Red Hat Security Advisory: OpenShift Container Platform 4.18.21 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-45339 — github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog CVE-2025-6032 — podman: podman missing TLS verification CVE-2025-48060 — jq: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:25ebcf2b45e16b0f7703f8ccbb21dca34c9c37187b90372fd0cc2889a3263136_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:9d05d77a68f71ad24ac6ed0a5559a6778f13b59d8196654b490c5a9a446b1dc6_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:a54d887a07e48df9dc81468991ab63d628397bd54044e61b21c7844a3afbaf01_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:e0e33ff952b61c0907d6d9e7cbb2d5c72ba66c67f41d77ad4c4d498ff5c50415_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:0883dd82a82be25ae017664e622b46d036281667fa8a43ad10ebec6a9cdc6be8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:29dadf861b9290bb5d832455c762f59583dcf3c442c50e32df3f4caccc81ed47_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:cbff190ef136fec39396d2fbbb40987e5dfb67d28336254284bd27ed1847adf1_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:cdd6c5c93af9f2ed9161b36ce46c56b35b29161af421d4f22fec6b44447dd370_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:78989724cfa4c413944608fa943eb058def0739b1a27b454823384ee2e58d43c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:80c6289891877e4826c80c690748a179da6a817342ffa5b3a6db67d10a1d2bf3_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:98b5839497214059a87641009f42c51f022d62aa1b3a0c37d11dd0c7276b03c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:aea6c5d665b638f02a64b8ac4d45a8865c732fc185d77ff9cac64c404a1783e4_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:3584d5e6402371adace7e7f1f1a8b6919a9ef3e67de33825218ba415eaa9347a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:4aa12ca95ae6a0050a0b790edb732d804f959a138b7887560092343660f0e235_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:5e0cb53b1527fd17cf2a1966c11381509e66ac34f545188d4db89e7e1c3d6d64_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:aadcb358e0a30b85505d1ef4f78a603e475f05b8eefe6747c0721e0d13e4146a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:16d2b265b704b2dd58f8dd753a6da79fda87cc81a90b1734fe34258d667ce2d5_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3c43657c762932cf5fa19245e6d3700ec688ee65f6fd00c865ff315a350f079e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:7753740a5c07b587683917c41a687cb73f64f99ae5d3cf327a0d57e22f9ac7bf_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:c9a1e8454cba77bb2c047580f09d71d36b2e2e33edff995ef59c58a37c0be641_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:32b7fb24866fc1464cba053919ab7a4185a517ad49f34e7949771fff1451e874_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:55ce7c527f4686256123311efb03d4e81f9e25fa962ec87e79ec26ab13450312_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:cb3f45a953305dc034ab94569c698721e8cc9f3534e532895600b9f3009115da_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:d38b461106ef0b022b33626eca9ddddfbccc46875176aec5a00ae19580b5998d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:27e37b755e8acf58863507e555b03cda234bada69191a86592f7053b00591bf8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:52babe12855a6a0fd29af2231bbcc357c930935120e20550caffbd7d02be874a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:b1a65c49b997de4df66ccf6aad987e0b4727fdd95c58ccd24c680351edff4775_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:c2521730ca0d85afe323165385aaf377480e20da9171da469cf7545d45a4de87_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:2eec973542682f90b2e6ee52159e74b148b77cc6633b273fc49279971d914d90_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9d1b107adad76f023493b8c2b74902639f66273cc120e255454ad447a9ef27d9 (For s390x architecture) The image digest is sha256:2c4ebec9a6d45e18666c4f32b20b55a5058daaf365aedd65be0d5e2dcd07b548 (For ppc64le architecture) The image digest is sha256:96e05192eebabb4f77b38bf01dc98ef6bae65cb2b732aae9cd2153de057e24f2 (For aarch64 architecture) The image digest is sha256:fb5ab479f13197b2c8339621bc56d96d20c0bf4edf5a1f91b539031f0c9965ae All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Download the VM image manually with another tool that verifies the TLS certificate and then pass the local image as a file path to podman, for example: # podman machine init --image <local-image-path> Workaround: Do not process untrusted input with the jq command line JSON processor.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2025:11677
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2342463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372501
- externalhttps://issues.redhat.com/browse/OCPBUGS-54314
- externalhttps://issues.redhat.com/browse/OCPBUGS-56167
- externalhttps://issues.redhat.com/browse/OCPBUGS-56995
- externalhttps://issues.redhat.com/browse/OCPBUGS-57068
- externalhttps://issues.redhat.com/browse/OCPBUGS-57782
- externalhttps://issues.redhat.com/browse/OCPBUGS-57887
- externalhttps://issues.redhat.com/browse/OCPBUGS-57949
- externalhttps://issues.redhat.com/browse/OCPBUGS-58203
- externalhttps://issues.redhat.com/browse/OCPBUGS-58280
- externalhttps://issues.redhat.com/browse/OCPBUGS-58366
- externalhttps://issues.redhat.com/browse/OCPBUGS-58457
- externalhttps://issues.redhat.com/browse/OCPBUGS-59235
- externalhttps://issues.redhat.com/browse/OCPBUGS-59260
- externalhttps://issues.redhat.com/browse/OCPBUGS-59280
- externalhttps://issues.redhat.com/browse/OCPBUGS-59421
- externalhttps://issues.redhat.com/browse/OCPBUGS-59443
- externalhttps://issues.redhat.com/browse/OCPBUGS-59501
- externalhttps://issues.redhat.com/browse/OCPBUGS-59623
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_11677.json