RHSA-2025:23248HighCVSS 7.7
Red Hat Security Advisory: RHSA 4.7.9 security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-25621 — github.com/containerd/containerd: containerd local privilege escalation CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-9648 — civetweb: Denial of Service in CivetWeb CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-59375 — firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:23248
- externalhttps://access.redhat.com/security/cve/CVE-2024-25621
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-59375
- externalhttps://access.redhat.com/security/cve/CVE-2025-6965
- externalhttps://access.redhat.com/security/cve/CVE-2025-9648
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html-single/release_notes/index#about-this-release-479_release-notes-47
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23248.json