RHSA-2025:1451HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.14.48 security update

Published
February 19, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2024-45337 — golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-53104 — kernel: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:481b577cf73108741d9f96f533dc20edfa38528a58638b2ffb43b8958aeb489a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:5913fe5a3e81ec3e3958fb55293dfff1cb457905ed76f6f59c8dda32987885e2_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:65aa83df2b9710e9167ec44e907e2148b71eaf8169d214b25b6f67b4387c8f82_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:ee1cb8dd5896a3178b62a251f7bbb1165cb4973d5c1cb3b6d44e582a6633513f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:78b95acf5f1e673c2bc3ab7e5fa1a4111b7d72ddc025eb5bc012d8fb07872bd9_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:7fb91c564b92bb3e7c1eb1f96c1c5129b1a0810e2c9c4a33d226f4f18e9b273f_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:89ddaddedc91654f2da321649327da489e71a283252da2b90e43f041c44c5ad5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:9fc31537b678356f3df1c78c35e9dcc19cccfdf1651091c2b7e19a647c1643a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:7f16b95d3b99aae4059d7ee514a7db1b4709530dc9d6490022838bc5b5d896af_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:ab270d1087ade9f001731748875fcc908375eb645eb5a5e9c4d0b7acd7e697ca_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:b45da08ab95526ae4fa7fc00cc8e8cf855598cd73e720f306c0be873a0045c64_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:c1454927640801a946ee623365aa3d9fbc53a9dc7e67e55ad7755a6fcd615014_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:65c7eacbac717299821eaf8bef6508e424f5342f928cdaa3907f5bbe0e791e54_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:98815713766aaa7b2892c16a575a29d610118d0b10ea54fc02bd7552a6b93057_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:c497753d4027ca3f980226a48ec8a717e9c27d18cb287e82c9660dca893712fc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:ca11183e40804a3aaa217df4fd134334cd04ac28de68baa5573a1a7fb7466a6f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:0a8e1606c8166760df9752fffe53967fc172ab4092031166124187f189fc88a8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:4325069a9eacf03284a008102c8d4c0b62d33c25cb67bf0eb8b871f3f3474e84_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:67e37c1ccad9a83c7060f9b0cd502b7937f28f4dc9a3dbdbc26dc85941ecc8e2_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:da465b1670cd6ccd6921dd14fe8fa053e60b28729fd9849bdf35530d6a7f6f45_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:05ced28fef5d9587c1ec1fcbec853796c836589f71bb58a138c9587ccd743a5a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:1eccc4eb3c6e353219250d76a7b3e6c723879983308293addde1acd996b03981_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:3d4b32b5b1dcecad0d18c5a4e3ed9da1729f20478f6cdafcfa7cbaa224c162c4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:c27f695c0f1c8a92cb135fa0e2aab4c1b267e244ee5039728dfea3f4431cc279_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:5135b2d4194fe26eb1f646b1a5cf8fc4f0f58f452ba5344fc7cb3b14b06cf04a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:6e4e792e3ce4d3bbef330b8f1778b4af41c07ebe6ac5a25927c848ec3ee24d53_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:aa6fa3da9619710c746b14f05803fd59d7275a2d88e901eb2dc8cb7996595e0f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:b8e6291d48ff79b72493c51f85f74a2cd5623840d0ffc8986ffaa7b1e8c5a450_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:24c9efdc10e857464b0a563c55ed24f0e6e328455b796bb3ad9d9fc0aef0d427_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:fb135efb431ce01079dfaab6c1384b5c299311b74271fa37e5f0068fb9383282 (For s390x architecture) The image digest is sha256:955bbd931ce22c4e0cc844da73047a909174b16e4500589a3d78709580f3073f (For ppc64le architecture) The image digest is sha256:e44aeb0568bfe7c4d1e6f256f331c517031bf2e7049110a37c8a68a9fb48537d (For aarch64 architecture) The image digest is sha256:076dc5c6a7fe62973abeceb85787df8cf9a29b37f5e83befdc257c7e4e1184ae All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure. Workaround: This flaw can be mitigated by preventing the `uvcvideo` module from loading. See "How do I prevent a kernel module from loading automatically?"[1] for more information. Note that disabling this module will prevent UVC devices such as webcams or video capture devices from functioning properly. Preventing the `uvcvideo` module from loading is also an effective mitigation for OpenShift environments. Different methods of applying that mitigation are available, depending on the vulnerable cluster's configuration. See "USB CVE-2024-53104 Mitigation for OpenShift" [2] for more details. That document also details alternative mitigations available through the use of compliance profiles and USBGuard. 1: https://access.redhat.com/solutions/41278 2: https://access.redhat.com/articles/7107058

🔗 References (11)