Red Hat Security Advisory: OpenShift Container Platform 4.16.44 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http CVE-2025-32462 — sudo: LPE via host option
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:5b64b353def8b3c264fed8b2692ceb0899873bbc627e2b33065ce9f70a5b8280_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:92456a019ff19151174a7ad5bb63daf7ffaec50f8e6b5a7fbc2391db9cf9af65_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:9f06cd4cac54618a45400350dfc6b7565ef1cca595fa50157117954d0b937669_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:cd6bcb95bd641cec458ce7b57d30424434336699b5059a5cc536e4967204cada_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:8dc1c2d003b3efd3c9de2c5c4face2297ee12e897d2a77e524078c1bef0b45c8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:a13492c1547d8b75610b69c213e596d0df52eb9073a1ab6b6d0c137337d0443c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:d98364c3cee73468e7953071de0b6f7f05ac285f7e392e5aa474d8cf58bc8862_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ecbc2eae15da4039aa2c84261b8c47e402f79d33b31b0c3eaa376e15f3cf3d96_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:13dd4f0cdc056c9f2e855a4baa3bae7be37cc93b8152ffdac834758c58770d73_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:2711d5065950105508329ae9eae4038763589d497f29956971619105277c3b54_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:3acf8deca26857a75054c63ef545d08b3e098f50ea8b6f7b9890dceb22e9d8f3_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:d2939900c77d11a893b214423364595136d3f024e775097b19850266c82b4933_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3bc4537dbcabed71b6a03851ae13d2930b39bb7febc3a0efb5122bced82ffd59_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:aa3fec0f0c13a959c37c9f8799ce35e7f9de7935aebfb7fd116bd9b56686a953_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:bf182fb0d73983ae9f5912ede4ed7f4c0f3c2431f7b028b6d31f4552af46c82a_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:e2c1f99578b138301f9bc0a419236c0f38740b44edd95415b0a5593aa63922f2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:3d67fca805e81eb6f182c8697fdaf9a0cb402fd63a985f6dd69365e948b29608_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:69a06ebc8e85e0059c96be333acc3e0e5bc52c9a2a7bf0b3bfdd1e93d77c7071_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:9881e793350553650f2ca3542ec58ab7212bcc6f1af2088caaef86a1da3796fd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:dca8961dd0b01d0af4d96b1a03c15a156da8b290d80948351543b15b57a254fd_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:0a946efb5bb41d9ba5cabd33a8980ea231391120e42d941c035180bbb8e592e9_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:3abc92ddcb078ad38ae1642e4c70e1765c7fe3ad249487861a153b4a4c51d886_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:967691c9b846e43fc3b87ad2e326f068d9823f059142306d090c5cb4dee7206a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:c961cb499c5522b9c802e13299b10a81e15bfb3e7e7f6e3478706353e95e4d4a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:1553f83ce13116f2f701cdd904faaa05b727980a8e95e69e79b68a91cd85c4f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:435bfd48f7d9a4b877ffe324b107cbf1706f6101094f39deecdd959c784b01f5_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:b0c06dd47bd1defca57e2677fce108d82d4e326b2b06eda1dd0b46609df0d7c7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:f1dcfe223e87009149d1cad8983ab3d17cf9f51b15e17ee37271e4772187c267_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:3cca698bd1ba42da63ea6601c57efe2f26e99e944987d0871859c7252a3dbb1f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f41be65a929742f584bb4299dfa48135b093b3cc86dc76c3ab77265574bdd4fe (For s390x architecture) The image digest is sha256:1fb74752e79c7fc248548dd16c60820c3ef2a7350782bbd6aec452e63f4ba9c2 (For ppc64le architecture) The image digest is sha256:e3e5c701997d1e3294405f9d21e90d8ebb977e05ec99efd30d9613df93c6013f (For aarch64 architecture) The image digest is sha256:27dfa2840fce419526d7162992920367c4ae05b3a2a8ca412649fda4ff1de980 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: For environments using sudoers files: Remove rules defined in sudoers files that are for any system other than the local system. For environments using LDAP: Use a narrow-scoped search path in the SSSD configuration so rules that don’t apply to a system are not included in the LDAP query results.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2025:10781
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374692
- externalhttps://issues.redhat.com/browse/OCPBUGS-32934
- externalhttps://issues.redhat.com/browse/OCPBUGS-55807
- externalhttps://issues.redhat.com/browse/OCPBUGS-56424
- externalhttps://issues.redhat.com/browse/OCPBUGS-57396
- externalhttps://issues.redhat.com/browse/OCPBUGS-57460
- externalhttps://issues.redhat.com/browse/OCPBUGS-57498
- externalhttps://issues.redhat.com/browse/OCPBUGS-58054
- externalhttps://issues.redhat.com/browse/OCPBUGS-58188
- externalhttps://issues.redhat.com/browse/OCPBUGS-58270
- externalhttps://issues.redhat.com/browse/OCPBUGS-58432
- externalhttps://issues.redhat.com/browse/OCPBUGS-58505
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10781.json