpatch auto # enable auto-patching
sudo kpatch list
Need help rolling this patch across a Red Hat Enterprise Linux fleet? Our IT Solutions & Services team manages RHEL patch windows with Red Hat Satellite / Insights / kpatch. Get in touch for a free consultation.
Solution – Alternative Approaches
If the primary patch is not viable, choose from these:
-
Roll back the offending dnf transaction:
sudo dnf history list | head sudo dnf history info <id> sudo dnf history undo <id> -
Version-lock the package so dnf cannot upgrade it:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add openshift sudo dnf versionlock list sudo dnf versionlock delete openshift # remove the lock -
Install an older NVR if a regression is suspected:
dnf --showduplicates list openshift | tac | head sudo dnf install -y --allowerasing openshift-<older-NVR> -
Switch SELinux to permissive briefly to confirm policy is the cause, then re-enforce:
sudo setenforce 0 # reproduce, capture denials, author a custom module: sudo ausearch -m AVC -ts recent | audit2allow -a -M mylocal sudo semodule -i mylocal.pp sudo setenforce 1 -
Take an LVM snapshot before kernel / glibc upgrades for fast rollback:
sudo lvs sudo lvcreate -s -n preupgrade -L 4G /dev/<vg>/<lv> # revert later via: sudo lvconvert --merge /dev/<vg>/preupgrade && sudo systemctl reboot -
Where kpatch is licensed, apply kernel fixes without reboot:
sudo kpatch list sudo kpatch load /usr/lib/modules/$(uname -r)/extra/kpatch/*.ko
Verification & Acceptance Criteria
All of these should pass after the fix:
rpm -q openshift # expected fixed NVR
sudo dnf updateinfo list cves --installed # CVEs above no longer listed
sudo firewall-cmd --list-services
getenforce
sudo needs-restarting -r
The conditions described in the advisory must no longer be reported for openshift across two consecutive runs.
Rollback Plan
Capture state before any change:
rpm -qa > /root/rpm-pre.txt
sudo dnf history list > /root/dnf-history-pre.txt
# Optional LVM snapshot of the root LV:
sudo lvcreate -s -n preupgrade -L 4G /dev/<vg>/<lv>
To revert if the patch is bad:
sudo dnf history undo <id>
# Or downgrade just the package:
sudo dnf install -y --allowerasing openshift-<older-NVR>
sudo systemctl daemon-reload
# Or merge the LVM snapshot and reboot:
sudo lvconvert --merge /dev/<vg>/preupgrade && sudo systemctl reboot
# Custom SELinux policy cleanup:
sudo semodule -r mylocal
Prevention & Hardening
Reduce the chance of this recurring on Red Hat Enterprise Linux 9:
-
Enable automatic security patching:
sudo dnf install -y dnf-automatic sudo sed -i 's/^upgrade_type.*/upgrade_type = security/' /etc/dnf/automatic.conf sudo sed -i 's/^apply_updates.*/apply_updates = yes/' /etc/dnf/automatic.conf sudo systemctl enable --now dnf-automatic.timer -
Register the host with Red Hat Insights and the Remote Host Configuration daemon:
sudo insights-client --register sudo insights-client --check-results sudo dnf install -y rhc && sudo rhc connect -
Watch Red Hat Product Security advisories and the Red Hat Security Data feeds for upstream changes.
-
Mirror through Red Hat Satellite / Capsule for controlled rollouts:
sudo dnf install -y dnf-utils createrepo_c sudo reposync --download-metadata --downloadcomps -p /srv/mirror -- repoid=baseos sudo createrepo_c /srv/mirror/baseos -
Version-lock sensitive packages so they cannot be auto-upgraded:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add openshift -
Monitor file integrity with AIDE:
sudo dnf install -y aide sudo aide --init && sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz sudo aide --check -
Enable kpatch so kernel CVEs can be remediated without reboot:
sudo dnf install -y kpatch kpatch-dnf sudo dnf kpatch auto sudo kpatch list -
Keep SELinux in enforcing mode and review custom modules in
/etc/selinux/targeted/after every package upgrade. -
Apply CIS Red Hat Enterprise Linux 9 Benchmark hardening and remove unused packages.
Related Errors & Cross-Refs
Issues that commonly surface alongside a openshift update: dnf lock contention, systemd unit ordering cycles, SELinux AVC bursts, firewalld zone drift, and kernel taint flags. Useful triage:
sudo dnf check
systemd-analyze critical-chain
sudo ausearch -m AVC -ts today | tail
sudo firewall-cmd --get-active-zones
cat /proc/sys/kernel/tainted
sudo needs-restarting -r
View all rhel-9 tutorials on the Tutorials Hub →
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Primary reference: Red Hat advisory RHSA RHSA-2026:3875. Manual pages useful on Red Hat Enterprise Linux 9:
man dnf
man dnf.conf
man systemctl
man journalctl
man firewall-cmd
man semanage
man audit2allow
man kpatch
man sosreport
Other resources: Red Hat Enterprise Linux documentation, Red Hat CVE database, Red Hat product errata, and per-package notes in /usr/share/doc/openshift/ for components implicated in this advisory.