RHSA-2025:1386HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.16.35 security update

Published
February 19, 2025
Last Modified
August 7, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-53104 — kernel: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:38f608cfc7c72750273a93a48d6830a59c8f97112862a20a062f6074b683f102_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:55b90fc4d3d826ab127eeaa0bb7642afd8220e5eb1dd5df7c722a5715d9253f6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:b63b1fe8b9e3b11883971048d5433c45648a785a590b7135b1580149b9b737c1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:e4e1ab76f0bdedc8ce0128b04e288f721acb2fa37733b19f72b3f87a4c435c6b_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:16bbacd8c73dc16c64e009623595be64df064c7c4d41dffcfec0b6bb85e10e39_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:8baca5695a5ff0c3533cbbaef32fc7198c8e95132e9882174d16e5e307f92c36_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:96c52c7c3fb4f2237c4164190dd10c69c5e2089c27a18dca6796fcedc2c9b75d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:efe78d0e2e873034170a319d1e9197e0a600ef88bf2d32b16103950920c8c87c_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:48f6be1e440712d13f2d84f515601bb96c82921873369201bd1d48da962c09e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:c1b62e5204d65b451f165cb27b1f0798e91276f09724d6e313e48dc015157413_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:c28d2e85d25b573ded0fa673ead1cac984a540d8ff3f628bfd892191489ec5d6_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:ee0134709487c41249ed8dd815d867e540d0e20ada4ef3e0ffb01e41c420e851_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:31d324580bb18ffb1424c2dce54228f2efdca3eb30ad8ac312e22ec5e92ce5fc_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:5dea2171e586b86fc2102d94a5eea8573aadf21d253ad8378b9f25daa23ecaf3_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:dc35be075f6242f4b9fe6d59562ec155c721e6243bf7f92b67817d815161d6bf_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:df6cd47d4bcb3106a5825893a9bf55efd3cf072c9ea5f32f24e172d795f586b7_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:68d999a23cf53b37bb241892163d2a66b54794ad5ae62f069048f7e0b98c0d29_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:825f834bfc7042a8f164c02fcffa8a9f3a7227a73bc4acee6d06814c1e11352a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:ed9eda9588b54c588e39005293c52c8a968bf24dc0cc38ad92e63ba91a049e5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:fed2a25ba02c459deebc96e984cdac9ec958b82bb4ed0600d6305d19b6e145f6_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:33c51399d06eea91f445f94a99a435eec791ff26e9aa083cc70bd7ee1a22b711_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:402ad19fb379c345607e69323f7ee0a1748f8d9592fd588ccf27386926c30886_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:dd700e6ceb5f505130eb71cb36de0c2044b36e454ae119c61bc8bfec266ab42c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:ef60c104318bc142ad7175076fd22a50625db1174963916cde296caf2967cd83_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:4036bc4f4c4bc6933fe0bc6db9541ba065c8a10672833a75d5499a7c158df205_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:75aefdedca8fafe2c1ae8a81c090b0d85698fd9024ae670aef1be464fff92f06_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:875537117d860f7b331b785a020d50eca40b7a13977a4377b7e84bfae5a7faff_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:8c532aae1c3d768a5ce2ac9634d9e8e5e98a709a5159d4d475ba59cba818db0b_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:53ae337a544536964c318892eec0ef4d4eb178e7cea610805e568fe55ece6afa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:dd47bc0727149d906272e68f3c89624d7bb2a1808a3c2267653ae518d92f79a8 (For s390x architecture) The image digest is sha256:a21702afc8f5d087dd90a90c259ccfd6b478a575f39098d32ac46871bc1baef7 (For ppc64le architecture) The image digest is sha256:1346cc4aa54a51ca03e443bada57dc678c9edcc79cd23643522a0b03e49854a5 (For aarch64 architecture) The image digest is sha256:d9840779fbafd75956cfa8469ca53e50125dbfa22038f1f163cc3c3c5bfbf27e All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: This flaw can be mitigated by preventing the `uvcvideo` module from loading. See "How do I prevent a kernel module from loading automatically?"[1] for more information. Note that disabling this module will prevent UVC devices such as webcams or video capture devices from functioning properly. Preventing the `uvcvideo` module from loading is also an effective mitigation for OpenShift environments. Different methods of applying that mitigation are available, depending on the vulnerable cluster's configuration. See "USB CVE-2024-53104 Mitigation for OpenShift" [2] for more details. That document also details alternative mitigations available through the use of compliance profiles and USBGuard. 1: https://access.redhat.com/solutions/41278 2: https://access.redhat.com/articles/7107058

🔗 References (11)