Red Hat Security Advisory: OpenShift Container Platform 4.17.16 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-6597 — python: Path traversal on tempfile.TemporaryDirectory CVE-2024-8508 — unbound: Unbounded name compression could lead to Denial of Service CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
🎯 Affected products89
- Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:1c5f6352386f918c5c1ff2cbff522290448a996c6960f815095a6b0fb8f626ff_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:36749d17c557f39f84c9b6120246cd55f4c2177948778fb941b6ffbc599f4c4a_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:38b401bc3a125738b5382e90b4132c2ac1b028fcf8e2db7bc64a7741de126e67_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:955140a0fa118143982ee43ff2eee71cc413a4bf74a7c2892f1c524e63048058_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/network-tools-rhel9@sha256:1198b8be4dc5d2a85553e355b0a8e33ed96d4dd876e19c92ff9bd38dc67e533e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/network-tools-rhel9@sha256:cfc034b7877d47a38210805a2928fa6f01489ef2853b56b1063bff0e01f24b80_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/network-tools-rhel9@sha256:ef6404c8030261d84dadcf4c87c6ad08f0cdbece1c231bb1b6bf9c3ab1b7c11b_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/network-tools-rhel9@sha256:f37134d1e4c21cf0d2f840597c584995985470a905e67a89d86b96b6da44f7e0_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-api-server-rhel9@sha256:48d31e4025ebdd3bfe46b3f380cb5bc7512f1b9c7c73b423d39d3ed7c4bf53ac_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-api-server-rhel9@sha256:88f8232223ad481f33fa348ba8ecd0aa4289ae356f710776f15659e77f5a175f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-api-server-rhel9@sha256:96da2f8d90ba5746a5bd6d9e65b1896687b8db65ef98b3b9443a875dcf835e56_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-api-server-rhel9@sha256:e3222425d80b3efbd311f9ecc25ae9e81d595204cfb59eb1e958bae07321241b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:7538110dbacaeac214b1c598105cad5c11c2e475b4114d47b980644948a0b007_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:c1aee4577d0927cf0d40bf8123655f40e34469500a008c3c4891af245dea0b45_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:cca7fdeb09d98b1bc7993e470b1cb02ff43f55dc13e679e99389b23ab6bcb631_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:f0cfd8387315881f1f0ef161660b2756122c805e8813ed058f984692aa5f262f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:8d6315ee5236c2e21906b860141da34e3e9ffe54b656ad3df5e294484d89acef_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:a08d2bb8e1bc6d1dc4436ac87de599d3ca2838334af3b6453990b05f31df5066_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:a2496de2a2f463583ce9ebc90a5c00ae1a39f0741e9d2056f0ec15f3016c0d3a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b3c1c8ed42106446e275b5701fe7f07cc4f1d5bb1c670ca76a844960a95dd249_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-installer-rhel9@sha256:35913f996bc8229b73ee2a053ff05ee9e98c41f4b39f5b222dcdaf580d5fe6be_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-installer-rhel9@sha256:3c1f58d871ebd3e43538aaa5cb1df340493c54cad8e313ce1b6a7b7af628cd00_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-installer-rhel9@sha256:8a524f99319abd11bd361d4f62be855df05a49a27e35b5e61395b240f440794a_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-installer-rhel9@sha256:d351b8e1d4a8dbf3bcc428b4e240bf981b139f414f30fd2ef618ebb25d10c77b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-rhel9-operator@sha256:51538d1d76758546ad5b13c628cac5cdccf4a27f533d607718b1d3ab458595fd_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-rhel9-operator@sha256:7ca42b848ebd364e136e43816f5f76cb35fcc311c81d4f53f3a700808a8d78b4_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-rhel9-operator@sha256:ca2829f38ede688ed4b270130beab99286aeee4f8e7ff30c3310e7ca780d63b4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-baremetal-rhel9-operator@sha256:fc5bec074e5f25b92884a0bf84b919845ba9730a663f43d33a074246192e52f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-cli-artifacts-rhel9@sha256:464ae1932ac899efcb5672067ef56d9ce30e4d8450eeda64c5dda4743609cfed_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- +59 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e0907823bc8989b02bb1bd55d5f08262dd0e4846173e792c14e7684fbd476c0d (For s390x architecture) The image digest is sha256:0ceb174ca670cfa3202ce15e1a884478bd4474c6bf2cf74fac0a44681bfbb8f3 (For ppc64le architecture) The image digest is sha256:460da6202791b5d3ec0ddd71a577723ffc68e35cf728ebbef832ef0a3c42e7be (For aarch64 architecture) The image digest is sha256:4b48c890a1229bdb587fb4865fbebbb9f466e7e4a9bae0fbc7ec85352c5d6041 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2025:1120
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2276518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2316321
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2330539
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://issues.redhat.com/browse/OCPBUGS-39602
- externalhttps://issues.redhat.com/browse/OCPBUGS-41300
- externalhttps://issues.redhat.com/browse/OCPBUGS-41596
- externalhttps://issues.redhat.com/browse/OCPBUGS-42763
- externalhttps://issues.redhat.com/browse/OCPBUGS-44927
- externalhttps://issues.redhat.com/browse/OCPBUGS-45268
- externalhttps://issues.redhat.com/browse/OCPBUGS-45740
- externalhttps://issues.redhat.com/browse/OCPBUGS-46465
- externalhttps://issues.redhat.com/browse/OCPBUGS-49399
- externalhttps://issues.redhat.com/browse/OCPBUGS-49685
- externalhttps://issues.redhat.com/browse/OCPBUGS-49701
- externalhttps://issues.redhat.com/browse/OCPBUGS-49756
- externalhttps://issues.redhat.com/browse/OCPBUGS-49758
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1120.json