RHSA-2025:13289HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.55 bug fix and security update

Published
August 14, 2025
Last Modified
August 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-45339 — github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog CVE-2025-6021 — libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-32462 — sudo: LPE via host option

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:57c2106a54dba0da94bf5281a81b00a5c7266b11f678c272ce27413a5bcd7c88_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:5fa1cac0580e2819a0f0b76a583724c7883433034afe8cb56548b84c4e64241d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:6bfe6c09cb5df52ab77d92cb18bdef4556f0b65c251be65d65251dbe7c1b721a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:a270d8ad7909a4b204b3bad4759f0ba634d1f13a54a0f00c581735658e85d2dd_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:702305fddfd3c10208415342f012d023c3cb2ceaced5c245c43f9f7544985501_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:9b43890833778cbfaf9d0d02c2181b2dc7fc8838b9dad053eafb888dc37c9a8c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:a117fc84d2f0f6d5cb8cbc234db7711e78b98237d36a05cd8d6100f43459b479_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:af8306ebd857087f834ab655ae934b2433f9f23f9bb7acde2ddbe0047bac8ddf_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:5369997739d479e300ad26806f608cfe6d09fc99cbd78ec06ec939d5d8c5d584_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:9cf89087cecc8840cdaa810b355ae409ac2c3bee654e328ba9bd99d2c3575abb_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:ab1517016517a960f7577c2cbaf3d4d4b483ff4827dda39689206fddbb7be734_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:d5cab12795f60239d8f7cebad2407ee929fb571fc3b2c6ba6ec6dfdc5ee8bd8e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:65f9787b9b7ed71de3a8393cec21ede622388a4cd62d2242d70c93bf55834992_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:79651047281ac3dcdfe041a95ba3b05be2f8653572693182760b8f045e56264e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:91fa760027b33fa49a85ff14f53426a1b44c61aa4da38ae00efd5bf72241de1e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:aefaa59dbe6b8f5b1a111847eea5fa6e1701e2d29d4ab39e1accf3da2075098c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:65a79f2f2d385a46564daea1cc0b97325f0b31f61af5729e830cf17d4b6307af_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:79edd7ec04208e223d9e7b198ed9707ce90b965b6891b5ca84f9893ae39d43e5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:856e2228b020c2a3a4611082783fca98600710618ae59f6a5701e123c586d150_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:9a4b940375694778dd5d3a6da20768e4edef3b735e103fb594a0e3d1a9582595_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:66aa5b1674ff84d4d52d3a415cc9495539f4da2214cec93231275fad8e30c481_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:8df4b39b5002c1419b0c8de8c2bedcecc23355b8ae38fa0749e155d36c95c300_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:97c1127e546f0b8ed2155ccd71f537729af4c524fafc20829559c79588e192dd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:e613aee2114ceabde8dc312c8049da00b93117929b38ad9f7e27cf42c34e4ea1_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:13c9abd0d9b3277b8767dc2d808ec0e2b419d14d360bbdb3937400c1fb5af451_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:16df690245e620c3c9cd1e2f3cf29deb3a1ba5bfd75f89add1d9f609d5529f51_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:ac237d40574681c1565af3aebf1d9f91bf2ddcccf852ef0aa9a908bb22bd21e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:f7650981ab3fbbedaf693ac5992eec94a29802007ba37149742fba42f3c40ad2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:1bdfd9b5353037838ad271dfc1b790841b0b82c0f85dec09290758a6e6726a0a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:25904f8f9b41f2a613671ba35ec15a8a2f19ba4f084026428dacb0cbd9f4088e (For s390x architecture) The image digest is sha256:de4165b400fabdb7854667c69374c834535195c8575eefb4c0df6f45b8ad4749 (For ppc64le architecture) The image digest is sha256:0f40172e2e7ae0e42365157610cc358e9246de1ff04a150065a745ec1321116a (For aarch64 architecture) The image digest is sha256:77e7cc6005486fd67f7e3a8bb4ff5c5890ed4fa32ba373d8997a86c051601772 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are strongly advised to apply vendor-supplied patches as soon as they become available to address the underlying integer overflow flaw in the affected code. Workaround: For environments using sudoers files: Remove rules defined in sudoers files that are for any system other than the local system. For environments using LDAP: Use a narrow-scoped search path in the SSSD configuration so rules that don’t apply to a system are not included in the LDAP query results.

🔗 References (8)