RHBA-2025:15694MediumCVSS 6.7

Red Hat Bug Fix Advisory: OpenShift Container Platform 4.19.12 bug fix update

Published
September 16, 2025
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-5187 — kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:004ebd00806f07c72b9c3408187fd1227ddf280d2113c4c73404967c8ef644b6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:377d1ac2d4bb570b2a049d564f8e334da2dde1a47e31ac5d210bf701b5d5bf54_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:6e2f0c11f21d97f95d5799bee387d435b25efe47ca3e694d4b233bb714027eaf_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e712d207542b63283d7f535e664938bd5bee2bd95bd204d43ac9c824a305a32f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5a553fbd361daf9ca8f7f5a411e4ef5d0e2bc87b1d2979f349075e0aa75e879f_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:662c43244ac6d0acbdd3f7b6289400163fb5d893c92d39aa3eabc36c350f01b0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b86e13901755ac0bf975e1a4f948a9ba6cf2318281597d570ba67ccd32354eab_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ec49dc91f8d384ffd39c1d6745bf62f5d2dcbc9c53ec32518fb27cce934fa9ba_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0ebe2818d0a8fa5113bfe0235dfc5208ab8003afe6441f7d14eef5809c5d2a92_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:567bd4b4c841d364b76e85d9a073343b6f06a9f7dbebc5fead8cdf20bb68afae_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:73a16de69252eaf2911ff398c7fa67b225cd757d9a3c240d226636b36376c7fc_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fc9150c35bccc372806c6db6a3bc2aed06c337293d85ee6ea2cf7589a9dd05f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5a960e7819fbac7ecf7faf58dc10780cf9d9c58f74b60837ebf78f47b568ab45_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e8ec0477a5806a5f53b3468620268526ae769c4b0a7e77aff562e2ac2893015d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:eb8911d1c053e355cd871b54857efd162dab312c3cd915843cb03221135cbf22_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f17f73dc742d5d3b95932bf8f6219d776905e8b0699675f9d5a2614446d18976_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:48d418f165345f720e1b60b3f990148090d6b54e54f8dbbf59b0dc9ab10acea0_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:729086eb2711314d89f307020edf1d58d8d6c4e96eb6c9161aa5b8cec8370d17_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:768d68fecc0b2c9619f8efdf693c4f1601050e76429d116ec059aa179eda5335_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:fd7cac644a3d84f2450c2a1953b5145ec5b9ea0d5efd210ab28ae02d61abdc6d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1f8daa6b285bf3f83470563377445244c01658adccdf46ce1f74a31bc40e6599_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a686440bba2d1c73922da126f7435d892ab23b8c3941259b5d3a20d595fd5303_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c449bfead28191c5c7dd08e85e9d72685c38b01b2ff4ba640a07461148683bb3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ce7c4e1bbced6a77bb5df2c26113b879861be62774bc9490033d0b88971db5e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5d65cd8116b1a4be5ca72d064d5015d044c1e59430501cf3039293d0072d21a9_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7785b2a16b2a2c7443cfc59164c74acb341237b09a9f87c5f0747c9140d21b92_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:97212e58a6bc1621334f76b1c5829765dc28a0d1606d446b10ab69ec22d6cfe4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fa1397c77592b9b7c6fc2b9a3dd5bc332f280bc7c891c07123cd1af3274247ed_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:145e53ff21b92e08e32bfbd93d0e64c1ca805c0e5af512603c3f88aec3652c4f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f0ca7c0e9ede6440119f3fd90abdd87e77cf99b7e68d6c1f95ec1872c62cbb17 (For s390x architecture) The image digest is sha256:d6f8ece6352f890e927d9deb4255bbfb67760965b9c94e60b875080ed028da6f (For ppc64le architecture) The image digest is sha256:4dfd2f864c890aa8af14d032bfdf076c818f92dd9853f802d41b65706541b61a (For aarch64 architecture) The image digest is sha256:849353b2beb257c1cfd66079647e0426e4662c514606acd013273ac40f3a92f7 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: This vulnerability can be mitigated by enabling the OwnerReferencesPermissionEnforcement admission controller, which will prevent any user without delete permissions on an object from modifying the OwnerReferences on that object. Note that this admission controller will apply to all users and object types.

🔗 References (4)