Red Hat Security Advisory: OpenShift Container Platform 4.15.44 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-6597 — python: Path traversal on tempfile.TemporaryDirectory CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:2ae7f43de8a29e39a978e3e5d5bc07795aeb4cb89322beaa5c894def7dd5fbdc_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:ba073cd76645c8d54808a04b4e9b960b3069797f11b7503b07e618cf6962a68f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:e4d83cfa02962d9e6bba318a6a226f35daa73a3776c0c88311615e2e26e1f9c2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:fd81b60bd4a6bf3a8ac9fc24cd6b2035f365bf9020e361142b0bf7941d5cdfd8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:47a1dce8ff67d2108362e77b212b48e314e3b710c6d3831c7e30cda2018b1190_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:7d7ee75447779de87808f2fa125d1842e981d8c5e7bb9d44b89d8afdb1c7c103_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:dc11e2bc91f4c0d70f202b34224ecf3da1652eb3c0563e4e4f9d0967a8c5321b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:fc0537905c0c98581f1779858c1716ab056f2462b4214bd04fa1acb5f95e1d55_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:0781547566c253acd49a35bdaf4bdd89d33c07ec804b3379e89b2f5cbdc916ce_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:145a5e65cfecda8783e83157d75725eeda5c0024c56a5c813b2653c3e0cbc300_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:c387f86c84b9bf3b711b2ebde5c449354ec5f9cede4c8db6211319f8dcdb7e09_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:fe58eae1604dc567b3c9b22a4df3ef9f0cbb666c7e95eb15da1f1a92e5da883d_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:1e45ffbebea14a1aaeeabea856e4337b3eedc38d9281e2ac8cc0ec33d75ae6a2_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:6b68a4af68954611f50365a7013822aab866f765b22adc1aab3a66f0219b26bd_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:98d65e3181d5a0ec875ea0348e3d363f22492082f3c1c46fdb27440385bbd9e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:c2c57c95d20a4e40f140287d1b2a6c59d719f4b32d8ad44bf7496aa4bbc1d427_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:07251e2511c41d83f5e1d970f61b9e78994b1bb19f8e4d8b94abf201879f47ad_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:0c20ecfcbaabbb06d28ef39a20d796df0e49a591453041db23aa22c418f038f1_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:97706454e47e688da3dbf43b2b6f7d81eca46621cef28ecc0b597ba96f6e22d4_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:b3061b739bd6de2092bb0cce57ac8b2e83c5647115ead1e24846efec20b9f0b6_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:388d9b0547a8d00e46b1ce7f1f81e627f8a9e073ad9493af35155c9ee87a2a79_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:8b8afdc0992e8a49fb5be4c3cb35add90144c189b294b2929b11efa2fd151167_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:b0f0ffe3cb31f033701e71a1d2a92ef8359226a02e9c8db82c7fc892a78ad89d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:e55890a2686c0d63694a43644a123583e8ed4b84212b050f21508ae1a876c437_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:0ef30edd078015203d6b44fc9cba884f9cd52512a81e2a6ea65a2ec4698cec71_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:9dd2890729bb07aa1ee4ac985e2d4b6721c33918661090e71b535882c0f90241_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:dfbfb58d0f1ce14ceb6e16af7cef57e49bc23de55856a528d87df025fc080fd9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:ff7882626f4f6996f55d1a12c6f77520df92f924a9776f7a8fe2798fda8ecbd2_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:2205cdcf1fd4ee4dc2969f2b01a98012cea34dfc381059e8c8f6c40998884625_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:a42b52fe6d1521debfab6aa72fdbce79b9077bb8fdc6392608d07f1f5dbed3cb (For s390x architecture) The image digest is sha256:e87f6b03f0810fe7bd5144d1368b67bae097704846ba5bcd8870cff45a32ffda (For ppc64le architecture) The image digest is sha256:6696e1de988f8f2e6b11c68545ec39086fe996a468f632c26098294f3a9f7754 (For aarch64 architecture) The image digest is sha256:49a6d2b6dba439b2bb8cc356d790a4df371985f0f3fefa2a23bf519b3520e46a All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2025:0646
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2276518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://issues.redhat.com/browse/OCPBUGS-36247
- externalhttps://issues.redhat.com/browse/OCPBUGS-44259
- externalhttps://issues.redhat.com/browse/OCPBUGS-44708
- externalhttps://issues.redhat.com/browse/OCPBUGS-46389
- externalhttps://issues.redhat.com/browse/OCPBUGS-47633
- externalhttps://issues.redhat.com/browse/OCPBUGS-47756
- externalhttps://issues.redhat.com/browse/OCPBUGS-47799
- externalhttps://issues.redhat.com/browse/OCPBUGS-48048
- externalhttps://issues.redhat.com/browse/OCPBUGS-48062
- externalhttps://issues.redhat.com/browse/OCPBUGS-48207
- externalhttps://issues.redhat.com/browse/OCPBUGS-48280
- externalhttps://issues.redhat.com/browse/OCPBUGS-48281
- externalhttps://issues.redhat.com/browse/OCPBUGS-48298
- externalhttps://issues.redhat.com/browse/OCPBUGS-48545
- externalhttps://issues.redhat.com/browse/OCPBUGS-48551
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0646.json