Red Hat Security Advisory: OpenShift Container Platform 4.14.50 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:2433233c5ce8afe11079023f32b3d8efe3a071b7062cc50a4c4d0e18dcf353d6_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:35b4087d3788f13cd257f7b9b73c127c1fe740784cc0a767c9c2b4165e3994cf_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:62473a839354a9ece79d613f91c76874e8007fc8bd910ac414051b0e13d08a9a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:d3b65a351aa83061d6127f7ff1c4882f2be6f14756729f82108c6cc0d91693b1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:5052d909eb10ca0a757d72f542e922855c98806422bdaf4e2d2017b0b4544fe9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:a8c57ea9c560a05c8d96ff3fb6fa86043bcec3f4624243073fd2c1b754abd0fe_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:b87a47adee6e40ef996f8f1308256213350272b1ce20f3672e326c5e57ea7971_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:d12b0c7636fbdcdb6d459b855aec88873d347ea0cd9fd244c81e086400ffac8d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:0b1a82ddcbbec96d71be8a7e59c716c9276f362d1f23b5c1755bec87016480f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:510abccb94589d2a28628409c4addbf0d2c4012e659aa6f5feb6eb061c034f27_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:9768cc52ad006127a4e762166a9901929edceeea8508e8beada35d562bbc0295_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:ccd4214d6454faab52d405f6554c0f39952238abe8e49df306eb945d69c710e6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:1eb34d488eb30de67348852eb180a7f5a87e557ed11602844bfc0cae1baf89a7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:4693442dde17c234c5c58e97f2f23d56f1c21e614913c63aa24dc379396e9236_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:9ff6bb0b74ca63785eea6defca994e71073a6acf075fa076e358dd2ac2332339_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:ad9c60d3196e64a19aae9061a370dcd219148f3ee29ec155f1507905a9e0f846_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:397b8a65e46d78edf76541303fb8f04ce5da8eb0090edc3adb4008d1afb810b3_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:3a6488bd437d96d15974c21f3f451d73d013667618ace6db55f5cde5cdb78565_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:a0be4fbb22f5a33f1e6508a10f3d79c063add543c6dca0ce3925da1588423bbe_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:ca9c127a734d439e744dda5de016cdd5395deb7c59090fcb0f0eede63c1293fc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:393ff19dcd17c078f3047c3f793b5ed3c6b2d9f19e14f042613dab5d0aca1180_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:7aa4ab543b8a50e9070eafc4f3547f370e2c45a7410c54842f88a2c495f3d6c4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:8f1d3a53be8bdf2f77f22918627d55f566d57429583e50dbd04f21d8aeec3569_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:ccf1e258683fe019d6f4b5042f7dc25421a740ce42325fd729be45c8251b9926_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:026e058b073733abf4a83641c780ae6582543a95414bf1cab83c103de2eb0b45_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:4cb17b9b6bd626359b7a3f8a213d72be073c0a9ce0df9954d2bcf92ae21b203d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:5174f9272222cd7b77d8410926c6ed267d57bc8ce72d3260093374bb9288866c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:bdec7cb7268d4d275b1d220391a049f31473cd9d16b2b0afe8e89254b095f7ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:2f77d7eb36b92535949a0d9aa884f404deac8a8f9fa4f651909b7aae88114134_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:a5fd4971417fc924f0f5196c104298096c835d8dc359c444cfbb028dc221889d (For s390x architecture) The image digest is sha256:f43be2693dbf9228067bb8174194214840b0665132b8b9e7d73cf06bb1ee25f2 (For ppc64le architecture) The image digest is sha256:957d912dfe5cbf1e8cdf397929ecf58c15b12ca2bd07bb0a5d78c62b82245254 (For aarch64 architecture) The image digest is sha256:ce0bf7f226a29f8ca4dee52c2f95f4f92722eb6f59ce6a495b970d13ddb86bfd All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2025:3569
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346421
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-45559
- externalhttps://issues.redhat.com/browse/OCPBUGS-51118
- externalhttps://issues.redhat.com/browse/OCPBUGS-52500
- externalhttps://issues.redhat.com/browse/OCPBUGS-52996
- externalhttps://issues.redhat.com/browse/OCPBUGS-53314
- externalhttps://issues.redhat.com/browse/OCPBUGS-54167
- externalhttps://issues.redhat.com/browse/OCPBUGS-54260
- externalhttps://issues.redhat.com/browse/OCPBUGS-54404
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3569.json