Red Hat Security Advisory: OpenShift Container Platform 4.18.20 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http CVE-2025-32462 — sudo: LPE via host option
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:0080d4a255167ebf17499d3ae6ed1e58bd67ad94fa1816fbf6f41b0ee9e045cb_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1b08a2c409dc3d9dd3011c690409cc4a581b6e79e131a2952e579f58096aa224_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:a4e97661fc95e862f4caca8875e52254e0cc163dbe3abe2f513b3903faab6594_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:fa37eac690d12110d79543ba796441e5efec2bc7ce34b4eb23895aa37c3be14c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:1893e933767941b3e24d95da432a41eb093e02b2be599f775e2227956986efa9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:455312fbbda63deead56b7c19f590f01531b812bb00c94e0b356effa7bae5031_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ce768767f84068dccbc99b72ebbb18a87307d779388bf3623376e4aa62e9e44a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:db0d2cc89eb47c622d8ba8ac445f0a3b06877f01f7591c23d6ee6c88157657f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:976874ced90729a0d3a8115918509097b10d9fb9ed13061d4f0beb893f7f36b9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:99664a834524fa40053774fee97375b583a3f37dd5c2f768bb4695adf69f4a07_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:a389f92d8e1ce22b8191ca18cbc7cf497d9aa338430346b1b0ddb0328642771a_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:af991aeaba688c5df9b10cebfc9da9607c2101a5da15e7e075ffa8c2bca0f42a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:55006d860ec96e7056fe89a389d925e18d65eb419cd6ce830ea783f3598d6b75_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:5d1192db7d3939d3d774081791a377567561ec6667f984d351d520422ab755ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:acc7ee37e3f7919f0e1e503b73793983efa052080a3e68973a6abdd14e230a21_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:e2c81d7217030c51e60a0fc80b37e23b56720a169784f7bcea7ed230723b742b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:2617a7b8d90c4e6ed1b3608bd1d23e8103bcf0003e8ce76362bde734a50c4893_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:5e383985a94ae7736d8ac308632dd4000c5298ff6b7996f1e9b98e21a404fda4_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:8ec10db8e227598d3c2a2271490a9220ff71e1240fc20e9355866bd1519b24d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:de83af5706eb857b6f404486f973768c38e00815a9a5fd75968d166bf3a7d75d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:178febf2c4e882715dcaa441cd5e2c6f4685bd1347c29e500a80648fb3bf79fc_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:263ca4501543db3c9cb813260777bbfca09fd47422c0efd9f5ca35abc74e0870_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:9839e3f9eaf84fc96500995c06eefdfad1cefcd506419e6d384164aec79f91a7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:c2d9a355cab029f51ac7d0a1f179877f143133e0d842934786e57f1cf866a997_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:75ae3cae747eeed781af7934c65e62cf3e965993b3748c48cb757b340c6903ed_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:8bbc67976b1243199c371bb63bc05b07cfddcc2520928a12391064e6de66f44e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:a7ca7c4f8cd92d9d9570163f97a448139161d13879951f27d8b7a01fa69ab65a_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:f243e00288ed450085fe54ef93a6636848866fab7b645b8d12edfbf3cf749de2_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:1aed888175b9d3cf25d4a6d9f22688151dc3e8676b456998f399de4aa6adcd53_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5e06105a6ba80d04eb5d8d3f9a672fb743ce4710876d99a375c2d9f7b7eaa783 (For s390x architecture) The image digest is sha256:2771caf2e2feb31b09ba8c940df42c16b98aceb455156fdf247025ae80e169ab (For ppc64le architecture) The image digest is sha256:1e7c7b5eb1d96ce6c285f292ffbe1a7a757c99ea4ad2945a05723bb95c2b591e (For aarch64 architecture) The image digest is sha256:399af8a368f954b6804c3d76d0553eed55435f123a5e362d03b3f5c6aff262ac All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: For environments using sudoers files: Remove rules defined in sudoers files that are for any system other than the local system. For environments using LDAP: Use a narrow-scoped search path in the SSSD configuration so rules that don’t apply to a system are not included in the LDAP query results.
🔗 References (45)
- selfhttps://access.redhat.com/errata/RHSA-2025:10767
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374692
- externalhttps://issues.redhat.com/browse/OCPBUGS-43939
- externalhttps://issues.redhat.com/browse/OCPBUGS-46401
- externalhttps://issues.redhat.com/browse/OCPBUGS-46629
- externalhttps://issues.redhat.com/browse/OCPBUGS-47495
- externalhttps://issues.redhat.com/browse/OCPBUGS-54744
- externalhttps://issues.redhat.com/browse/OCPBUGS-55246
- externalhttps://issues.redhat.com/browse/OCPBUGS-55297
- externalhttps://issues.redhat.com/browse/OCPBUGS-56434
- externalhttps://issues.redhat.com/browse/OCPBUGS-56609
- externalhttps://issues.redhat.com/browse/OCPBUGS-56624
- externalhttps://issues.redhat.com/browse/OCPBUGS-56928
- externalhttps://issues.redhat.com/browse/OCPBUGS-57037
- externalhttps://issues.redhat.com/browse/OCPBUGS-57070
- externalhttps://issues.redhat.com/browse/OCPBUGS-57124
- externalhttps://issues.redhat.com/browse/OCPBUGS-57197
- externalhttps://issues.redhat.com/browse/OCPBUGS-57213
- externalhttps://issues.redhat.com/browse/OCPBUGS-57286
- externalhttps://issues.redhat.com/browse/OCPBUGS-57318
- externalhttps://issues.redhat.com/browse/OCPBUGS-57328
- externalhttps://issues.redhat.com/browse/OCPBUGS-57427
- externalhttps://issues.redhat.com/browse/OCPBUGS-57767
- externalhttps://issues.redhat.com/browse/OCPBUGS-57818
- externalhttps://issues.redhat.com/browse/OCPBUGS-57931
- externalhttps://issues.redhat.com/browse/OCPBUGS-57935
- externalhttps://issues.redhat.com/browse/OCPBUGS-57947
- externalhttps://issues.redhat.com/browse/OCPBUGS-57964
- externalhttps://issues.redhat.com/browse/OCPBUGS-57970
- externalhttps://issues.redhat.com/browse/OCPBUGS-58044
- externalhttps://issues.redhat.com/browse/OCPBUGS-58067
- externalhttps://issues.redhat.com/browse/OCPBUGS-58088
- externalhttps://issues.redhat.com/browse/OCPBUGS-58095
- externalhttps://issues.redhat.com/browse/OCPBUGS-58126
- externalhttps://issues.redhat.com/browse/OCPBUGS-58135
- externalhttps://issues.redhat.com/browse/OCPBUGS-58159
- externalhttps://issues.redhat.com/browse/OCPBUGS-58233
- externalhttps://issues.redhat.com/browse/OCPBUGS-58264
- externalhttps://issues.redhat.com/browse/OCPBUGS-58312
- externalhttps://issues.redhat.com/browse/OCPBUGS-58317
- externalhttps://issues.redhat.com/browse/OCPBUGS-58321
- externalhttps://issues.redhat.com/browse/OCPBUGS-58346
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10767.json