RHSA-2025:11359HighCVSS 8.3

Red Hat Security Advisory: OpenShift Container Platform 4.17.36 bug fix and security update

Published
July 23, 2025
Last Modified
August 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-6032 — podman: podman missing TLS verification

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:11346434faf3ddb071ea7424b94459f41c8c027eab66434c64fd907a41513b15_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:7d44200b393a323406cd7563e22d12e653703378148923ee6d72beecff85a9c7_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:8ce8d57fcceaf4f9d49e8f9da3d16d28bba099431f26fd2cba10be4770a2216b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:b96b8581dc61a4c36c41b9920be132210b8ce2b31005f6e68fccbcc412642470_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:25585c69e6aaad0b41dd1da607af819cf95f84c0f293078a9936c5fc4ce4474d_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:36e43c3e4e135d733d28a642bb4baeedd26c47f68c0af4147cd7fee06fb67222_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:82576228cce20da5a87a0b04da4fce11ee48d0183c3e84feb88ac5082570b53c_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:cd3d661b9f7b90cc9ee241bc71f695bb45f6cc4ac0ce11487563e6a747a70e7f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:31ad336b84ffd883bde47916e72af29bbd634170c5d7d3f3e8c0c8b0eaf7cae1_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:32c7a2ccc8948fdc48cc39cb066655e4176bc3ee945891f8d3939e5007848f34_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:61e41179802b794adf1a4cbb0e75637ff8f02473e3e1779ca15dbd688e4ab706_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:8e96b1acad5edb1307a352eabdb64e0ce0ba2c26173789f277cc019c737bf85d_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:1ba1221574dda396a1bb0030192efb9fafbaea97e438d64921c2b76d286e49dd_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:5e7bbf0a2991dcba9774b2bb77448c0cf813d71aea1db6bb1a8b60ce95444381_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:985eec2a458ab3cbbcaafb722ba2657548febeb3176d5c3021bf3345fc0fe259_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:c7406e878b0c48d23d97d58da88077176cc7a1dc8409b5114053b23df026a4da_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:502ad56b8473d96a225daaf224643f28dc7edb8f8d4991666d276577e63180cb_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:95bde68d8c99b95d7584ec6c2f44ae5a378d58df3d6788713d19c1a82754ed78_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:adefcfda9aa612dae3a01cb989dc502c18243df04c9ffea7d3e498ec2dd36119_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:e69addd4822405d1d4935689c91f0300925b1d3b4196663e4ec6f1c2880cfa76_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:290cac54c6482d1abd9d15a4e779a2421a38a96bef315f087da4e1dbe873a143_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:4cf2cb17af2ad6b7b00184d012cc84bc6cda7e63cbc77591695788bd38a66133_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:5686407be006390eb5e317e04405ec1f3613bca2846bba605491c5f00d1df4c5_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:68f049b20cb940deb7cb60216eaf0907c27630a4ac2b9f866f8f4eba9b32dbad_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:39cdda938d27ae11811b61b972963d2f1a0bb6a6f0aa6191d80ed0fba3e14523_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:3a339b0c04d4bf97854892828012342d8780db43c4e8717294f440da0561e17d_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:50c437bb952aa202392895d32018b818b8c7b86c5aa9db8b17afea8c61579a15_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:a84f8bff720818900a861de52d31c9a0d73b9d3767e7becdce49f381735143ce_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-metrics-server-rhel9@sha256:7d180e09dd1501019954f1e0b5538890335175de823aab4995c2270b69fb4903_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is ssha256:9c476b68adc8fbcf44f37d96dd7e45e3a5c792d80cdb5227108e87aa9d448e78 (For s390x architecture) The image digest is sha256:c6cee18326895baa17e6bd99efed015508c45cad625f89193bd17a2e2b0f360b (For ppc64le architecture) The image digest is sha256:c87db100f50f086af5f32c250332795a486b9c4633d1e3171a8481b19ee116a8 (For aarch64 architecture) The image digest is sha256:b47058dbe3d4789d6c70d9c997264bc51af6e9c6067959397174c0ef40d1a5de All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Download the VM image manually with another tool that verifies the TLS certificate and then pass the local image as a file path to podman, for example: # podman machine init --image <local-image-path>

🔗 References (18)