RHSA-2025:16124MediumCVSS 5.4
Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.17.2-1 Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http
🎯 Affected products10
- Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9@sha256:352e5d404bbdcc2b97a7ee97f209343eafd16dee86d2e7efa6fd227a3b426c95_arm64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9@sha256:f96a1326b5be6bed8d1a00ed0e2f6fb8eaeffc3160f148a6dcd2bc46a6b3520b_amd64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9@sha256:120421a9593d6d8fc9df3b01b4bdd310ef35013c89459dd12405664486cc378d_arm64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9@sha256:2e74f27a4663eb7e6da9ad7097cef7fa3091753a16aa1fc8f06109e5b34b345b_amd64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:aeae57b2fc706b782a3e3905e5c1825fe831f96f5b1c9478e1f2b217307a892b_amd64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator@sha256:3909f3842913d3874f7ee9db7406420621d7175579d4af61e89e2be6099d2f55_arm64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator@sha256:9d50de394b75c76608483d7869a162454f7992f6b33fd737c4f6577d8fd404ff_amd64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9@sha256:23b892a80ef6171d259ae9421c6de9bb14d52311b9eb5bd21ddb7b4de8f49e57_arm64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
- registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9@sha256:ec233dbda5693c0d2f9e10b0caac9da2cee109e53eba51c5984044cb298e4612_amd64 as a component of Custom Metric Autoscaler operator for Red Hat Openshift 2.17
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:16124
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/cve-2025-22871
- externalhttps://issues.redhat.com/browse/OCPBUGS-42559
- externalhttps://issues.redhat.com/browse/AUTOSCALE-267
- externalhttps://issues.redhat.com/browse/OCPBUGS-35181
- externalhttps://issues.redhat.com/browse/OCPBUGS-58129
- externalhttps://issues.redhat.com/browse/OCPBUGS-55598
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16124.json