RHSA-2025:3577HighCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.18.8 bug fix and security update

Published
April 10, 2025
Last Modified
August 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-11218 — podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile CVE-2025-0624 — grub2: net: Out-of-bounds write in grub_net_search_config_file() CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:37412c8d9f5e3b0f4ff07ad94993a13407502bd8f5e1f83f80e292356742d29d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:5a93c587542f6e21ed65d0da553ec5605899b9837dbeead78daaef35f52d018e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:77f4e17055c1462d7d7413bf94fe44dac8501dc47eaeac68e4434f8bdac423b3_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:871f9291323d3090777d707f1b83a635770ee3026e873b5bf4dcaf6fb46e8105_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:1a1a82da40845503e47825f1abb3d280b1fb36287cdd24984770dfc80b081941_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:b9c370b239597b0c6fe9a3f7f4844e0fc458b526789ccd6dc593e1802134f420_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:cb988b75e93e9720279e1f11165b1a6e56c4140d2ca01659304dd71f395201fb_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:ee660e9fe840d92e312507c04b217f51b2d9d4d5f72e164de63c96165625a7b4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:32ce989779e48fd8b12b5c4cfd5e072614c19c19e24fd3eb625861f640274795_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:53618bfe2f4a1595b1d65ee2b4df0813d3ca0b8d5fdf88acd92de5921d207ea8_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:d156f669cc68ad9a2935238229d3be3aec3078c8118c0d91088a7b2c91aba6e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:d405083a08b13cb2e15bd7a25feb082d0394bd3187dfa1841ea83475df848b76_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:163fc43caecee8fbeddb7ad98111f69d7ec879d6255a91a549386bee7b8c2c6a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:62a027ea373d586b843207c0a6ae2193e2bd6e2dadbd5264303c5037c2d0bfd2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:919be25e25ed6cd54175824c38d1fc1a05c01c25c962e5af798c08896d51e8d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:eb1edef18d0bb9e6c5cfcd71f015205b4b692b7a9fdc781ab63227f53771ab30_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:336fb9edb24da0714b56b7dc28eed5e8cb361ef5396522f1da5ac3e762de2bfa_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:56c9fb1ab96157616a0fa2056afafbcdb3bbee8331f2f465853a6a2de0362fad_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:80907407065450bbebce58b8ff9898821366c8dc8bc212b74f4197ead129292e_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:e18fe19d41ead8538d8ec4ef4be79f1e7c9007e01e96e9f4ddca923257a99bba_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:0fe268fa3fb816f3660af80275a34d3344d323771ffdbbb41a1b7077bbfdf42d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:2c7d8a4ddad5bc97466ae2a26850fd15cdc2d6319eaaf7c3982a28722f25ef91_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:5f2184f81e0e63476cddbaeee13aa636eef97e4b8c4502767f8ac3f5b846e95a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:83a67d2846a2dfa3aa1e8d4419b135ad7f1008de25e5af52dfcef7e559340fc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/frr-rhel9@sha256:23cbd663f05341ee8b02efb28beb87fcb6b163fce51fad2a24dbe23940a655db_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/frr-rhel9@sha256:652e900ed79da33235efe2ce111a4e8b6438133f09b9b989d07368e7a795657d_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/frr-rhel9@sha256:86d73a4bc269b32f442db9a957ab879494684f5c80e770095a526bcef4e590c8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/frr-rhel9@sha256:9059f77c821452368c59c401ff8a23c8dc0a1d04c33e4baad870db510e86e8c5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/insights-runtime-extractor-rhel9@sha256:5b97720fa7fb582dd8c26b3b1699f39803704da9805da83576ccb577787f1bc7_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:509888097ba7d3b4eeb5aac0586acff2ec13fff07004ac692e0dcf5cf4fe2690 (For s390x architecture) The image digest is sha256:7af6036c5d10145fa4d4138aeeb07ac812f658b100913cf8722f365973566b1e (For ppc64le architecture) The image digest is sha256:c36276a6a0473f03319fb57179538a41ca9e75c1c30d0a5e5a277a082135d6e9 (For aarch64 architecture) The image digest is sha256:b9dd5873644fcab301178105df2b45e29d885da98b373a215329b610efb6c6ec All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mandatory access controls should limit the access of the process performing the build, on systems where they are enabled. SELinux enforces strict access controls by confining the build process (e.g., Podman) to specific domains like container_t. This prevents unauthorized access to sensitive host files and directories, even if a malicious Containerfile tries to exploit the --mount flag. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (19)