Skip to content

Commit 36d3a81

Browse files
committed
Patch release notes for 4.9.8
1 parent 669d6a0 commit 36d3a81

3 files changed

Lines changed: 28 additions & 3 deletions

File tree

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
// Module included in the following assemblies:
2+
//
3+
// * release_notes/49-release-notes.adoc
4+
5+
:_mod-docs-content-type: REFERENCE
6+
[id="about-this-release-498_{context}"]
7+
= About release 4.9.8
8+
9+
[role="_abstract"]
10+
This release contains fixes to address security vulnerabilities.
11+
12+
*Release date*: {ga-date-498}
13+
14+
This release addresses the following security vulnerabilities:
15+
16+
//ROX-35018
17+
* golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (link:https://access.redhat.com/security/cve/CVE-2026-46595[CVE-2026-46595])
18+
19+
//ROX-35022
20+
* golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (link:https://access.redhat.com/security/cve/CVE-2026-39821[CVE-2026-39821])
21+
22+
//ROX-35139
23+
* golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (link:https://access.redhat.com/security/cve/CVE-2026-42508[CVE-2026-42508])

modules/common-attributes.adoc

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ endif::[]
6262
:product-registry: OpenShift image registry
6363
:olm-first: Operator Lifecycle Manager (OLM)
6464
:olm: OLM
65-
:rhacs-version: 4.9.7
65+
:rhacs-version: 4.9.8
6666
:ga-date-490: 30 October 2025
6767
:ga-date-491: 24 November 2025
6868
:ga-date-492: 16 December 2025
@@ -71,6 +71,7 @@ endif::[]
7171
:ga-date-495: 8 April 2026
7272
:ga-date-496: 6 May 2026
7373
:ga-date-497: 2 June 2026
74+
:ga-date-498: 18 June 2026
7475
:ocp-supported-version: 4.12
7576
:ocp-latest-version: 4.21
7677
:pipelines-shortname: OpenShift Pipelines

release_notes/49-release-notes.adoc

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,7 @@ toc::[]
2323
|`4.9.5` | {ga-date-495}
2424
|`4.9.6` | {ga-date-496}
2525
|`4.9.7` | {ga-date-497}
26-
27-
26+
|`4.9.8` | {ga-date-498}
2827

2928
|====
3029

@@ -743,4 +742,6 @@ This release addresses the following security vulnerabilities:
743742
//ROX-34736
744743
* Go crypto/x509: Denial of service via inefficient certificate chain validation (link:https://access.redhat.com/security/cve/CVE-2026-32281[CVE-2026-32281])
745744

745+
include::modules/bug-fixes-in-version-498.adoc[leveloffset=+1]
746+
746747
include::modules/image-versions.adoc[leveloffset=+1]

0 commit comments

Comments
 (0)