Red Hat Security Advisory: OpenShift Container Platform 4.19.4 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-45337 — golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto CVE-2025-32462 — sudo: LPE via host option
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:57591729017f2dd084857ef7adc7169448fd9f75d93344740843e9a1224f1180_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:a0ea39c694729ff398d886c7f6e25143627af6f2aee0a2192b0f2c6e2b4056d7_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:cc1807d516b392f3f4f173e74876c6c7bfdcc1219684c1dcd338d5175fe322c0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:f81af2f59b9f6cddc6fb09396dafd060c5ca13e3ce7907df1da999928951698e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:0d99e5a0d539deb79d6f0e1449fce77b02c7fdc830dee5d288e1ba1358d8a2ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:258f4921cb712b5d76fc80f87af90ee75957bff520d57b2541d30f8593874dc5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:79e3fb91cbd12e8dae5395b7b7fc38e271d73bf0d1829eb4d30d62470d70b92e_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:f57c930dd9116ec4a42c2490ae689303168679b641c965e414c0dcd95a5621ff_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:409aa8a397b5548c834954fdc0bb9dab2e6763c1047341490a987c08481e2e3f_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:54cf6f7c31e2db14784b77757cd9ece00a1fffe6b77665fffad069c339fe53b6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:739e42cab78d984e90d502f51154472e02da066000682c20d4840fcf1845ac58_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ca13238c488579dfe57897224335fc4b86c04b28b9106f0ecaffe62e761a362c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:1abdee5545f68cbe03b4ca26d270c55b4dc4a0c56b4d88e67782de71a00730bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:3bdba24205fe181ad5f3799f888036a3d752c76b4a43a88345b422ad8253a0c8_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:ac4332de1072718ad42b57d81a994f4f77a29106c45003c18a9f7e07c5d6b09c_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:b7232d7764b5cebfd46fda7820233d6bb46c07115d4bcba44a8ac5f78a5cd63e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:429999903c2683f232cf669e4374601617068e85aa7376acbf6dc8b0a637c800_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:a278f8d0068dfc33dfc6ffc232af4abcc7f96ae1b465054aadd4e4be983a6d85_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:c5e68967d68ae8c5bede944e3275c256370f3f220d30d9a432483dbec0dfb5dd_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:f4809e7d2613563934b0eb34bc38bbf11d245af0cf2ec20c10f126ecfbb755f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:04e97e0d56f7ca1f8d7f9e7507b5c6a8c1786fb058628afe42ac374f3d60ab9a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:b04587e168db89061c68f045ab5190caecf64dd502f39b29c50e7e63b233ea51_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:db9c6bc78a915c18fcdaf27a936223636ad54d5199819ea0361a66da6765adfe_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f4598c66d41dab30dde254378e2a5806ab200d331e482d43a9ffa340a47fceb3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:0d5316d5fbad07567931c5e42bc694349de07b578bbe8cb1784f94e717e1c8db_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:0e8a568a4df5192ae2fc11952cfe724af70e6ba96cf28f357847c3f151cb0da6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:3fc27bcb791ff19fefb5767a69491f4060f6698d7bb0da4757a8786c72c074ce_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:e931f1e243c98091844d7fa99b7da2094259ea80d4515a22c521596057db43f3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/egress-router-cni-rhel9@sha256:3c15afcc7ac3ba4a0a3843d2392262cdf6d3e9f086e82b8b1465c02e69a159df_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8153a8c010b292c0c4ca7d8b4ca13ebeb634d449982c66568764511c736281b8 (For s390x architecture) The image digest is sha256:569887424b27c3330108ffe4b9f67be8fdad8d9ee8b2fb2c8050c8c341796a2f (For ppc64le architecture) The image digest is sha256:b33e97289af82545c8e62fea3f14f3ef0bd85da95de383df7e784bda81ddecfb (For aarch64 architecture) The image digest is sha256:0b702f1a2cf8fab1f29eb615c80dcfa5760e191d9e9f0daa2d1af39057227de5 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: For environments using sudoers files: Remove rules defined in sudoers files that are for any system other than the local system. For environments using LDAP: Use a narrow-scoped search path in the SSSD configuration so rules that don’t apply to a system are not included in the LDAP query results.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2025:10771
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374692
- externalhttps://issues.redhat.com/browse/OCPBUGS-54458
- externalhttps://issues.redhat.com/browse/OCPBUGS-55918
- externalhttps://issues.redhat.com/browse/OCPBUGS-56163
- externalhttps://issues.redhat.com/browse/OCPBUGS-56781
- externalhttps://issues.redhat.com/browse/OCPBUGS-57206
- externalhttps://issues.redhat.com/browse/OCPBUGS-57781
- externalhttps://issues.redhat.com/browse/OCPBUGS-57922
- externalhttps://issues.redhat.com/browse/OCPBUGS-58073
- externalhttps://issues.redhat.com/browse/OCPBUGS-58116
- externalhttps://issues.redhat.com/browse/OCPBUGS-58263
- externalhttps://issues.redhat.com/browse/OCPBUGS-58276
- externalhttps://issues.redhat.com/browse/OCPBUGS-58279
- externalhttps://issues.redhat.com/browse/OCPBUGS-58284
- externalhttps://issues.redhat.com/browse/OCPBUGS-58316
- externalhttps://issues.redhat.com/browse/OCPBUGS-58335
- externalhttps://issues.redhat.com/browse/OCPBUGS-58343
- externalhttps://issues.redhat.com/browse/OCPBUGS-58350
- externalhttps://issues.redhat.com/browse/OCPBUGS-58375
- externalhttps://issues.redhat.com/browse/OCPBUGS-58377
- externalhttps://issues.redhat.com/browse/OCPBUGS-58394
- externalhttps://issues.redhat.com/browse/OCPBUGS-58403
- externalhttps://issues.redhat.com/browse/OCPBUGS-58820
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10771.json