RHSA-2025:1225HighCVSS 7.5

Red Hat Security Advisory: Logging for Red Hat OpenShift - 5.8.17

Published
February 12, 2025
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents

🎯 Affected products60

  • RHOL 5.8 for RHEL 9
  • openshift-logging/cluster-logging-operator-bundle@sha256:3cf2582ff1b25552465dff4fe83664c766a5396d8bd966460abaae522dc7c8f5_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:25fcfaaedabdc08e0f83b762e7a64ce7ffe692bdf7fa59e3a715e39aeb28a5e1_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:7b595b59306d97ae7a31981f1501b09b192a45b9a238e62891c4afd86f6b8e0a_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:aa5f41aeffd761f2d2706894585ae13d7be07c60784f86b2c56528ad28598ba8_s390x as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:ee89aff1fa83b5998104c1ba150a1d806c1999c54e43fd0958d60fcea6d24250_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-operator-bundle@sha256:aa6a0de64014a53fd80ae8abd42f537222360ac7084b69781f0555a0ed6902ae_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-proxy-rhel9@sha256:0de9a339c1ec7615154dcd15c9178b1ff5e060dd40af3785cc3ad401faf9afea_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-proxy-rhel9@sha256:42682ace8e6d6040c103d761c9a5a640c99634104ff64d943e179fe9036759d4_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-proxy-rhel9@sha256:43cccce76d269a7a7e920fce95db08ec9e469f06f88dcdb893c6c6c60eb37c4d_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-proxy-rhel9@sha256:78a5bdc079ca1f79780c94df811991236d5bdb011a549b246dd2f89bda19b3d1_s390x as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-rhel9-operator@sha256:6a2d8319ebe08d91c62599f6143474b622d040f05f2dba690dcd3ed997a0307f_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-rhel9-operator@sha256:7877325bfec88f9e039c357f7d7640d835f79cdd20bacfc68ceb58e12463b31d_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-rhel9-operator@sha256:7a0e07cf9678be95c87a4c726eaad28bff720029b9dee0402831c59c6ea4efb1_s390x as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch-rhel9-operator@sha256:b21809755628012e88a65904534ef1f129e09823d2520dbc2ff4c3a2ad117d63_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch6-rhel9@sha256:111c2ce3a570549c3372c57dc550f314af9031d84fce668c1382406905d49725_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch6-rhel9@sha256:7ef9fb3e1337c5e143d2ff6a20373c6ff94aa4e9cc625748ce38aa274e736be6_s390x as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch6-rhel9@sha256:87c88987883ede216c3fabdf580a8bd2b66c22e782d6197f730b56745cfee106_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/elasticsearch6-rhel9@sha256:892f382eddcbefc09c3d255c6c7300b2f6a7273927c23ea96e9cfbdba73d6d82_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:0ac67161ce4919637cba2694b56ca5d00089b309678a1047e22c05ef9a8cc8b4_s390x as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:35eaf2f960a2da7a255a75819bedf7eb297a12a0558c50a86112038d0dd3c9ce_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:4128ee491db22e4088eb5fa43a7d2600ebb2fe6c2695cb8b881539df5c70a931_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:cb93b7187ecfb64a521939c704613d5db05bb4609582a649e0ee000df1b8bf36_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:6179df84a1afd1e5c4fd0e82a8c3c1bd7083178e9dc431fe5f00a9a874a43f35_amd64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:6253646d49884891a42e88f426b6d6248fc80ef81787b86d67980b086e54f602_s390x as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:87e4ad39e6d4eee645caaaa8266c5fc97c4e8308e248536842b05c589eb31ba3_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:d0bdeb144c17bb5951c21b4a1f824a707fe25e94dfd778f092c6f49e947a6182_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:54c6e34ce88a61786ef0167392b0a4be4dd43b78e31166856a328a5c4ad26deb_arm64 as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:815128bf82747aa9c7fa3d327170f1cac1dd82034999943d799a81aa2feec354_ppc64le as a component of RHOL 5.8 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:8ee06578837f01afdc61011edb9feba46120271aead9c30856f871aca1281c90_s390x as a component of RHOL 5.8 for RHEL 9
  • +30 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html For Red Hat OpenShift Logging 5.8, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.13/logging/cluster-logging-upgrading.html Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure.

🔗 References (5)