Red Hat Security Advisory: OpenShift Container Platform 4.15.48 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:284caa4758db34490f47b418f550453196c0dc20c2f16cddf515a2b59fbef37a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:5db361f5c516bf879f35fe9533133eb150c50834430385e4419c7f76e54d0609_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:79afadfa0a38ee2c0108737ba73db2469dfc9b43e0fb13d2b7c66dc58ee271f6_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:f329bb5b0d07aac7bbbbbf4fd46d30339032a4e9335003fc22974367399cb046_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:409869b55cb1fb9e48e1822d926497b1bee0634cdb2cbee2646293ec1f66ee16_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:6ff9a46331311a24a29c1daf2705fd928427ed15da168ccc51bb708b41ba1edd_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:ec620b761d419fe0d63f0f654d529ff7bdfd0030a95f386a1ec2f345d8e0f164_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:fe77dfa14edaff90709d11d4cecea7a1c7ea73829c76215fee7adb940f04ef71_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:10801f3b699a24d8951a68f99d9b9a72a64c83a81097bb403ad2b3948cf656e4_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:21cba4ce0bdcd80e9007ed062958e789e5e5e01f6b87fc3de3e8fbd9a4a9923b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:3a1946953a8dbab5c7e06d22d856d3af9a933c0e03b0b66217765c52a91d45ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:ab2cbe2f9645fa3c9e17729162fbf7ebc7655f9ffba04b97c7740eca73a2f7d3_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:201a80803b955b0ce3926104f15e124d5032fb1d910c1c092106dbbc6fb2deab_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:4e24d6767539e17f6e36b650ae300ab49aec8b853b932de6eec4c2b7dea92a20_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:a23e975a6805504b3d6d318efad85c12389669aff45445c666773abf2c85f78a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:e1389453d7400c857af7601e8e915653eb8e7540fb190ed959463b47b96a6d28_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:2aec5d5f2fe986e9f6f9a79adc4fb92b758e5ca2f6e88694bf9ec2d2d70c9780_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:2e15ad9f31d3dc7c84f036754b5b2ef09c23d786a507226fdf2791642e8bb1bc_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:313010f33c4cdae221c66ebd54828fc1e410cda74172a02718e8525ecce6b4a9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:930e47695e5484938fd9a823d1843b79a105317326864a45f9605ee65afc7674_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:192b14adbe3605952fccea53d6d89ed17c64451c01944bb307e1d6c850774f2b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:7aaf4a62158fedaae6e1d605015bdd83e720a0ce71b93f01c5aa5d1f5e20febb_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:c9af103d3efe3a3a5781feb9ee540e2f9537ebdee94ad2c60d8dbf1057f306b9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:ec6d1f5947fc9134b1b99d112d4257c0d3637015f093bdb1d18ca786dcbbf54f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:5cd1611ed5ac0ed83254b742bba8605b5602c5abd613610cffcaffefc4aef65f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:d6b1cb7bb91708ffc30dbf184fe640231afc700795adb7ac6d4222321730250b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:efb3a907807d01476073bdc94ee1c1277ae2b345b8e2c42408bf8187fdacd5e9_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:f0a19db1290a36160c05074b7c588526df51641f4b97214310c6036c526a9ec5_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:bcbe7eeeb3a277e68ecd03c3eeae4f104615b37c212f31446452c4731c44f888_s390x as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7492583774d8ae5ef7bcf7edf83630b4593f7c6a52c442cd135e4479c995ecc5 (For s390x architecture) The image digest is sha256:6fea30f4edca482e79f8c38077c6ab7c8de521103dd66de00a245696a8cbb46e (For ppc64le architecture) The image digest is sha256:215af95787ff0c4184769f3380bf6d7d8406a6989cbc8a03206c3e8d7bbe4dbf (For aarch64 architecture) The image digest is sha256:5bd455e3be160f7cd1c0c7988a4c0e52a83238a9434e727a92bc81d59efd7be7 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2025:3055
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2334412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346421
- externalhttps://issues.redhat.com/browse/OCPBUGS-43375
- externalhttps://issues.redhat.com/browse/OCPBUGS-43742
- externalhttps://issues.redhat.com/browse/OCPBUGS-48662
- externalhttps://issues.redhat.com/browse/OCPBUGS-50994
- externalhttps://issues.redhat.com/browse/OCPBUGS-51208
- externalhttps://issues.redhat.com/browse/OCPBUGS-52344
- externalhttps://issues.redhat.com/browse/OCPBUGS-52481
- externalhttps://issues.redhat.com/browse/OCPBUGS-52499
- externalhttps://issues.redhat.com/browse/OCPBUGS-52896
- externalhttps://issues.redhat.com/browse/OCPBUGS-52992
- externalhttps://issues.redhat.com/browse/OCPBUGS-53226
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3055.json