RHSA-2025:0876MediumCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.17.15 bug fix and security update

Published
February 5, 2025
Last Modified
September 6, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-9676 — Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:2bc15f619dbc02bc38481c88fc3e83e1ce1ca8470ce675e8de238402bfd5f144_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:bf3fc67d22c3c8b824a6a08263553b0490df73e4c9d537062a03b2ece4bea765_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:ec6833d93e9d5ee201c08a6ff2c801828eda548d971154bacbcf0d17401b84d4_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:fd0ffacaf24c6f575350d75b5d6067e6dcd346e95e842880c185de415fb0f5a5_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:116ee60b96abf67e538eaf795224d43361176fe68625e1f076e1915bfdff4c13_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:999134ce2dd037cf3b983deacccd0a97e74aa7a5ff91970f0ded8a85494416c6_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:b09f830d2a682385a7739ca4fd016858342cae6eac7c1e41a6f4df73c619d04d_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:da33bb61a1280044c72e3a519ff66dae6405183682efba649f16ee3cae6a0d46_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:138756348aa04d427d5c302049caadd471b34a53ff24bf57c6ec51b9f648e5db_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:1581ba725888ef5bd131e89b38a8a6bdb6ae899c4fb9657b7f8fb3f52fc73f50_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:2a755b02df8d8ca9b4158250582c8ee9787ef6458149b944066245d0045d6467_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:46fa869f363a6fdbd078c6082206619590dff94a0e94bd4198dd13caf301bb39_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:435d614ef9b938b1989c9ec4adf8b89697b48ab2e50b582c943f30afc54d9b1c_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:ce40589124710ba86be648fb8c252fb135415c2d360cd59308da5c28b4e153c7_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:d71450a23932dcbe3446e5bdf5929c5dd53774215f84701d808f68b28ed7169f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:eb718d31242d77200357476dacd3038e8df1c5f81d58e24ff6cdfd0a59918b66_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:4f0a7b470e3fae166dbd06622a1e37bba6c97ea332e43cfb86bdbd9279099ef8_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:8ba13e17387519b4e4c152bd44fd861f9e7a1c0e71de964779388bd970c201d4_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:cc74b1e8234328cd8e5a8c59baf756119f6fdbd91bd8675a4287638911070f86_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:ffc7682846d663106e2851e01b328aeb7a1c31b9db93db53e8f3b43b76767587_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:986d46074c2816711695bec19098023983cb0c45611c11a84895fca113e4b36f_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:b050d46b7468b3bc933381c69f7364c0cba89cbb379f6182284682624547d782_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:d36278815d41a7f97b10ba18b81f8eb3b4a07b91a9134c21831d4d67fd59e18a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:d8dbc3434eb034b35e1e2d2d6833ea162ad4e92a57e04f187fd3eb4a7a71c2a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:0eadbbb45f407e6725aab4e21abe8bf5d9f20c18f0383a380e3e53206116f04c_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:63f52639b94bc1f9af09648be2f2e7b7c422d83b0068e0f7c57d058ff045bd99_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:968a62580f5051f1140337f9e937687dbf0adca55ea15dabf9a3eb9e1bce83c1_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:9d18b1b45fe2419ac9a72065ae31a966dba25f71ab91aa70394ee563d0db147e_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-metrics-server-rhel9@sha256:931763b2db9de1b9aadcd2be40ae68db4eb10d67d6f2b130f2a889400e4b61dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:68ffa083a5ab473d9fd87cedcb01c6f27740aad92de0ee39a7ac408da9a65857 (For s390x architecture) The image digest is sha256:846ebc62ab2f2f449260b34d16a40f070c43b29a4d79455796e8aa700453dc97 (For ppc64le architecture) The image digest is sha256:1176732e9041adc188c006da5e3bb77cf7b90c5fd85ee6ab0390c91cbf8a7e0c (For aarch64 architecture) The image digest is sha256:1a6db02e197341338e207a850b4a12cf2ab3e1e4fda8ed72b563051e57b4a8fa All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking.

🔗 References (18)