RHSA-2025:2696HighCVSS 5.8

Red Hat Security Advisory: OpenShift Container Platform 4.17.21 bug fix and security update

Published
March 19, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices

🎯 Affected products88

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:539afbf44d727657eb54b8ba7d1e7a0ca2dc992eea15d530414c08bcbf99cd73_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:721a5d0f95e7a75f04af0d5661829a98a5105ce0018cde470b8f4025d79cb348_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:bce72b5d72965531809e7424d271390575a0696896af4841290b30cdd54e1984_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:bfd381eb29635ac73ed5d8df1dd2a5f834ec09a7a3eeca98b52a5fa7ef0a696b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:100768530d6cad43836826a0fc63c32cdf9e60a1205a1a646542fc4781d5871a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:8648c92dbbbf1ebbee711a4800f1224f63e9478d5c3bccaab48637c080701274_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:d0597f671a242a77c5f5c071c5688ac5d6c9eaca6d61a523166fbfed8d842b58_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/network-tools-rhel9@sha256:e13231fa9485833c5702b861d609007cfbc291c93477c4e963f1c036546caa14_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-rhel9-operator@sha256:6dd22b43db9a2dcacca35795d023bd1d6d6331a1c9d1be353abfe6fab8755742_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-rhel9-operator@sha256:c7801fe20f1ee79b01050b7ae052af34aa92bfee3ef277e11a1e4c6dcaefc059_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-rhel9-operator@sha256:d25fc1db14915fb0f782033f8264e562d57686549da2fe324c431858ed98e60f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-baremetal-rhel9-operator@sha256:ebe22bd66aa177b365ecb51ca498859c147233eb86f6f1085247491983642513_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:47e87dd6956db481b60f7bff93c3012cb9922c6747a4037bef32d527b3c9c197_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:6ca2097cdea9e3a2cab0b917de06ff3d1722f73f7cf81b9df25acdf779030b34_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:9f57e3f3233575051c73b379518e6d4dedbb8439a256ba366e3925e694c87e3b_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:d4a51253f0ed5d130792a9af04ccf82e21f63ecb217ad1ed2d1b428b7e1fe801_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:42600082a39a044940f0604a98b836b8cbc85e9f6e0a735ef0b229064f3c25cd_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:61dd0c1337a508b074fbe8333d9382191b16e19a61dd3fdc67de0c72cfe1b0c5_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:7e69a7f575bd9261db3bfbc99402e97161d6afd235ef6c2e9427278a92687da2_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:8cddad35e161c977d4be85debf3296db4afb7c303ed30db170a05dd040baacd9_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:118711d19ebbcb3921a03d663cb39182cce4b6edd0f3958938ad4ef7aeb5e83e_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4e9a613f0d36a1ad64673247f8cf86a85f7e2fd0faf800223c3be2ffe5676d28_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d328efc0a49a71d1c9015f1f411bbd5376fcf53d367df040e01b6d993ce1aab0_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:f316395585ddf5564691724235ecdb64087f6ee7b466e64b5495ca2e89dcf555_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-version-rhel9-operator@sha256:10b0fe5c484a7bd1e1ea8e4f574187b8791555a7560fe2122802fb117b813687_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-version-rhel9-operator@sha256:68d7fadefdf43ea96cd6b58dc6b886b3f3052115d2fbb6af3e19ff7c30343e4c_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-version-rhel9-operator@sha256:77a11ed62cfe3433e32d7a4869cbebce26a91168cbcd5756cfbb57aecda45232_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-cluster-version-rhel9-operator@sha256:9042105599d9071ff207be3b2424a0f746e4131f6c589e847bde37dd7df389cc_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-console-rhel9@sha256:7b94107c57440c1718d030ca99ba9e080f375660709ce9c5a4a90a62808d3986_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • +58 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:875094103228a685ab9c2159f5bb97455a823d137e9da09bfd0e00af9296b042 (For s390x architecture) The image digest is sha256:e58f5fcf5e47bd00bf0bc0eb73b4d16e0da066062e7034e387f5dbc4c574ed7c (For ppc64le architecture) The image digest is sha256:f016b55cf94d5b24de70ca8e708ee30caa176a668e747bfae4578c8b9ac2238c (For aarch64 architecture) The image digest is sha256:1dbe1293475e6ac71e35301542a9e017a624e27ea17309194ed70439722092ac All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.

🔗 References (13)