Red Hat Security Advisory: OpenShift Container Platform 4.18.4 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-0406 — mholt/archiver: path traversal vulnerability CVE-2024-9675 — buildah: Buildah allows arbitrary directory mount CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-50302 — kernel: HID: core: zero-initialize the report buffer CVE-2025-24976 — distribution: Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT
🎯 Affected products156
- Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:8b2d7f8911d7bcc84a24d13fa2f4f034b17c010ce593819ce061b73505c5e94a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:9533534d18149fa469f6b28cce394f15fe2ee8edaa72a5708722eab356d58c11_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:d743b26cf815700129ca6602c4f4694bfab1be704e92118d2132da40653886e1_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:fb1db0f789fe937d2824e1301962a8a969a65527462318dc44aa423f6d8a1f56_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:3d83796ca12b4cc4998ff469bf5f4228b7850b68b74af1d5eedba6fd5b5c5384_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:4061b33db66719f1ed9cb05486d81ca00e6ae9fe05c8c385122ce618684f2c75_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:740abc2c25f7a220c3dfbdceb3b41e9aa27c042af5acc6044ee5735cd8647f58_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:ffda7d609896cee01362e407294978a5549f5860c1d92cabc250d5022027673c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:31af354ee24fa0b2ea5df9277efa19df749dbfa00852730f133e7d561a0b7fc3_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:644a5d5160f32d56405dded2567e5240da461dce9554dad827427374cc58e3f1_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:a8f52d8d5d52b874993aac8d25dd7d160b2515b5e5dc9bcf1ee26975c09e3183_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:d083c12ec9220f8cd77fd6ed4af3489db03295403c51395686e943f9a07164fa_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:10ed29b02d2dadf90ee5466dc362f826f0b604397861627e07ad550702e64227_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:11f0a4d3d5d3f4ea87df47c3b330c74414cf4de5067f0e19294b8ba38f7b7128_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:79352088cb27d051189c7894efb97d6240eb884b06fbf0c297bf96416db2b563_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:7f4828a419b073a64b6c3b3538e18ef265b9642e4061e54d6cf789ddfdd87ef9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-rhel9-operator@sha256:304714b6a21f17d1d3833c015a72ab381e7cf91d4019c92b2fea7c1db14e9575_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-rhel9-operator@sha256:7f0fe67467609053fe27e1db86961c877a292eddee3b2b92b862ec5ca4a269e9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-rhel9-operator@sha256:9295f330c1cb1701c6b61cd64b207bc0660289ae82d258b53af1a4cda56949ca_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-rhel9-operator@sha256:dec9122b23e06301d49e286a7ef17de6949fa307026865db3bfa06f53e12563a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-config-api-rhel9@sha256:4e658e582f67ce8cfb5c877a90e2505a92263ea97d54f1b84a8eb95b81f82a89_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-config-api-rhel9@sha256:7a41afb770faec9e9686402092ae2c7f738f55d9fca89427859d4df70dff8ed3_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-config-api-rhel9@sha256:b6a80826938e4d084b6ea6816775bc65433949716087d4a6e60ca841f328f672_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-config-api-rhel9@sha256:e22ca7d84bf202738d17dcf90834de9fd027573b07d72140c1f9994356a378cb_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-ingress-rhel9-operator@sha256:1a0e8cf38efec679a9107526da4a85c00ec612eeb72cb9f7c0792bec8fdf635c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-ingress-rhel9-operator@sha256:7fa6f1d292ea0456c673d52fa41322973d3e90778af1612a84f3e7ebd8af9293_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-ingress-rhel9-operator@sha256:c0d37b744effb30512852d70f0e12a4f80a1e58ebc26fe30f4d2ec662a37497a_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-ingress-rhel9-operator@sha256:f0d35b83d2727ce50b1b5bb0a77876c5d3c49617b996603efe27f83e2764b51d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-network-rhel9-operator@sha256:26e286197985b46b8d5d5a82828d60a46b436608e836d00d0b6641402b58e0a2_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +126 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.18/release_notes/ocp-4-18-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:61dffd292f6689a3381dd05f7845dcd5d27c099fce2f460aa03d760d535f81e6 (For s390x architecture) The image digest is sha256:eb491d073925d635cbfe0d56d2474ef5ad25301da175648a7d577ed4cd4243c1 (For ppc64le architecture) The image digest is sha256:5df510f9d63ec31215a16cf0e08b0d9834d51c700666814cd3b6cb66b5572833 (For aarch64 architecture) The image digest is sha256:218776c1c290da3bffb333d81ea34fb287fc8549df204fcb49eabcfc92c38f0b All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.18/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2025:2449
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257749
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2327169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344940
- externalhttps://issues.redhat.com/browse/OCPBUGS-44027
- externalhttps://issues.redhat.com/browse/OCPBUGS-44310
- externalhttps://issues.redhat.com/browse/OCPBUGS-45250
- externalhttps://issues.redhat.com/browse/OCPBUGS-48296
- externalhttps://issues.redhat.com/browse/OCPBUGS-48377
- externalhttps://issues.redhat.com/browse/OCPBUGS-48809
- externalhttps://issues.redhat.com/browse/OCPBUGS-49885
- externalhttps://issues.redhat.com/browse/OCPBUGS-50865
- externalhttps://issues.redhat.com/browse/OCPBUGS-50981
- externalhttps://issues.redhat.com/browse/OCPBUGS-51086
- externalhttps://issues.redhat.com/browse/OCPBUGS-51088
- externalhttps://issues.redhat.com/browse/OCPBUGS-51149
- externalhttps://issues.redhat.com/browse/OCPBUGS-51180
- externalhttps://issues.redhat.com/browse/OCPBUGS-51211
- externalhttps://issues.redhat.com/browse/OCPBUGS-51263
- externalhttps://issues.redhat.com/browse/OCPBUGS-51266
- externalhttps://issues.redhat.com/browse/OCPBUGS-51295
- externalhttps://issues.redhat.com/browse/OCPBUGS-51314
- externalhttps://issues.redhat.com/browse/OCPBUGS-51375
- externalhttps://issues.redhat.com/browse/OCPBUGS-51380
- externalhttps://issues.redhat.com/browse/OCPBUGS-52173
- externalhttps://issues.redhat.com/browse/OCPBUGS-52290
- externalhttps://issues.redhat.com/browse/OCPBUGS-52417
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2449.json