RHSA-2025:2441HighCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.12.74 bug fix and security update

Published
March 13, 2025
Last Modified
August 22, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-11187 — bind: bind9: Many records in the additional section cause CPU exhaustion CVE-2024-11218 — podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile CVE-2024-21626 — runc: file descriptor leak CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-50302 — kernel: HID: core: zero-initialize the report buffer

🎯 Affected products193

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:811e45cfe31314b8b10a924b684a561e24c01aa0f9e06788a0cb188761057743_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/driver-toolkit-rhel8@sha256:98bed3c2cf40d105df2d2ad7b419afa95ff513fa26292a47d15eb95713c72c18_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:15147b23e2ed12026c164f42b3b2e1326c8c613d0535c700a15f6c37afd604c1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:e71003fdfda74aff4aa5f053eb8d8832a3f0751d6429852b7fd73e24de4a1204_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:126b7d53de17fc07c4fc015ec1eb509ceeee7fb9f01174e9fba34a066b055332_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/oc-mirror-plugin-rhel8@sha256:214ea06a085b08256c231e469c90de6cd329f37ad1f905201323d1df3b9680fd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:22712bcaa472687484ac1cf5e63f35c3860f986efae1fb797b83702071b3a7ca_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:8398d0f99269ac5b2111b3b4bce7e4dfed6481dfca00b9cd78ce8294e6ce9cd6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:5ef1bb36e38ed0195431327f1f9bfe1be525143adedf63ea5d26502ce6066c20_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:ee352bd775b380322645f7b5452425500e5cbef2fc8e84583f275fda5f172f85_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-orchestrator-rhel8@sha256:dbd0d50b4646d58cbbfadcb5347d4fe9d59a0b86e18d686e1bc4e08f10b9b904_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:1b6cf07089f2c604cde76b056ec950b19d3763fc057e5ad501332a0fe8ce5100_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:de74f3959725d382844137e0ba2d96946b320c9e004beca8b52062ac474610e8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:25feb0af735cc1cadf9b9bcdd7de681322b57dc86b1c1f0b5a7fb9f1306cfd33_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-machine-controllers-rhel8@sha256:a75e6755b1dbc73939d3a8c1d780e5fff973439aea95b34c061ae2389e34f183_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:23979ad1cdcf25dd88a965b37621282a498bcf1df0d6e30f33b655ab641c6113_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:16523aa896480e186e43814ead4984ae6d814a11dfd43721bdcdef1b507d0515_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:b72a5ff26d5faceec72096f7a035551eef22ebfb0d0867ec81470e6cfb44b84f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:d1919627ab5eb19c0ebd055cef957fd0ec240374dad753d84c8022c8a3b54da5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:5f21bd032a09965cb7c5fabe61d0eb961b1c3b74108a6fbb97ca403b792ce772_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:c0a1005a8341fa114474c5543cc280edbb6ab777e1323f91f4f8eb30216e6bf8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:792cdfa47c580c591fbd8ffe02e9c9006efa4e7f717a880be384c69c51de9ee6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cloud-node-manager-rhel8@sha256:d0f5e6da51eddbef8ed30a85e7e5cfcc45183ce1944cc76cbb7bc73c8a7fb777_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:1e4351ec6411646ac87d80bc6ec54f935451a881a05edefef463bfdf71c11841_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:374ed138a1b03d1bae18e1009615e88d53ad59af291289cfed16b1f8803605c3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:d7a89febfff4c924576b70d048c9ea86520d791ba119d98fc2c133c81b1b5a41_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:620d2ac24e1dd7f569096f7a4025e5d4d1e286e00a200de441a1c76ae4dbde52_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-file-csi-driver-rhel8@sha256:6f1ba0be464ae57bc0b9c72ae13c72b13ccdd495eadb973e1b491d8bda6b6cc9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-baremetal-installer-rhel8@sha256:a04c8c569ad8f2207a3a6cb11f40733ff16ec64a68ba4ef07a6bdb37d8a8bdd5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +163 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:7257adeedec4ace7a71d419c154855773219af4183eff625c716d0923230220f All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: Users can set the option `minimal-responses yes;`in the configuration file located at `/etc/named.conf`to mitigate this vulnerability. Workaround: Mandatory access controls should limit the access of the process performing the build, on systems where they are enabled. SELinux enforces strict access controls by confining the build process (e.g., Podman) to specific domains like container_t. This prevents unauthorized access to sensitive host files and directories, even if a malicious Containerfile tries to exploit the --mount flag. Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (12)