{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Red Hat OpenShift Container Platform low-latency extras release 4.11, which provides an update for cnf-tests-container, dpdk-base-container and performance-addon-operator-must-gather-rhel8-container is now available.\nSecondary scheduler builds and\nnumaresources-operator are also available for developer preview with this\nrelease, however they are not intended for production.",
        "title": "Topic"
      },
      {
        "category": "general",
        "text": "Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.\n\nThis advisory contains the extra low-latency container images for Red Hat OpenShift Container Platform 4.11. See the following advisory for the container images for this release:\n\nhttps://access.redhat.com/errata/RHSA-2022:5069\n\nAll OpenShift Container Platform users are advised to upgrade to these updated packages and images.",
        "title": "Details"
      },
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://access.redhat.com/errata/RHBA-2022:5869",
        "url": "https://access.redhat.com/errata/RHBA-2022:5869"
      },
      {
        "category": "external",
        "summary": "https://issues.redhat.com/browse/CNF-5541",
        "url": "https://issues.redhat.com/browse/CNF-5541"
      },
      {
        "category": "external",
        "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2095539",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2095539"
      },
      {
        "category": "external",
        "summary": "2072709",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2072709"
      },
      {
        "category": "external",
        "summary": "2078239",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2078239"
      },
      {
        "category": "external",
        "summary": "2081852",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2081852"
      },
      {
        "category": "external",
        "summary": "2087159",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2087159"
      },
      {
        "category": "external",
        "summary": "2089414",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2089414"
      },
      {
        "category": "external",
        "summary": "2090184",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2090184"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhba-2022_5869.json"
      }
    ],
    "title": "Red Hat Bug Fix Advisory: OpenShift Container Platform 4.11 low-latency extras update",
    "tracking": {
      "current_release_date": "2026-08-18T02:17:36+00:00",
      "generator": {
        "date": "2026-08-18T02:17:36+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.16"
        }
      },
      "id": "RHBA-2022:5869",
      "initial_release_date": "2022-08-10T12:16:08+00:00",
      "revision_history": [
        {
          "date": "2022-08-10T12:16:08+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2022-08-10T12:16:08+00:00",
          "number": "2",
          "summary": "Last updated version"
        },
        {
          "date": "2026-08-18T02:17:36+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Container Platform 4.11",
                "product": {
                  "name": "Red Hat OpenShift Container Platform 4.11",
                  "product_id": "8Base-RHOSE-4.11",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift:4.11::el8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Enterprise"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
                "product": {
                  "name": "openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
                  "product_id": "openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c?arch=amd64&repository_url=registry.redhat.io/openshift4/cnf-tests-rhel8&tag=v4.11.0-51"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
                "product": {
                  "name": "openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
                  "product_id": "openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f?arch=amd64&repository_url=registry.redhat.io/openshift4/noderesourcetopology-scheduler-container-rhel8&tag=v4.11.0-28"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
                "product": {
                  "name": "openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
                  "product_id": "openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933?arch=amd64&repository_url=registry.redhat.io/openshift4/numaresources-operator-bundle&tag=v4.11.0-80"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
                "product": {
                  "name": "openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
                  "product_id": "openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0?arch=amd64&repository_url=registry.redhat.io/openshift4/numaresources-rhel8-operator&tag=v4.11.0-74"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64",
                "product": {
                  "name": "openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64",
                  "product_id": "openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf?arch=amd64&repository_url=registry.redhat.io/openshift4/performance-addon-operator-must-gather-rhel8&tag=v4.11.0-115"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64 as a component of Red Hat OpenShift Container Platform 4.11",
          "product_id": "8Base-RHOSE-4.11:openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64"
        },
        "product_reference": "openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
        "relates_to_product_reference": "8Base-RHOSE-4.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64 as a component of Red Hat OpenShift Container Platform 4.11",
          "product_id": "8Base-RHOSE-4.11:openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64"
        },
        "product_reference": "openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
        "relates_to_product_reference": "8Base-RHOSE-4.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64 as a component of Red Hat OpenShift Container Platform 4.11",
          "product_id": "8Base-RHOSE-4.11:openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64"
        },
        "product_reference": "openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
        "relates_to_product_reference": "8Base-RHOSE-4.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64 as a component of Red Hat OpenShift Container Platform 4.11",
          "product_id": "8Base-RHOSE-4.11:openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64"
        },
        "product_reference": "openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
        "relates_to_product_reference": "8Base-RHOSE-4.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64 as a component of Red Hat OpenShift Container Platform 4.11",
          "product_id": "8Base-RHOSE-4.11:openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64"
        },
        "product_reference": "openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64",
        "relates_to_product_reference": "8Base-RHOSE-4.11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Joël Gähwiler"
          ],
          "summary": "Acknowledged by upstream."
        }
      ],
      "cve": "CVE-2022-29526",
      "cwe": {
        "id": "CWE-358",
        "name": "Improperly Implemented Security Check for Standard"
      },
      "discovery_date": "2022-05-11T00:00:00+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2084085"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the syscall.Faccessat function when calling a process by checking the group. This flaw allows an attacker to check the process group permissions rather than a member of the file's group, affecting system availability.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "golang: syscall: faccessat checks wrong group",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "8Base-RHOSE-4.11:openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
          "8Base-RHOSE-4.11:openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
          "8Base-RHOSE-4.11:openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
          "8Base-RHOSE-4.11:openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
          "8Base-RHOSE-4.11:openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2022-29526"
        },
        {
          "category": "external",
          "summary": "RHBZ#2084085",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2084085"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2022-29526",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-29526"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2022-29526",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29526"
        },
        {
          "category": "external",
          "summary": "https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU",
          "url": "https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU"
        }
      ],
      "release_date": "2022-05-11T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2022-08-10T12:16:08+00:00",
          "details": "For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html\n\nDetails on how to access this content are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html.",
          "product_ids": [
            "8Base-RHOSE-4.11:openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
            "8Base-RHOSE-4.11:openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
            "8Base-RHOSE-4.11:openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
            "8Base-RHOSE-4.11:openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
            "8Base-RHOSE-4.11:openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHBA-2022:5869"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "8Base-RHOSE-4.11:openshift4/cnf-tests-rhel8@sha256:2fd2a5e84572f7778428a8eb5ce544676f7e0a40e08ce6fc06672c4914b5e72c_amd64",
            "8Base-RHOSE-4.11:openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:5b99ba80888ee16602779b9aa4b2dcbadee205c23b1f23b68cf11c752b16243f_amd64",
            "8Base-RHOSE-4.11:openshift4/numaresources-operator-bundle@sha256:55809e710697b1c2f53b6d84749a40398106678bf4150bb157fb929b92b44933_amd64",
            "8Base-RHOSE-4.11:openshift4/numaresources-rhel8-operator@sha256:c808cdd9231f68543e00897d775c7ddbc15f480e7c923eb09ba63d6fe8177cf0_amd64",
            "8Base-RHOSE-4.11:openshift4/performance-addon-operator-must-gather-rhel8@sha256:33e913731af09fdbf7feb25d205259c4f06f79a3a8b6555bd330222e10fa4edf_amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "golang: syscall: faccessat checks wrong group"
    }
  ]
}