RHSA-2025:1227HighCVSS 7.5

Red Hat Security Advisory: Logging for Red Hat OpenShift - 5.9.11

Published
February 12, 2025
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2024-47220 — WEBrick: HTTP request smuggling

🎯 Affected products43

  • RHOL 5.9 for RHEL 9
  • openshift-logging/cluster-logging-operator-bundle@sha256:05d36790c431c5bcdce4ac9b0e52aa1cb05fd4b544102733d49b74d23571f74c_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:5d91887518d966664794f4871653624da04a9c555d21752a4790b70bac47e1de_s390x as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:883f362a4397547edf23b158fec1d7c83d33d88d331d3f6041656a6834ca01ae_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:e6386dbf8cf2d2c0d953f3c378baceeb480ee8943d7522d975c2abde7aab0325_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/cluster-logging-rhel9-operator@sha256:f6fae7a55c5f45d90a9df360cefda01de744b10b50b138d40f75a1cf1f778511_arm64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:62a3fb23bd1d405a87d94a9a93ad2b3dd1d44d9eb2d062cf40cb48469e2fe754_s390x as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:a64fff60352252e6f0200e8f041f3216bad06320c95c6840da2e9c51fcab480c_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:cfdb5836eb9828b86977aec2186906bc9c12b80eca4ab066ca13e542d797f921_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/eventrouter-rhel9@sha256:f937390944ecd159bca06b91289e847a00a3949c29823e8a9f9490cf2aaa5671_arm64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:67927403108d96de2c1611c578a17e32afa8c6dadf62a96d3378efc16bd20396_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:d0516cdb390b87797550ccd54b92d8986c1742f405f8b894df7b61a474801a68_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:e15eecf4b824e54f22facd4468460d50718cf8c493370d7486cc3b22e3be1545_arm64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/fluentd-rhel9@sha256:ff369dce86ef0a6dc6fd0f9a84c191f5fc5551d5fa80bf06017cc97c134b8218_s390x as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:1abab6bfcbc41e0c0e50b56a1796e20ba0a5a68433632bcc82eeb2d37d8c3402_arm64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:ac93b9ee0ef564713e225ad271a44d4b382ea5e6a44138fddef76645df7fc599_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:c8131af6025d0db9b10d9d8f7622de16520bd39755ef8d856dcbd0652175138b_s390x as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/log-file-metric-exporter-rhel9@sha256:cf0db800309fc6549eed4ac00b4bb4fad601bfe0f941cf4a4c3092b05d037be1_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-loki-rhel9@sha256:1d4a55c485dd0866a3d7ac66a4e07d4ee4b974b3b0e0086e97b531fd1be22983_s390x as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-loki-rhel9@sha256:295698b1487cf0b8c216ebe404e7c8c8c4cfee4e59fee0967c96fc444c0fdc4f_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-loki-rhel9@sha256:6d73fef832b6c9fc131507f2a0dc966bfc40ee9c8005019ba43f417ca89985e3_arm64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-loki-rhel9@sha256:78b2993a35bc6c52dba0d9e9516943ebba02432206de321b8a06c4012bc1b349_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-view-plugin-rhel9@sha256:74be6cdcdfe1da1b5431cd7f66c78db2a7c399445e905ef704ca4171d3ccf846_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-view-plugin-rhel9@sha256:a480418c3a90a85d411d46a2276112089173affbb23c5fb32691c9e53433eda4_s390x as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-view-plugin-rhel9@sha256:abf424f8915d9766eb87f151bce018cfb1864d45f0d85f4707b09b7072277a03_arm64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/logging-view-plugin-rhel9@sha256:f95c480d56b07083820e799e1de944693a6945a89c360d3d5859392090e4f944_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/loki-operator-bundle@sha256:fd4dd6de9fa37ef936cdb1c7d13716c85207f114701fb0ffad00233242fbfb63_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/loki-rhel9-operator@sha256:35d52bf4cbed75a78fba98ead066a88993622f5b648b49265455c90dbea6b57a_ppc64le as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/loki-rhel9-operator@sha256:6f379a6740699d19a0b9c14ed4f306b4cf8533b6d88e28e4cd2564a02e20f334_amd64 as a component of RHOL 5.9 for RHEL 9
  • openshift-logging/loki-rhel9-operator@sha256:b35a0df55c1de24bcc6ce7740210abd61b4fc4d1e769a3c36f6014dee55efea9_arm64 as a component of RHOL 5.9 for RHEL 9
  • +13 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.14/logging/cluster-logging-upgrading.html Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure. Workaround: As a temporary workaround, avoid using WEBrick in production environments. If you must use it, ensure that your application is behind a reverse proxy that can handle request validation and filtering to mitigate the risk of HTTP request smuggling.

🔗 References (11)