RHSA-2025:2652HighCVSS 8.2

Red Hat Security Advisory: RHODF-4.18-RHEL-9 enhancement, bug fix and security update

Published
March 11, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-44270 — PostCSS: Improper input validation in PostCSS CVE-2024-21528 — node-gettext: Prototype Pollution CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-45337 — golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2025-0426 — k8s.io/kubernetes: kubelet: node denial of service via kubelet checkpoint API

🎯 Affected products109

  • RHODF 4.18 for RHEL 9
  • odf4/cephcsi-operator-bundle@sha256:20632b5a8d188f70e98d941b26c4516c5343d74ed95953205bd03b8aa9129380_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-operator-bundle@sha256:9a8c0f7dc8daf5e4e5c6d93ecfaeecbe683eba9c05a19a868571a92d7e177941_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-operator-bundle@sha256:b58347355ffd1509d9d3f59bed0189c23354a45ee4492a61705ecd0f35e84434_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:64696c9960feba9639d65c7fc9cfc7ce2bcbfe95ca4b3327ceeef631a3379c8f_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:bc2380e7693711ff2d4ddfbd37140df47c28c4fc418b7c0897879ee6cba82be5_arm64 as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:d16d2c8cc06e3b6bc729e97e9161987f5be9859cb8eb3ba416019322d5c2acac_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:df9d5204cb6a4533283f777a96f6ff4f625f9b2edee6a9825ae0f552b30f4a7d_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:ea8ed6fe27c85de85849b0536b9d5028fa0eb6f33e733875ab23032d6f04c54c_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:f59a7faaa9cce68519a45bc5d18c8cda76f241eaac40b54cc290f8482ab8adc7_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:fddedfed484608871b8d3c7aa7e4695117b329a89a50c4192964b26ea10dc5e1_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:748591086c667d2aba6df5e0adb6f171fbc607ea0ad671b6f25ebb4db1f435f1_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:7f69338b20bfa26b14e40658ca2c7f328111bafdd5ef5b3f6ef3e5c2f06e133f_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:ae3e577fe2401b7295a325f5bbbdcab603f78358bc62c40babea6e10958f1a17_arm64 as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:f740f0a4ca53b1dadb0ebd2c8ed0454d90b88bb1fe3645d15c7571b1f9c2cb82_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:1ad66b6ea94819bdb2c6a42187a96bec229219f49036409808200dfee0628901_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:b9f3d9da734b4229620a7f832be59a5a1b30295a4e7859954dfa9f11184237f8_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:bf0b8d5eb37cf3d789f718a9b891bad603a6c308683e7ff38e19b9b75c90c66b_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:48622adeaa18d610a38380754893d8d96781264b394e6e3430c676668c9b29dd_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:78f7807b2b7a0f95f0ef363bcf8fa48ca634e46b2362add3d364fef9e011e0bc_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:d37d8e6de35d5814b45bf62e7e0db6606687bfd37baf6d4b5db24123f623511f_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:df85029012b7197ebb629d6d55e7ba3827bdab44a23d9be997beb0bf1a4b15a4_arm64 as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:3f5b58e2dd2de9a44b3193498c234cbbf9947e1ee516fc9aac578b743c94df94_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:5a9557b01b8dda05eafb3fa41090c276ff436f2978eb2693ddefae8a943e24d9_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:72263fcc840fcd80c4c35a6b98677259e85bc4846dab5d3615183cf44eade93e_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:0881ff8185af7a3ea30217d33e227975dbf055fa4e3adb63c277286df491ef33_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:5f77747b26ed176a08d4326f066487d6d02fbca3bf66b273d4dc561863155a59_s390x as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:abd47397225dcd009e53495f11324aafe39eb25fce6f847c5484be79d1d09155_amd64 as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:3df4d486dddb95e7ddd851145edae137a261b655fa70314529e58ac26f8d7925_ppc64le as a component of RHODF 4.18 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:801e827f37fc56a8cb75d3d84bc816ffd833efd9a24e459ef9d0e3ef0ad8e905_amd64 as a component of RHODF 4.18 for RHEL 9
  • +79 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: There's no known mitigation for this issue. Red Hat recommends to not parse untrusted CSS input using PostCSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, disable the kubelet read-only port by setting `readOnlyPort: 0` in `/var/lib/kubelet/config.yaml` and restarting kubelet. Additionally, disable container checkpointing by setting `ContainerCheckpoint: false` under featureGates. If using CRI-O, ensure `enable_criu_support=false` is configured in `/etc/crio/crio.conf`.

🔗 References (69)