RHSA-2025:21885HighCVSS 7.8
Red Hat Security Advisory: OpenShift Compliance Operator bug fix and enhancement update
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2025-5914 — libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c CVE-2025-6020 — linux-pam: Linux-pam directory Traversal CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-7425 — libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr CVE-2025-8941 — linux-pam: Incomplete fix for CVE-2025-6020
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:21885
- externalhttps://access.redhat.com/security/cve/CVE-2024-12085
- externalhttps://access.redhat.com/security/cve/CVE-2025-5914
- externalhttps://access.redhat.com/security/cve/CVE-2025-6020
- externalhttps://access.redhat.com/security/cve/CVE-2025-6965
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/cve/CVE-2025-7425
- externalhttps://access.redhat.com/security/cve/CVE-2025-8941
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21885.json