RHSA-2025:2445HighCVSS 7.8

Red Hat Security Advisory: OpenShift Container Platform 4.17.20 bug fix and security update

Published
March 12, 2025
Last Modified
August 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-9675 — buildah: Buildah allows arbitrary directory mount CVE-2024-50302 — kernel: HID: core: zero-initialize the report buffer CVE-2025-24976 — distribution: Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT

🎯 Affected products141

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:363572fd43989ac7a91ee6245f021be7528edb40a28ec61fa3b78c15da755fc7_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:4620a01ed0b5921095a31fe63ad3e9cef3bc0b373ecb1d669d5356351ef1e4b2_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:f25214d79041404e374d5bc2c00ef38b5d576656aac83e57b7acc0af32ff9c24_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:f9ae16d77b1c834e1e174d50e03815952b0cf8c38ea588d7e3e47b1a91fe9963_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:2f1b5db7806285e5294023a0468d8c5422030d9cf65dec858e7d93ea0c963f99_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:b0801b43cb8481894f9fdc2d940133454eec669152dee781e5c795cedf80bf8b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:be438b9cc6a1dd928a8196d270c64e284b3cbc174b2054f54684a5182ca781e4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:e3e9fbd9b93f3396a150c6fb5ad87051b2cbac535f828fef62599bf2998cfd9a_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:2833c256f9c6fb4d415d710d8bc2620b37493f0dd3decf0bf35cc308bcf5e2f6_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:89a59ed25cca0465899ae19644b944e13efc8a90ac10b471f5265646dfae46f0_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:ac440de6508f70ff7b0a2181b4ddc74984ab047d5be86cb9fa10ee94728d09a8_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:b3c0cd37cc60026252f1c45ee7764f27ed19ee7f0b94b633a86d1ebfd369d123_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-csr-approver-rhel9@sha256:2d6f70a47f59132b61129033cbe8548ce46f52a14c78c57c46a29d5cb563c0f2_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-csr-approver-rhel9@sha256:7bd4c5d63f552231dac223cdafdeb99adb02c418064231286da88b24226c07ba_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-csr-approver-rhel9@sha256:91be11137123e7bbd7509e7dc915b658ffa196f5789235b960ab722e24f15384_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-agent-installer-csr-approver-rhel9@sha256:a3b7ea38b3897a757bd9994356ebd192bd19bcf5a75269d0d4bd083a26a4d2fe_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:beb5449c59ef0e31fff8a8e2383daa67c4617e9f63c35298e52a7181e7595ba3_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:c837a57e9aeeeca6d49aa9da92292251a01ee2c341897c577b6ca4431f0c34b2_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-installer-rhel9@sha256:27594750ea16a19ed0fcdde41b7b93449b7fd8c5f9fbdcddaaa243cec3555568_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-installer-rhel9@sha256:3a5e9090937a0c09aabc1eb9a62e3f45429fe21deb3f2716f2e66a7d07f16dbd_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-installer-rhel9@sha256:85891848e05e8a2cd487595d1f14811375cb0b1bad6b3d9f1d2bca8579bc71da_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-installer-rhel9@sha256:a41743c32bb834bf37f11e471ecd31366267aad9e86d4363d128d4bf9bcac360_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-artifacts-rhel9@sha256:2a8e0ab30984f4f70dc3b492734eb42f4ac6cefae04647d4e0238b01377d83cf_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-artifacts-rhel9@sha256:3636f6f0293b9b8bbe4c5bf59dce35b9aeedd4144f83bbd5ac4cd5fad95ec52f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-artifacts-rhel9@sha256:70c7df0a420d95b522d29c270c2fef5fa167818df533262a8fedb255df9fffaf_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-artifacts-rhel9@sha256:be80fad61fcd573cda3a351c4550cd1f2bfb6c58bf3092f8693aedc7ca6f7b47_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-rhel9@sha256:0c89f5a109948336ab37c26b3092a60f71deb03e6e89193cd64fa1a76653709a_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-rhel9@sha256:2b28a82e22d7e79dabec4c72b95870918dab24248e02bdd6a43dfed63cde44b4_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cli-rhel9@sha256:9bea35f6e56715b7abb9067f5391748f2b86fa88892ef3343d89d43bee034fbc_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • +111 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:fc702dee694fbf3179ecff9b933a6baea6579b291eea13523330954972c126ef (For s390x architecture) The image digest is sha256:7f94e4013e9c59e5befb398bca532b588cf30caca9b4054f49d5228e177ad3a3 (For ppc64le architecture) The image digest is sha256:6045c45bc63610506c33a3f7dda7b14a18dce2abc5a652644b6f2484c8d4ce65 (For aarch64 architecture) The image digest is sha256:50d7ad83896c396a0063fca186632efe8694a887f4b4ab301cec9aeb1732f324 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (18)