Red Hat Security Advisory: Insights proxy Container Image
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-56433 — shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise CVE-2025-4598 — systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-9714 — libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c CVE-2025-53905 — vim: Vim path traversial CVE-2025-53906 — vim: Vim path traversal
🎯 Affected products3
- Red Hat Insights proxy 1.5
- registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64 as a component of Red Hat Insights proxy 1.5
- registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64 as a component of Red Hat Insights proxy 1.5
✅ Remediation
The Insights proxy container image provided here is downloaded by the Red Hat Insights proxy product RPM. Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: This issue can be mitigated by disabling the capability of the system to generate a coredump for SUID binaries. The perform that, the following command can be ran as `root` user: ~~~ echo 0 > /proc/sys/fs/suid_dumpable ~~~ While this mitigates this vulnerability while it's not possible to update the systemd package, it disables the capability of analyzing crashes for such binaries. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The impact of this flaw may be reduced by setting strict resource limits to the stack size of processes at the operational system level. This can be achieved either through the 'ulimit' shell built-in or the 'limits.conf' file.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:22868
- externalhttps://access.redhat.com/security/cve/CVE-2024-56433
- externalhttps://access.redhat.com/security/cve/CVE-2025-4598
- externalhttps://access.redhat.com/security/cve/CVE-2025-53905
- externalhttps://access.redhat.com/security/cve/CVE-2025-53906
- externalhttps://access.redhat.com/security/cve/CVE-2025-6965
- externalhttps://access.redhat.com/security/cve/CVE-2025-9230
- externalhttps://access.redhat.com/security/cve/CVE-2025-9714
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22868.json