Red Hat Bug Fix Advisory: OpenShift Container Platform 4.18.24 bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-5187 — kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3d49af13876ecc8aff4fc54d6e8f9ae59da311ea6d9846f6c4f36b1ad9f69415_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7ad7c7f55a4275865903041d614f3fd967ff84f0c9c065e561493f01e2ed7f06_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9fa130a69c08a16d8bdd49ac69bd1933fd782cb865a5b5aee25e09e62953404d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ae93cd96c35064801db0a3a6e36d65dfb7ad96a60df68b3fcf9149856bb91382_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:520c680458ec672c0a1c39f4124819dcf1a213b01165fa6ef95e18019fd8732f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5f942ecc3fcdce8bb0fab49baa65968bc362e4ce62a80f3078d0520e723f90fd_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:80cf1e47478cd403f9e45995e10d4a3af4cb28bb529fb8538ce2305ccf57c05f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c62e422d47172eb74e2d588ad3bbe9dccd87b302efbe26c7756322913c3ce69b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0913d6044df7276b4bd859668a8941ff04a1feca2fcccd10de9daf43e2602ec9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:218c3a38733b77a31af5aee85048c6b99c028658824899628992961ffa3f258c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:59913a295ae67701c3f91b3344db6aec4f9148c17ee68c3b3115f14c2818ca2d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:62e4bf11c51fed8e48bd5c89b0e0e17caac059d832754fa9cb8dba61115fab72_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3f18898abe21412ee71c37253cbbfad83f2a935b8c92bdfafa3d5127d6e12fee_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6f0d5a4680fac79a254b67c0661e2b482eb35cc2b4c92f0ee27226a96ef5580c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d789325b82fe8545c0ee4bbaf28e75287ce358c4ae6638866648bae63ab256eb_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ddf10104213897ba1fcadf2c66156c1aaa065cf58b027935a6aecb25b1a4c4f7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:23f16eac5d2f35378fd8e3b1229af0a14c1631cf9d5f8edfe70f8f89843f8df7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9e3a43e80b9ef0a57b51e0598d28ca63564385ab558a17050cf8765fca7e1b59_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c92646730dda530f90e75e90d983bcc72246e153b43e9e4dfbb247f966edc89f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:daf9c36c34f10270ee946b5053f33560f27d711ae018172c962d7656132c5a32_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2bcb60729538a2003ee5adb24f5375280bd6332f5550efe05f88bef27eb9eeaf_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:4dfcf6a2db28f5771a94d7e69e45246bd1475b9292f18b885f499fed4723c29b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a5651deff75744b1ac61dcfaf58cb14ee0f86fd1e2d0098726bdb68c0f2d2dde_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:b213a0d329ee102130c6d48de9089fe778e45a8cc2b9a36dbe9cb6099c3d623a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:2345b446980062f0edcd8b47d2e9d49394d84a21cd5837883ee77a322a198097_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:3e0ff60e32a7acca9679273e57fba649456fb2c777659da77cc7f922774647ab_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:486a2f685dba23a312234b97055b12718d39f050302c43c5303b66acb0a6144f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:c72058f679a236d776af6bdb4f6c24f44abb3546981566506c50880db12b72b3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-exporter-rhel9@sha256:0165d42e845be2725af10593171458f29cbaa9491f6de529fb565ee6f28719b2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2db093f063ad5310fa4e5ed2d2eda4bad5215c47092b72d1cfafbcfdbf1f4dd2 (For s390x architecture) The image digest is sha256:578636cf6c118e3f27e73e2d44895dd5dd619c50b8f1f3a32e08b1df628f9dcb (For ppc64le architecture) The image digest is sha256:6d3380150dd6b9fe1044503a96bf42199b271e7758466649c4b6fb08ff25c559 (For aarch64 architecture) The image digest is sha256:63d620c118a8bfb4b9d4344715a648327dcdcbd5d66488ae8c0f25cf63d98671 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: This vulnerability can be mitigated by enabling the OwnerReferencesPermissionEnforcement admission controller, which will prevent any user without delete permissions on an object from modifying the OwnerReferences on that object. Note that this admission controller will apply to all users and object types.