Red Hat Security Advisory: OpenShift Container Platform 4.12.75 packages and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-9675 — buildah: Buildah allows arbitrary directory mount CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-0624 — grub2: net: Out-of-bounds write in grub_net_search_config_file() CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 CVE-2025-27363 — freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files
🎯 Affected products193
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:364ae34be1699fafd6e3bd560e092cb2541dbd7d5dd81bb9c1e28df80ffaa99f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:c5d3d1338fdf268ab6fd5d0cc26bcdd0b46c0c62cad6cd0b6a2a612fe1563557_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:9f4367c05667569e1ab6c5b717897d08370b3fab6719261e0009651856e08cec_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:7b9e7d374b997d190451c70aa8ae76e65bbfcc6147852be036ecee0bf7ff2bf9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:4870595b6124fd7b6209170928b5358a5b4530e6b5226cd6625ee9b5b59cd0fa_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:afd46ecdcca8dcbd8c5725b9e850116e085fcf3c85b18ac7d8a90261b41823da_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:25694e276b7899585163fda2724e685c0081a3b66dd4c2e1cdb9deb312fc45a3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:820c5688927a9c63dad5bd365260eea82d793da9db3392083bff6a05912ef455_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:aab7e61fb52dd2935e1074fbe020abad97534889519222ce4053cfac89c25dc4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:70cd571dad26ff89b6249b724da9b52a1ea93356c4f1bda12c2a238f31bb1ee9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:e9345edcd7b24825c729bd1f6ac14f9ab7acb09b9f66dd1e3f015901afed43b7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:4e3569a46912b609161232cec82faff2e5fded156bf8f7878439025e973cbf5c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:8e6bb0f39936a942a73bfd303d346faf9ab1329d6f0377be2a797199f942227c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:eae86d197ac741f6aaa8ee41633917d230ae17eb4e177ea44f7dad61f429250e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-machine-controllers-rhel8@sha256:0c3b3ef2a88d33aa9795ba91b2845e335fe268e2e4f9c79d47ebf9f816b1f769_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:acb9ae02686748521d502e1117ef410970df9c8c8a7e46b5440fdb8fcc87f7bb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:90c17c6d0c2d749be164956d3b3698ff9b0baa1a4f779b4955c54efcac5e2603_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:ec0f18a4f33a49caa05b6e6a60ad955df259035a2e7ea67e87654577177f59b7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:947ec1ec1b8f06d9bcbe8068fb4474261b968ef33e525456099cbb05ff1e7207_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:0d7d4fe8b983124c853b627dee869051a26a67fe5770050a9320b2be002dbee1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:041f23e15b1bba5fc317a17e81b43436bb4addb52a1db3cb392690f0c4e5cbee_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:7bfe3f31073034c9a1fd1f3e17d3814b308ae457183933da7c3cd6e4a3c2ba0c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:a8e01a1657ae5be12586a5c6cdbcaf42d2e442e1bc6a03b42cce76629de66cbe_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:77158265dba271c0d2cc11b14241bb4516b9440a9d02454de2e94f5c78d85170_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:2cf365621ca5d7ae797bc4a60e70ef392c75816064b9ea7657dfb436b1124bcb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:f8e0b74888608f8f695ce4a4239e89712bf27be1f21f0c8f4b3c4b4aae98b28f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:2353f0b45bcc08b53fa33dbe109b3105b7a2fd19e4100d205469f8a31f69cb9a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-file-csi-driver-rhel8@sha256:ed32c82d94b844de0c99e067dba756f93ec611fa5008f84fdaaaa2fe843dc266_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:feddfabb2272a25fabd1ed4c1f3cb7a14caae72c878623a07aed12a7d15466ab_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +163 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for the x86_64 architecture. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release are as follows: (For x86_64 architecture) The image digest is sha256:24c2ea09853e520e47bdd03e5fc9b865f0a8bac7a38aad458e9785fe0f7546ac All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: By restricting the sources from which font files can be loaded allowing only fonts from trusted sources, as well as validating the input for font files to avoid malformed font structures or any data which could trigger the vulnerability would reduce the risk and mitigate this vulnerability until the fix is provided.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:3573
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2334412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346112
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346421
- externalhttps://issues.redhat.com/browse/OCPBUGS-50502
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3573.json