Red Hat Security Advisory: OpenShift Container Platform 4.15.55 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-51744 — golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:154b93165ca600f2699963c491e393c3aad4285183534d9b0764dfb5b682ce1a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:5c78e54b72a75a2c2360021cb296274bf1c73494beecdc64a80565151210c31e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:aec6cc21817e6f11efd2acceba2908b85bb3b3d2d7cbb1a2aa92a2732b74764f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:cd00374591beaf292248fbc2128b640c509ce5246b49199b869f023c73ecd57f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:0572ac0247142f48e3e994f92d874e014b920f0af3b92640cd9b48867ee91015_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:184fd2596ede0215e9991f917d586ba05032d53067f60ff9c7c163a995446fcf_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:6be4e862e16a1d897e22d8e6a64e04b62a48cee04a137243a0e561718b6a28b2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:d403fe31fc9fdb46aa1446953b5099cb330cd0e202cae56f04fd261794c357b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:5518f9df195575116cb3c4b4826da103e64d6cd45029aea9cbd47e5acfa6c3c3_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:a19639ccba8b673c77c203ea995cf7f7ff4bee3d34c2535be05746e122da20d2_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:d5c35b105c0e1929e5aafd987cbbb182472ccb6b2731ec5b40b9e4f9b9dc4b15_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:f851e16a9634f2abb4548df553013a2fe041b6ae6f5241b689758c99c40fbe50_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:2eafc6b918af4d59db9698f59aca7fc9289c4f711f9672af44a4e683e6f3df54_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:34e37b15c07f389efb3845fb109c152e11c817f10b004be3c8d9fba8b4011971_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:77e40a962f0a0e131374ed6d074e94733a31fda6b0012f9d2c2ae5fde797a269_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:bd228c8701b529920746dbafcc93ca0cd3a3e56db03231e02aaf94d61d61ef5b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:199e063b5a3f5ef66f6c486d5c700d650957a1a9e3e0a024ecec7027b2869623_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:730ee2f1abf062aeff0d7ae48127113f5d95fb9b3fe4168443261b78e91dcf7d_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:b4e1f4bdc013035de7f9c6f084c375c36fbcda60b84d2edc5948a0a381955ba7_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:fe6306dfd1f81c98de60c94af2992bef502ca27b81818033d98d84195b238b04_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:4ba6087a1f22c833867d83c9a26f2be042b1967cde1f30b01f07371fb0976452_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:9f1e7ed35a152454e3f4b6d967ac2ce1bebf9cf5620cabbd022142b3a4229f40_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:c837670b2cffa6bfadf9e16570175fd79668dbbca0753c8ec834a5e66c5dce38_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:c85ced824067623ce1191ca6727f366a74001e877d7062af7d8bc80d0d9ff0f0_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:66cd7515f814644969f7e9a01f61f47e4b88b306d30ac391dce2bbf3f81767ce_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:7b8b813c131bbc2d4d135d03197d55085d5cefa82159d969efc215c21289b8f9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:93b15a6ecf8de67b931e0d7064ba0ef5938eb5d39a4a6d7cb159bbee5a0fd81d_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:b5d2ff90b722d578a1be8266cb9e653dd2d795e4d53038a2cd91a4f2a17b7fbc_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:30b5ed8ce9e13a25d736edcc7de937a0f0f80be4f360c72210bf3169b867d643_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:3ff7652a165409a368a7cdc748c95efc17db0761d467cc85fb355cce14643602 (For s390x architecture) The image digest is sha256:e719d7719f466aa7584d8776d3f04ced742f5b2f7884fd1a8cb8f6cff259cbab (For ppc64le architecture) The image digest is sha256:3c3a437578260fde80a5b9b0a5513d4e016984156c0aa9d361b783ac142d9587 (For aarch64 architecture) The image digest is sha256:b086a8cedd201aee39e244dd7892d44aa39fc262693a8ea199f14b908018d614 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:11351
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://issues.redhat.com/browse/OCPBUGS-36371
- externalhttps://issues.redhat.com/browse/OCPBUGS-57521
- externalhttps://issues.redhat.com/browse/OCPBUGS-58459
- externalhttps://issues.redhat.com/browse/OCPBUGS-58506
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_11351.json