Red Hat Security Advisory: Insights proxy Container Image
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-6020 — linux-pam: Linux-pam directory Traversal CVE-2025-6395 — gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() CVE-2025-8941 — linux-pam: Incomplete fix for CVE-2025-6020 CVE-2025-32988 — gnutls: Vulnerability in GnuTLS otherName SAN export CVE-2025-32989 — gnutls: Vulnerability in GnuTLS SCT extension parsing CVE-2025-32990 — gnutls: Vulnerability in GnuTLS certtool template parsing
🎯 Affected products3
- Red Hat Insights proxy 1.5
- registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:4ca38b33efec0d2dd17a8fd822a7c18281810676ceabb0c1db90953cb91cd5ea_amd64 as a component of Red Hat Insights proxy 1.5
- registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:8eb6b896e1eac4080a564e146f95c4166e47ca137083b37119027c6a77011207_arm64 as a component of Red Hat Insights proxy 1.5
✅ Remediation
The Insights proxy container image provided here is downloaded by the Red Hat Insights proxy product RPM. Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Disable the `pam_namespace` module if it is not essential for your environment, or carefully review and configure it to avoid operating on any directories or paths that can be influenced or controlled by unprivileged users, such as user home directories or world-writable locations like `/tmp`. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Currently, no mitigation is available for this vulnerability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:17181
- externalhttps://access.redhat.com/security/cve/CVE-2025-32988
- externalhttps://access.redhat.com/security/cve/CVE-2025-32989
- externalhttps://access.redhat.com/security/cve/CVE-2025-32990
- externalhttps://access.redhat.com/security/cve/CVE-2025-6020
- externalhttps://access.redhat.com/security/cve/CVE-2025-6395
- externalhttps://access.redhat.com/security/cve/CVE-2025-8941
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_17181.json