RHSA-2025:1242HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.12.73 bug fix and security update

Published
February 13, 2025
Last Modified
August 17, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2024-53104 — kernel: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

🎯 Affected products180

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:febdcea9285cda26ced77b5ecf2ad429bfbb6d1f8e9c1d269e35cf9fa25031e4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/driver-toolkit-rhel8@sha256:ba1f7d1a6f41a91ad93d1de8ced2d216746d29500309f8742a75d7e6fe9c22ac_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:3aa47cfa7a47536f9233059bd5878801ce47bbb913c78bf86ff147c886c0026a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:ba7b618c7a86be04ffda196feba510e3853a9c9162d94b1e737ce34ff492a019_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:9ca419e26f04d3ee38d7cf7a851c0fc049feec59a1f5608dbaa40c8665cd6c17_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/oc-mirror-plugin-rhel8@sha256:d86e4563798eb0e63755d1200e4ff0c4f15cfa114ca85db61b063b3a3188f189_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:6f66ef2a631ad482981482fa7e5500cd290358bad46556d6fd7e91520ed97110_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:df64c1f73cc805246249c5e6879d38e2f42236aa183a21dd1ac44b80fbeb8d24_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:abaa4838c8901d0a29b46ec47c847d7d7310595dbffc8721dc641bf3a96876c8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:a283c93f422315fc638e63511cc867d0ccb0f30a429268a85fc0a9e898ef7f53_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-orchestrator-rhel8@sha256:617c2fa670f2812f6148f312001fe458d10ea1ccfec34e817d13c0915f9371c3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:3f410807d9a7684c724020e0f31825d9d4cf89d96cbe41df4fa0c850af7ea9f3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:49883e9918a7bb7963317486159ad1d7113df8328d77192970a42a918eef03ca_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:a9c06dfbfe8b9778f6e0e30e02fab5aa88082ad18d2bdb9101960f8858e4e69b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-machine-controllers-rhel8@sha256:39c3f41b475e3e459349bc78bf97cede88946f5629e188d3ea70db9bfc76c80e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:7790a803bc82e31517dd8c97213dd12d66a4b3203c5fa27b6cf97c5f36c7ed62_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:163e85eade7c99fa43788a8c95b8aed8a0568963955cd843a6e305a8e977a056_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:a9ee7b9b378e98bcf088905357db6cae46733fc344204c68cdc0cbf3adbc560c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:0e1e18a5c1c3d28f4a4452cad486987d530b056b27e31b6a7bea7ea2d1eb1d22_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:4738260dce445525d6e44e530747abbe503e0be16d2a6d89e001f7968b480f03_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:32bdf36ab34fe15574b95e51dda9c3f4dcdcd5a334b5e3bd4aa6b9d50fb75c1a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:a4966214ef13a33f63991a4438075a726fc2b0baf7ca05fd213c5405709366b4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cloud-node-manager-rhel8@sha256:ad2c80af878c645ec302b4e3cffbafb994715c3a2b3671decbb3b078b909f63c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:3ae49c126404f55734c2b4ffc6c1eb5adcb02e158392367cff7b24415e36421a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:ac7a2d9c5801ad4cd04d791029e2a75482479147caae945a0953cd4c34ee6c24_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:55899485ff19e67cf9337a66bb172e1589e3c9e7b247d95ae09fe2176b0b50ff_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:0a084f1e6dd0a553b5f2ff8edd01232fe3f2cc6f545e313afd02deb262e155cd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-file-csi-driver-rhel8@sha256:afdcad34b1a1c85470b14b35f5f24dcfbfa374f5d9a38e1d4bc1d8345265d84b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-baremetal-installer-rhel8@sha256:c30390789dfdede95db98d59f86e25f42c8c3ee84e47bad8f6f5f1a4a6fb0fcb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +150 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for the x86_64 architecture. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d0d7c548c8c5cfd86c29c5897f39fa5a953f549a9267e449fafbb75f1768749b All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure. Workaround: This flaw can be mitigated by preventing the `uvcvideo` module from loading. See "How do I prevent a kernel module from loading automatically?"[1] for more information. Note that disabling this module will prevent UVC devices such as webcams or video capture devices from functioning properly. Preventing the `uvcvideo` module from loading is also an effective mitigation for OpenShift environments. Different methods of applying that mitigation are available, depending on the vulnerable cluster's configuration. See "USB CVE-2024-53104 Mitigation for OpenShift" [2] for more details. That document also details alternative mitigations available through the use of compliance profiles and USBGuard. 1: https://access.redhat.com/solutions/41278 2: https://access.redhat.com/articles/7107058

🔗 References (6)