RHSA-2025:2701HighCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.13.56 bug fix and security update

Published
March 20, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2024-9675 — buildah: Buildah allows arbitrary directory mount CVE-2024-11218 — podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2024-21626 — runc: file descriptor leak CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-50302 — kernel: HID: core: zero-initialize the report buffer CVE-2024-53104 — kernel: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices CVE-2024-56171 — libxml2: Use-After-Free in libxml2

🎯 Affected products194

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:886320d581b59721ad5eda03bed09502e1631b2dd54dc4af69995a9d65ff2481_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:a2ba6ee7fa92c47401aa59ed07e9f95f61f5ff0ed48436090939e4278636f316_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:9f219c03eac7b0e58e3d0661e428e8cc2d5fadec68b7930fcbb4b683cd3591e8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:1f7e957b088c1dfd43e20006aa91c0140c5eece683e4e90c2da18605dab2c910_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:2cd1b7aab20b303802156bafbde235149a163d08c473e73cdcd617109c5e61c3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/oc-mirror-plugin-rhel8@sha256:6346921f2534f242d0beb9144ec50fa4d4dc8570211a508ab6288d11ab388873_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:3068b61b914bc47856997ebc6d789fc124ff2e79ef4c8e5fbc91faa66642bd64_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:2fa919d6c7ec746d4f34a9b204bd694d66ea12948417c4600ddec009c22f2a9d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:3bd9874e5510cf62b0c3121b9a242013cb7fb57e6169a35fa037b5bd6509f887_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:9bc8925f6316e6b604783ae26aadcba23df5b4d6b074a84ebb6f155ecb702063_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-orchestrator-rhel8@sha256:4de13bde5e654409cc4704612c33305712929d1c6979fbccbf6ef94eeff4e5b8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:b20abecc0f2229af578fefd3154604d9c6a8d7a6a35536eb5016adc261f4b59a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:08a9291e92a6869a89c6278cdba0dd53c338bbe6710fb7bcce703ac941d023ce_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:9b205a2d284fdc6cbf76f2f9ac01f1d7a611b13252c1b04ee6eb64bc7799e8bc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-machine-controllers-rhel8@sha256:a5efcf79f6882174b61f744989c4b12f088daf6d9b11efc5fe7aadc756ad0af6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:e1cacad488176d578d58ffb3d02719813c7a6496f41b7d7a568838a2ccca76bc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:41274bd870a2227464790dc3e4895da27c8f631c92afbbf6ab1e149672bc5f6b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:fec03f3553220b371ca5f7dcbfeacd832a5b4cf60478db821761d6790cc7814b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:f2ff4732c1302ab65ea92a6abb7e408c009c93b533f449db1b9c6240af229b70_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:ed982f9ab2c8bc6a2408048858c3a950e27343975d8b29ec96aeb2d5d50a8883_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:deeacf5b0a2714b2dc56bd7f7cde80386aacd1df5ea3e64d9dd1b76328ef9dfe_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:8aec84356e1c44e1102e080b52ed998c672d8cb93f6ac60174b374f1b6cd6bb1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-cloud-node-manager-rhel8@sha256:5a209a8b6f30fa9425b4d4639dcaaabc07426ce26cb8250221c8be5f4de9a102_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:e084ebb3015b7334ab5842f047f4c1477f160091a94ff5e3bf84432dbeddae7c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:c542f7bce1bb0af89fcd322dbf2ceea849d7d85d9d3fffb57c5e505a9f7ed67d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:4cf9fd9d970a2a9ea962ae4eb429084fc3b61e880e897f212e7ad9e426f5b4cf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:5776bb502ee1fd5979c51541b98831d6e221f7ba3148b519e1de8e3c8387edda_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-file-csi-driver-rhel8@sha256:9775c6239f0df4ffe1669825886464f75e20aba29c1fd8984949097daf80d6bd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-baremetal-installer-rhel8@sha256:f452b9225b340f25ad563b0f72f9352af4c0bd46e7db4199106abb61a8e57774_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +164 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for the x86_64 architecture. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:1b45fabb8dc896cdf904ee6f0b88bc47f0f570ab46fe796b2da9ccd4948971f3 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mandatory access controls should limit the access of the process performing the build, on systems where they are enabled. SELinux enforces strict access controls by confining the build process (e.g., Podman) to specific domains like container_t. This prevents unauthorized access to sensitive host files and directories, even if a malicious Containerfile tries to exploit the --mount flag. Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure. Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated by preventing the `uvcvideo` module from loading. See "How do I prevent a kernel module from loading automatically?"[1] for more information. Note that disabling this module will prevent UVC devices such as webcams or video capture devices from functioning properly. Preventing the `uvcvideo` module from loading is also an effective mitigation for OpenShift environments. Different methods of applying that mitigation are available, depending on the vulnerable cluster's configuration. See "USB CVE-2024-53104 Mitigation for OpenShift" [2] for more details. That document also details alternative mitigations available through the use of compliance profiles and USBGuard. 1: https://access.redhat.com/solutions/41278 2: https://access.redhat.com/articles/7107058 Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.

🔗 References (15)