RHSA-2025:2705HighCVSS 7.8

Red Hat Security Advisory: OpenShift Container Platform 4.18.5 bug fix and security update

Published
March 18, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-6597 — python: Path traversal on tempfile.TemporaryDirectory CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices

🎯 Affected products108

  • Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:020b29f3ff66339fb4ff10b2df46bd5976b515fbbf3a767a143a1bd09e91991b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:29d5bf4f0d7846f53eaa7d90157d98daa01796a7bc78f493172eb885440dbd6d_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:bb07f6bce7006a9e263f20f0787bfc96186e22bec9c79bd3d59fce6fba72ce14_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:f3cf16dedeb381c65aab9ce23a5f5c433d26609ddf1115d51b38a5d05d55009a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/network-tools-rhel9@sha256:4160f6c2353a61f5600ecea37f94c65f102d48310f7b2541faaa616fcb7095b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/network-tools-rhel9@sha256:622cd12766f96e5740ad07b185482cf06d665f3ef6b5fc2d39b91a964588289f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/network-tools-rhel9@sha256:ac81ee8b7ef25bb58a881e031342639f32eaacdde8c43ff3dae677be2b2c2db8_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/network-tools-rhel9@sha256:e5909685a0d0d27430a1274bf0a2c8e8d1aff727618fac03bc98440ca43b6051_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-baremetal-installer-rhel9@sha256:2b2d45367cff1f091a57e3a451190a06951ec1f8212ae9996cb2ea160120ce5f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-baremetal-installer-rhel9@sha256:8ceacc345040fb8f6b6539420fb387a57be867152fed6bd176a16037f5983796_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-baremetal-installer-rhel9@sha256:afb24d92831071f7428bd2fe17730f7216ab7473556959c69a470427dadd8242_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-baremetal-installer-rhel9@sha256:f480e695aee3df5be2e3c483fc69c79e710909217f0c5f92706b41f3179dbe6c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:39d8d910a4d60e5798d44caf7a57c57f6629b770f0214fb1cd7ce04e54fc5e9e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:4090266b45b58b5dd38b5c408383cc30390a0823d9b80567eae8564cd8274472_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:8c33e334894d36d094b9a86524ff9979a5f7bac2517a0452e9b132947ef5a735_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:b2c6a91e0db6af6b0dc2af841d451bd5016d045218790eac9caa81ba172b2003_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:1cb6a48e4b74633ff4616eef79c5a9f7528db5b1d1d1ec6c71f11ede1a867858_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:859ee72c47e1b8b5f3533cb754ab3c02b17c6295efce16a0f6398efcf0dfc2ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:ceef50bc3aa5b649d78a85a28086fd4bdccb7dab5c19044bfed7019ac3f8d840_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-dns-rhel9-operator@sha256:ddc9a235d64bd840a1f704e6389bc621efbaae14121e173f5502aaf4779c642a_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-monitoring-rhel9-operator@sha256:234baffa2f19c8e8f2f2bd53c3b3bfab15ec61513f33519bf065c14559c3a56f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-monitoring-rhel9-operator@sha256:2d544fdec90b9dd8131f433e9dfd61cbc260651a5cd1b59348763bd4a6a53b4d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-monitoring-rhel9-operator@sha256:67ae07dbfef7c2ba775359e91270231fce048352d1d6affd370d0de07eae5bb2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-monitoring-rhel9-operator@sha256:be6f6f13de75f06126c097a11c53b4299f80c9300db616f850703592caf59fcf_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:1e4c7b6650037a248689bffdf28e6318ca7352415ed8d9def40c961a22374afb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4ac02ea0f437efa0432bea385ea3c4279ee19ceda827d13ceefb027434bd9d90_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:55ba873cd63ca5e643ca1fd274f56c0119a41d0469499fd87d694040970c0d21_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:e8274a81766cf17861e77ea2e6e2bb6da908a058394a50aa051c538a48480074_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-console-rhel9@sha256:2501ce5e47346945015ab8c56491719e7f8778a4d461b0ce1b3cc5e31a7aec0c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • +78 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:93879f84b3165c5b5bd1fdf4563a11155dc61ea35cd93e67dc61c2b66e11c8bb (For s390x architecture) The image digest is sha256:9c48f890dd798cf11b94d8b952ccc1fda209f7976d1e69bdf3485d7a65a8efda (For ppc64le architecture) The image digest is sha256:0509959951f39edf73bd9e52791c7f10c4d8411af3983e83e064cc7727bf2fc1 (For aarch64 architecture) The image digest is sha256:b2ca04412aab2f1ea02e93679861366fd80c2b25186e8748d8a1f1558e8d62cf All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.

🔗 References (21)