RHEA-2026:0129MediumCVSS 6.4

Red Hat Enhancement Advisory: OpenShift Virtualization 4.17.39 Images

Published
January 6, 2026
Last Modified
August 1, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

🎯 Affected products105

  • CNV 4.17 for RHEL 9
  • container-native-virtualization/aaq-controller-rhel9@sha256:10b4afa9c56b108d28e1c6dfffe65511838a1b99b24cee2e73c4e489105995c5_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/aaq-controller-rhel9@sha256:88f449f05a4a073eeedf3a512a110fbef569820f589994bb6face481fa86109c_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/aaq-operator-rhel9@sha256:452fe6ff8db170a38e5d31f0aabcff0be22b44654eb7467c43854c3cc3f3f07c_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/aaq-operator-rhel9@sha256:b8d22e070f65537aa5087b8490fa0249168f51aeb3b55e8ef13c03fa06fb0e3b_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/aaq-server-rhel9@sha256:4b2b4fa842868d94e286c55340b7ce7384ea119898354368e709a39c85012586_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/aaq-server-rhel9@sha256:d97d38cb82de0ec949695181ffbbace1bacb6393adbf0578dabd230684b5921d_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:39c76f819b7add59a47f24d3a53adf6a7b59740f495e534ad280d5bb7f10b2ad_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:ed04f875b398ce342b526e219967ff06ce100a6fb81346f6bf8b07e51f5a6f45_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:6b702c28ce6d752d9cedab29fbb55714ebfb62cd6820aedeca1ae76e3ffd9e47_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:cb48e3ab57e3429a4ff65b5e96bf2303e6bb8c0108f38d81b5ce0e98e9784027_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:509b456a2667afafd1a0c894f6ceef7f98f94bb35a46502249b8b11be5c62f23_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:a00f262e33ad99e48613a4d20598f7cd8afc67278a4f2793106b3927b0101134_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:97e7758f9d1278879d80f2d4761c1d7f42b9bae8c0c998fd4fb1dae3adebf406_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:d683c12c2d2800ea21c8c44eeb89c874e9b5ae1c2f9a1c0e4273e3c0163bfe78_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:64d80218b4b0288a7517b8cf6eda5f1370bdf5929ac72e6cd61a2395d6394fce_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:e8756a0d3c741bee5483cd1aa99ba00d41693768db8ce0f008f467906bbb527c_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:0ebece62d3e3cddc5a2c43949435c88ad106ca6e34b9e22b4d6bc1af918f76c5_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:db799980b29d12951956c32e448faa49fd866bdfbadffd2444e63f4a7cfe7c96_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:58aab1dfa183eae04330672e3eef0115c9849bd803a467c7f30eee56004320c5_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:e60ef389e8c9b3d42649b09ad63e16935a9dea3ba3039a5c32a21dfe64deb459_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:6c1da1edaadd17b93071411112ff34ded19009c64f81a39f8b5f350126af1224_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:b39407227f22a5b2286685cc6906551e0fb06f0d57862bb08840ca5a2e4d4f2f_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:0fecac587277983a305a3f558d3fac1f9bafbcccc2fdae539a97497254e26530_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:aec7a92f29e5bc5f94f5891b3b84e2e361111a1f389aac296492353510bf279e_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:3de569acdbae4cdac35d49236e4cd7cc4dfdcfa7c782df980f809a376d8c47a6_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:abc7bb44480d89b9d680dbf8dcd1320b18a677c13811d9783f08a758484f38af_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:789a45ba9e79e80f1920b6a774d0f6921bd46003e94e17cc9ac1cc4a9e319e9c_arm64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:fd00bc88c2045c622b943bcd1d46f59499431c332bb9be2c7ee200a63c802eaa_amd64 as a component of CNV 4.17 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:04248c1934ee8d9f54d8352fe3fd81787280ad8401999f0efa569d817b4d73a9_arm64 as a component of CNV 4.17 for RHEL 9
  • +75 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.

🔗 References (2)