RHSA-2025:19356HighCVSS 7.1

Red Hat Security Advisory: OpenShift Container Platform 4.14.57 CNF IBU extras update

Published
October 30, 2025
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-45339 — github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog

🎯 Affected products4

  • Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/lifecycle-agent-operator-bundle@sha256:9cf48d6e26c1e74ae05761c16a66c1adcc50811af251131fc5b9947010f5e217_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:9d9db89434482e948a42d0bb3b7650322d8fcd8ba2c3ac8d59b698c85f2b3114_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/recert-rhel9@sha256:4634e6f6cab3d319c1ff8d2c49dc57028b2fd41cda05c86d2674888deeff5fdf_amd64 as a component of Red Hat OpenShift Container Platform 4.14

✅ Remediation

For OpenShift Container Platform 4.14, see the following documentation for important instructions about upgrading your cluster and applying this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/index Information about accessing this content is available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (4)