RHSA-2025:0115HighCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.17.12 bug fix and security update

Published
January 14, 2025
Last Modified
September 17, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-21626 — runc: file descriptor leak CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-50312 — GraphQL: Information Disclosure via GraphQL Introspection in OpenShift

🎯 Affected products81

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:46f73534bbb01dce1664e9fdf6855d41d3c3ed34029ac41026bb96f847b22de9_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:5212e02d762ebafe58ca2c73337d63eaf3e12698d3f7adb82dc081162c0a811c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:7511eb430c24855fe97ed963aed687b825e82c75d56c8856fda6923b35dcb23d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:d02412b15aa52c1cab70939212bc876cde131d8c0b221cd0bf9250f75fb2ddeb_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:726b429fe3490ab1a958cbba71f7b3a46d02b1fe54ffb5a70e5604a9a42e8f3b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:89882be3b40bd56f4758745d5ab5e91c489539dd60adc7ef906fd20a206b1075_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:cdda6abfeb0a9095177f60ea7b75db62b43af28de0d869e34e25050b8592ce7e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:e92db6450b2ac2cf37b6003eb690b74acd37c469b2fa97780ef86a9696913ff9_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:097c4e17ef4525e913b1b90161bea683895452fa338424e8add3aa3b71b674e9_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:15236fc08fa6bdf401175d9a898831684a0c5cb4058911425d8425a01a13c617_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:88338dd223edf215c26fa8acc77686e36709450d5d0372dfadd514d8fbab894f_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:c27928620dc56e0810301fc82ad619e4b9976bf601d48ce17eadf0c6321b57fe_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:49b3b961e2d80346432439605fcc81e10d5314dd86338dfb6cf67f39b2f7b5fe_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:6893734a11a3bdd5a46b285843e9b5a9c09b0b2d234654f946d5dc1291decc58_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:802e1ca56ee809f76f2ce5d926389ab72469d63d91515dc5b04383f3a47c5a15_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:da26422197147727aa35a92897237db53b7c8b1189c9804f0ea2417fa6ce77bd_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:139310acbf21f93759ccc8eefc384f8f487a75ecad99e3fb1160c3713f1d607c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:3ead532eec6f93f3b1e34d3144d669f1136132f7eb129ad25a0f6519012ac13a_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:3f69f30a2aea7bd89d21ef586d9a9033148dd79eb594241e29f339fd28810a31_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:ea5edc24bb8b9d2239bd7e33c89bbd7c76fc11e468ecb8a9feb4d122a5dd7ded_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:81207f1e27b22128634f0d63b62c36fe8e844067ac2d7894639a3e763cc1fe74_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:92faf8240c18dd8997a573204b5bf78a4e323c91775e6da37dfd8db5eadfa276_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:9aa04ebf5c9f8f772c50659b30b643cb5e100b26d713e048507e5e17319df46a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:a069d06d21386f150dc32e9adaad28da4069f924e685725158b62958d30c1e01_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-console-rhel9-operator@sha256:12c6cb48f15d58d2564a1a4140861ca7c1dcda1ded9924c4779486556731fbaa_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-console-rhel9-operator@sha256:2a8ded36de613a93c2980bf9859c7bd575d4f7105ae3e9d62db3e5b75d8c8e93_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-console-rhel9-operator@sha256:52255a9fee1486e0908c1f64187d421ffe07dd9a2c7b63d5be529ded2833e5ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-console-rhel9-operator@sha256:86ee4f1e2f565605880a38c01a594b9d50d485e7a1c3a986c7ead94028b699e0_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-console-rhel9@sha256:4224497544a6beac95ff098178b0f8611c353254a495324f59112d74d865d9b8_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • +51 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7b39e1a5a98fa5bda517f3a1800c4bc96838fdc8318036d1b0cc519fa3534690 (For s390x architecture) The image digest is sha256:c8f6db9b700aed437a869d28c3e657159fd882d51e50d4412b0ab33ffcb42309 (For ppc64le architecture) The image digest is sha256:f8fb1c6cd43b8f88ee7fff5870d0be047a2e3d6d7c3d5de1b4f5c56e414fd339 (For aarch64 architecture) The image digest is sha256:cd432819f6123ea6430afeb3bb6291deb691935c5e563bcd65f11a9237ce1328 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks. Workaround: GraphQL Introspection should be disabled. Users should not have the ability to view all available queries, mutations, and data types.

🔗 References (15)