Red Hat Security Advisory: OpenShift Container Platform 4.14.54 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:2e96d8490364755a6e7f367e92ca824eaddb716e2d09318ea9e86674e1bf684b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:3d96a3460b1f2a5dd2a73bf595c07e49b99905f236c3dfa8039be9e9b9621e19_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:ca13e6ce552c67b95e0b9057642f242b648d6f2a924d8e71ad9bb5d48328a524_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:dd9da3c1118c2a138f5efa61157e4a1695134a20849f9e1352d15492c9b243e3_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:2bb1d609b6f290ac853dcb76500c72f73200d62742b6b7001472b5156c8ba034_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:a08d3d192b9977b37f3051678af78b862d32dfe7bbc97f39051c2361838de9eb_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:b20b0cce51e5134eef9638f36c426c65d92b9e602168109aba12f9e4fdab8dbd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:e789b467cbf080923e758ae5c04fcb3d0c599cfe4d62d2b8df08fe2a6d376631_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:436933b9420af0f168af01f27e9bc962cef5c03b2b02632011e49d115bff0a85_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7eea59f9e841605dd15b11e6cdf698374165ec3d0ad96c5d750269157c071115_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:c77be7172506624f6faf0159883546fccf666f499e0621c1cb7f9a66ee6fc345_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:f162383851ac0f547cca65372fadf7ce44025f5d68484bfdc0896d5650b0d6db_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:19a99fbfab1a5b7232425be6b9499d861aa3f29fb35f309def23af8dc83218b7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:4df2d3400fd7e9b8f9fbe1c9dbfd3a9d08cc9c591f01fcc487d57d8c9c172297_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:c4bbffae434f6c34cdc48c19b212ff1eda9ab135e4b158d5e8ad1a5957922882_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:e369448e4b63cd7d55f80b71476c5c84886598864deb16c0296cb086f55f5a78_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:2009347627780f02a565a3759cd3f3d626b5d1f0a6ed1c59414638ae670c6625_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:3fb04ad25a6674789dccec54fe5886b181a8744dcd92d1c687b9ca800ee23472_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:58bb04ac45f727d8ec31f4336c50ac320bbe70a866e28808d4a0aa888f42540a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:dab4b67388e4f0d35aa7044219d09bb991c6b6dbb9339399192ab80f0281285d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:686b219ae37ac52ac59fa5244c77b332a97cf3fce10c1bf696a8e889e9a9eb3a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:7c30f7529d034b3118f41cd9867e7facfd9a2e34c2f4e615d4502eb512cbf767_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:a45cd2828fb03e380dca751ae09b34c01758ddc0033c07ab02374a4b023de6f2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:e3bbf1f59d5bf284b4cc76cfd6c0e738877e3433843b79fd0190e3c081fcf990_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:32cb3439a98849ea5a361b6267f0c69817a8e96c315dd4cfe35e95e7638140f6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:73bd5e27207661dbf2aa8cc9e8d62781f99cb5fb65255a276e0e5d90e4254216_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:8b75d993cd9febbdb7f2b77260630932d2d15a003a28f7e4d52ac20650f867e5_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:a595feff9934f82f1a2edea846a6d99f586f75c1783fb4631a4799d9a6751475_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0608d59d7a80818373d02b6c8d93948298b0716a9118f4dedb3300749ab95b31_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:aa5f0d1f11da363b48c2ae1e1827ea4f1b4a05e33b0f10d9d6f48bea9037b76d (For s390x architecture) The image digest is sha256:78229709209cb169a43716f0094a7bf2dc6943c3938bd69a310fe768ad8925be (For ppc64le architecture) The image digest is sha256:a36bbb7ed6b351dddf76e53723bd2125f70fdfcf62abf416e8cf57151a825c51 (For aarch64 architecture) The image digest is sha256:5f6f48c0b7bb083c05a3216cbb3c6e5e883889d74187fc7d7897d5a8d5a011c4 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:11669
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-55309
- externalhttps://issues.redhat.com/browse/OCPBUGS-58274
- externalhttps://issues.redhat.com/browse/OCPBUGS-58891
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_11669.json