Red Hat Security Advisory: OpenShift Container Platform 4.14.45 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-6597 — python: Path traversal on tempfile.TemporaryDirectory CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:1dd24dcce9f3636b75ba3bb56f40d1fa0e071f1992184b93b734a89312e692ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:6145e96114278e18a9e0ff02883235a5b4a629583f41dc15a8e1e6b0b7edfdc9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:658761f90c73be117b950e5a9e23b05c26c9214987589f79219f13294d7f6900_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:93e32ff80f810f6bb59bfc67933d9b8fe3e6c04f13abd46061da03816760ef0b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:0644b64609889bd7a8724c65c4a55fc4923f92639db4e7e328778bfca39bdd7a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:528abf5f87fd1f4fbb1e4c1de547b5725bfa548de7455de5e21c426a69a9f5f7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:54bade1577f8046d3de1fc34dad783588d23b2a05350515e9ad1c0658152c4a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:aa8e41c9f74fe69114e4eb8ae36c38ddd7bb8471f2645a907b5c9788a83c302e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:0104fc912ea6b7c1e1d37f3a27fb18dab3902b3ff89d103000237bd77b1e820d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:59226a6c53de3a971bc6ab0c918ae6bfc5489da94a1cc97d0d3ecba33af13db1_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:830d50ffa85bccffdc723bc9161f8a447d803fac5358c2f0a5415e1f0623293c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:c692f689ab195b8d09532402ebb3cfd1d42bea8a7a1c093e4b9fd70f24962e26_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:5353bbd3883ad508dbc7c7db09d7cbb35ae0dc4aba881cc7608f8ee996037a35_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:612a887794cbd398159f6b3ae46a3267b0e2750d5fdc08550e98e4e9a82d6ee9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:a00603b558575be11b8c49828e44084f481983c1d028a8dff10ab1c64a93e25e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:c4d23443bd0e6c77bbbd1d9e979008b15562d71553b5a49b29b39f3f1000db9a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:4167aab97dd3418022adb2bcef62b681336c3f50baafb4da7de1659b0faba686_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:4f5cce5725828a4a005b6c64e05142df98afb69181b739e326f7fcf5020647a7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:6d06eebeab225d8775cf09d4b857e71b1ec19ca943c6b4f48e5b3e7de69bf031_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:cbe1b2c8210cef90ecb23e2729df0c57372da6fea66fca273cc0904916d6d011_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:5bdf3b86649dd3c75b38e4a091af09a6bb5e400cde57d728decbca004a1ba119_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:7894310bd3958c0c719fb787c71e3e9971083cc0eaca99807aa1a563413cb75b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:d09e186fd142fedd04746d32cacebfa1e8337d03cb141b440f98384d6635b2dd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:dcb05e3ae097be5ea98c24d708fc9e332f4db5bd1e754485c91c8dff466e23db_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:2a1b177b6c0c5c2cdb929a3e743196025c78339fa1a4109252de956ccdc1056d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:a73fabc7f5d65c63eff5519f4f9ae822cf750f6f170158ece777e0e8748a060c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:ab18ba3438adef9a9355bb4f999b22b889e35decbe39bc2e80b3ab84b5c5e9d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:cecd8eab0fc71f9ec0ad1c463af58dd544427c31cef6a1ea1f2ef439da8708f5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:70e132639755b6b37395eb5fa34e2dcbb3c914d37b3dc5532a9f908e95fc888d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:725dc741c44b151b8b39ee3b2c7bd8364f1082c39c313de6d0579df001069fdb (For s390x architecture) The image digest is sha256:335cf0afdb38321f745da3b15336c7f6ba5c13908022351ec9648f1e16aaf6e5 (For ppc64le architecture) The image digest is sha256:5c2c6faeb9155a97935c1ec0e6f74c86f3a04022d1a242f02c62dc1f75fb1778 (For aarch64 architecture) The image digest is sha256:3628e6a5b4321b577b347adaf539502e3d04d02ca4f95f4901f67aef60f2df70 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2025:0364
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2276518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://issues.redhat.com/browse/OCPBUGS-42754
- externalhttps://issues.redhat.com/browse/OCPBUGS-43670
- externalhttps://issues.redhat.com/browse/OCPBUGS-45323
- externalhttps://issues.redhat.com/browse/OCPBUGS-47659
- externalhttps://issues.redhat.com/browse/OCPBUGS-47757
- externalhttps://issues.redhat.com/browse/OCPBUGS-48058
- externalhttps://issues.redhat.com/browse/OCPBUGS-48160
- externalhttps://issues.redhat.com/browse/OCPBUGS-48208
- externalhttps://issues.redhat.com/browse/OCPBUGS-48211
- externalhttps://issues.redhat.com/browse/OCPBUGS-48245
- externalhttps://issues.redhat.com/browse/OCPBUGS-48339
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0364.json