Red Hat Security Advisory: OpenShift Container Platform 4.17.35 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-45497 — openshift-api: openshift-controller-manager/build: Build Process in OpenShift Allows Overwriting of Node Pull Credentials CVE-2025-4802 — glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:52374b3dd320efe68d4b5d97990734acd6b1a8e0a7824a923e03465dd6d23f66_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:56ab85f1c595db9d4ac1375c96935bf3ef85b46f2113144a55723ded96818aed_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:89479f45d01fc6b7d00c124e6646e01972a0ded7dca769b121c8b068f7d8c266_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:966a9c5c8050c09f340a97e46ee4f491918f28cee5bd339b4d14343c03085455_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:2fe4c07605d1f8c75356e0591a5ebec3c20fddafcfd8948ebf1cd4e6c9142cbe_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:922c226ab2d95d0e39d14d8fd158779f0c2fdadbb1712b21a7b075e96711262b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9ca173482336a370647f33ac43c0d3df39a8eedcf112677af98176dddff8760d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:b8fed86ec445de9dea16800ff43d33c4ba19625fd0199fec8d39c280f09528bc_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:31a8da677554a3e50859424f157229c6e9f6bffccf5d921258394c9b5fe3a1f4_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:73a2d35963c335acdeb16dd45510216a3691b80c1c5daa6ea1d94c27e268b747_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:f656f6578a80cc2e0eae0a1c22471392051a8c953d68c6abd948259b39c62860_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:f8990c0eb70b0e8a291a112f5940293b460f26a48c8494f868523eb2ffe9765a_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:1a119ea9fc7b656835be8584108adc24dcbda753010fc6dc389e63cda4a3ac41_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:4342d5f1954a973a114bc32cd2052376cb4007589119e49097372ecb8f61a9d0_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:4f2c7777dd23a4fb6c654020261fb0fb2dee727e42dce6848a6274b08283e31b_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:73b0c953f07fe87b92a1596d72c3ae53909b0eca63324ca7bcf370dadeef3e06_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:907687bd973531aa5bc51a41dbec7a8299669d96919af1ed6e3a79759979fcac_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:9efc46bfc0886a6d04cc0e93ab51bbd13665b5d62ebd3f2ad2cfd72584510589_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:af91be0542c3caa8bf789b95643393b73721d4aa07649632b42ea1e6e9f71c77_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:b93fbf0435e55d2d270798e93a19fc3b17a35beb3214c0fc3ee55bc473a1d28f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:111a61c1baa6091c50246513b8a3cd286a28677277c2720ce03add0cdbc3df5b_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:3568817f6d55a7e4d71c2f81c047a66bb5218f6df4b6927563a0d31f61693131_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:9eeb22c61668501747c795b945d6482f77a7ef97b75ba63ecb9c4cd9d0f4d74c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:fd7f818aa57c56568f9856cff79195fdd80d21a05166509136c75fbd1de88834_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:2cff0b721a305eefb1542554b9e66e152ff27a5a52850479f8c58e80c56199e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:94db3ed28f09716604673acbb8d516285663effc677a39c52d1cc69e74d8d474_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:e95eef56abbac9c088aff0a09fc4fbe7b6df12080fb76807e45df5627dd5ca18_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:f26c953a23e8ab87a48fc4223bc1c7d2c668da6b1af00bf9d5ea5f91df32727f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:0960871f727449af29079aae4e44f4da1de6dcc541e59be5982f6b59cb232605_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:20bf36ab093f1da58dc9662f6cd132803babe641b7471553d2cd6a929bdfc946 (For s390x architecture) The image digest is sha256:dfef87cb5d0e6d86c4d1fdcbc10711625b621ea4b9b2ae1a9dbbb211197e1f46 (For ppc64le architecture) The image digest is sha256:395d04f9b79b09b2fbd7377f25ef927b81da984095aaf39d285206b451a1b683 (For aarch64 architecture) The image digest is sha256:c747886ef9befb315b20c99f29a39b10cbd07684a874aee15a5e777aaae50442 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2025:10294
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367468
- externalhttps://issues.redhat.com/browse/OCPBUGS-49702
- externalhttps://issues.redhat.com/browse/OCPBUGS-55021
- externalhttps://issues.redhat.com/browse/OCPBUGS-55518
- externalhttps://issues.redhat.com/browse/OCPBUGS-55723
- externalhttps://issues.redhat.com/browse/OCPBUGS-57107
- externalhttps://issues.redhat.com/browse/OCPBUGS-57182
- externalhttps://issues.redhat.com/browse/OCPBUGS-57196
- externalhttps://issues.redhat.com/browse/OCPBUGS-57289
- externalhttps://issues.redhat.com/browse/OCPBUGS-57293
- externalhttps://issues.redhat.com/browse/OCPBUGS-57446
- externalhttps://issues.redhat.com/browse/OCPBUGS-57932
- externalhttps://issues.redhat.com/browse/OCPBUGS-58091
- externalhttps://issues.redhat.com/browse/OCPBUGS-58218
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10294.json