RHSA-2025:16989HighCVSS 7.5
Red Hat Security Advisory: Red Hat Offline Knowledge Portal update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-5115 — jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames
🎯 Affected products3
- Red Hat Offline Knowledge Portal 1.1.3
- registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:31830a6c2976a2336f946569f10bd7d93d5a662666014e2be846311b12d2fa78_amd64 as a component of Red Hat Offline Knowledge Portal 1.1.3
- registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:7d3aed2d9f40ed84bf0b9fb71d336780a3668c0f9d29cc29ee7e11bccf7ef7bd_arm64 as a component of Red Hat Offline Knowledge Portal 1.1.3
✅ Remediation
The container image provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. A satellite subscription is required to download and use this product. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:16989
- externalhttps://access.redhat.com/products/red-hat-offline-knowledge-portal
- externalhttps://access.redhat.com/security/cve/CVE-2025-5115
- externalhttps://access.redhat.com/security/cve/cve-2025-5115/
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_offline_knowledge_portal/1.0
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16989.json