RHSA-2025:3301HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.38 bug fix and security update

Published
April 3, 2025
Last Modified
September 8, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2024-9675 — buildah: Buildah allows arbitrary directory mount CVE-2024-9676 — Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) CVE-2024-36620 — github.com/moby/moby: NULL Pointer Dereference in Moby CVE-2024-50302 — kernel: HID: core: zero-initialize the report buffer CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-0624 — grub2: net: Out-of-bounds write in grub_net_search_config_file() CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:6d46067ada529886ebe562844267c7416b8edab01fc939be820b7d5de323d031_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:75358ad1c0a95e61155e2e79862289913f0df2da02e3af7dab0cf4586ce26910_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:ee26d879fb5d1f5c92d45dac62eac18e5a09d400d9217a1c3297368b57e013af_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:f9910bd37d7955f8ca6e60ffef409966093a9608966535a9c986e7fb090972fd_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:4beba760550a16397ef522db43d7e371e54e079e4dda9098c2f9584b911bca39_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:60242d256cfc0c5a85e8bfad42e768a2117aed60f3768420fdb19f96a609337c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:d4ecd487380d728217bbcfeb2ac8e7d7fcaca8dab645d2ec6ccca2b99ad3ec23_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:ff67d3ffb9805512978d7905814608a0bb15f3ba693ba607d7c4af4163b67156_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:0d80635f3646393f15443cad4f9f98a7ddd2759551956793171d8d496532d6a8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:1c7ae3ff32c409c83209478c12b1017d6559e8f7d1f24c0fea0a2a099e2608b9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:5f143f7c38bde80a8ccb393179b26e116a3a4bcf217c2984a0b6a543f7101998_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:9395de6a2ed5f18f5b9c3cd7cd496edd8771d9ee6c33fda3b4131f8d4442140e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:0bd8031b1c6d2d335cfb8f90a98e8ea9652529ac129a782fddb9dddb31cd16b6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:171a7a8b822e4a3b9afdd7cf746c17f8987ee167d835bb3f1b8f51f65eb5376c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:b3daaabcd62340eef8b4c4c13aaf932046316a37115953ce0b96851a31f80654_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:c17a221a731733b5d63a9d3d470616973bc2132f3433574696b6096f5be46e52_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:03336515e9dcdece823625978b0c09ec9f3f4c21c8ce0d54d5b3bc90d9365c23_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:039e4b308261858e76a7c51a33160b1aba2c6d6597bb5cd658f5b72dfca6c42b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:7cbf2b894e15f353af7f66025ecf004c5e9a99830d2bb6e534ba3c73219bfd29_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:fd927cd52d40e549637b357083bc1860ee21047bab85a05a428e20454659da52_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:0803605eaf132445250d46cc226af68efca5ead2b0a69f20a3f8bf325773be94_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:2cf85d67b4702d4b093b20f26bb75a0c058b4c4caeecc12d5f13a094b6c56e2d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:8b35245526bf27377bbb6cc10db3cfd5df45231ef5c83441c1e38bacb9076d41_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:aa7c0ebc22b6a6da6ad8b9f71db21d7d58768947bf3c27ec2f4ec86420c2e905_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:1c22b298617ec01ec6ff9609b6711953246c5c838a73373b5870f00433b27160_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:1e7ec0365085a3ff50b9912c40ea7175a0d1404a4310597eb019cb650bd7dca6_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:516244d2fab2f6064fe5769b02f0bca1a3858e8434e5b7b023337e5980bd89de_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:6ffff350487270d659377e4aba4b37a5c9ba5d90b129451c5609fccf6a1fcdc3_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:213c9c841b376ff526fc6eeb6cef4a30fe2738e90b5812ad731cd92e3a26c349_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6da09834a9e0e30a79f77c13c2520a25172d8be3fc044dc2ad1392d69b2edfbf (For s390x architecture) The image digest is sha256:bcd96f1db1a6dcf6f7185d5410d9d665fb72545b1094c5d4e5696e08c10e0adf (For ppc64le architecture) The image digest is sha256:30f50074efde956337703e02c05a8a47854a669745178684ab9e18ca38173278 (For aarch64 architecture) The image digest is sha256:0b83c98681f690f8c45c0f13002c251b925023da9416bf3106f9e9aeeec810ef All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters.

🔗 References (50)