RHSA-2025:1711HighCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.15.46 bug fix and security update

Published
February 27, 2025
Last Modified
August 19, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-21626 — runc: file descriptor leak CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-53104 — kernel: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:c8b2c21367cd018e5c410c31f6e0a8c79889b4e660713ba5bdd5f25e719f3b83_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:ca0f058452269370295c6897d19dffb6a2f59316a8383b28dfe0521753820f03_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:cf6fcd2d37e336145fb92dc665b980be8e2f4249f34628b6e0a67b8fb991135f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:db35d3483beb4401c9f1f8be86823f894037403f3d4c86bc608afdde4eee4c46_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:819f0424562b5fb5003473a6db00932041af87063f10cc556cd63122b6374e1c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:995f3ee7ff59432c7d4513f6f30def1a523a8f57c4361123da5b529dc68e5a36_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:cca0c93c8f1ec35bf40b0fd03fc835b964974312eb4127bd319b5740efb5b634_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:e9717ca5574c5f2e6818e6c95645b7d5c21caec25beb0485012b4eeba5efca13_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:4439b75c51da0445cd6d061934a61ce4b597e02f79b7e48dac23d82235c8dbd6_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:515f6839b24bf53bdc9f6370a2ba757c557f7688c0326e8a7513248fd992c8df_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:ada3e6883393f7abf5477dc40795fa908b5e7da8e5753473ea34e1a5e3677b00_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:f1be37d595a40aa145432b4b40ff5367518fc46f8fb432514f6f18e516348a23_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:07b62f51a52413ff5fb55448e00563ba0dd0de100c15b4cb6158cb445dede3df_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:1fc057472acae5f8ceb2e39643e1058a7e78e0702b99a2cbc26462f7469b8c72_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:6bfb198cfe17706ad6d1c6381b5e1986206ebbe1d34afbed918abfee18e47910_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:9922fda234035a707d349edc25f3f803deeacb5cdc3a045314e054f5ae7d1b4c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:1ad00269bcdf36e6dbb80bad924b8c26f63337d990161712418c078573cf23df_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:3b612a13ba0146f9560244e0d7d898f818f5d2bedee43fee9cb2f323f56edf5a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:3ecd15510f141074f044aeca96a271b56c865bcea6d0e627b41e58be886d3801_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:d40313f38c48de0961e1169db95bacb9d09beae3693a926a67747b2ca2e65ae9_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:2727a6e1acf33a74c27cc0933aab9441a91ffeecdef2701b3da5924eea91f701_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:62b87b6e421bf2c1461da5627e2a95f4cafb462859761b29830fbf7305bd9162_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:6fedcb484f94ff0d978fd8421f177206995117acbc9b61da8ff1d6e3117944cc_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:8e8eace7f232c50dbbe4f27e1a3e89f7eaa448ebeaad7741461de3194fa973b2_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:052737127fde8331173ad1611aa60f67e5b63eb4bf39b2b06bb823b3649ac21d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:587d87b4e363f53b4e86f3309ec33b980f957a931b7e8272f2d505f74f63665f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:7b70fa15ce882ff7223cabb6410e31dcdc4a5aa18ed63fed94e7d0b8ced5ad9d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:d680f77743e67f5f319ffe90278cec9dc5672329e3bda4550135f2e893da6d74_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:1904bfb82cfd48284c40077f1574f67fe21d69a52687cc54b7c7888be3c759b5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:ea0429e14dc9ff007f56d5db2b75209c2510d81e6869194e33a53352d2b6a4fa (For s390x architecture) The image digest is sha256:1f84f636cca2e34fff9ece8ed13baeef9494716f08195918e4081f5bc2350425 (For ppc64le architecture) The image digest is sha256:ce13a5fc1b3b222c6043854d9b88fa80ef4107ae38f92d7d93d5b7987e01d418 (For aarch64 architecture) The image digest is sha256:388bbf2a6e139cb175a294258900cd3430e13285518d7ab5f6735868ad52c9c1 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks. Workaround: This flaw can be mitigated by preventing the `uvcvideo` module from loading. See "How do I prevent a kernel module from loading automatically?"[1] for more information. Note that disabling this module will prevent UVC devices such as webcams or video capture devices from functioning properly. Preventing the `uvcvideo` module from loading is also an effective mitigation for OpenShift environments. Different methods of applying that mitigation are available, depending on the vulnerable cluster's configuration. See "USB CVE-2024-53104 Mitigation for OpenShift" [2] for more details. That document also details alternative mitigations available through the use of compliance profiles and USBGuard. 1: https://access.redhat.com/solutions/41278 2: https://access.redhat.com/articles/7107058

🔗 References (17)