Red Hat Security Advisory: OpenShift Container Platform 4.18.9 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-11187 — bind: bind9: Many records in the additional section cause CPU exhaustion CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:4509b4257db4d0398872067dc2db3d224eedde2597ff1f6a5e7d401c9889709f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:7eef5e597e438197130e46c2dac84da6e4405bf3e04166ba53f30e1372e276d0_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:853302bbad33dfcbdfea34b2cf7d5e6a10d5d1abb059dc56b60153741137d927_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:d49cb803fb11b8b9f3d190eb2597a7ee70e98d78807a3a2808eb163cb9fe81f2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:54cab665df3208c780b0e7c94a63f6c4ec3e313d2ce1b1b6cbc4687cd5e5dd1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:71cb8431018c0965eeea70fb4e6af0fed4b8960e4d8f4f5746a91b4e3122c662_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9ad042121787c04e498b53d8935163c695cf5325821a197de767f803281bcbd6_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:e30f28cf87db805d2f5882d965c2dfe6f539d47fab0f5ed96b4682e895ae0ff7_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:35a7fdfde7ed2b7422f29d4fbd197e305a841e12a04c344fc930f89adc7dd9e4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:59319528a6700c1841977723557477955c172d156bfc7a35db6d7306fe089d3d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:ac5959a6d7870bc31de094b097700d786d93e7fbbf641f001fc7f150f90a1303_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:e977102705b2dc5f6e7b207958aa33335c50495313ca5cbf483ee10812eb2645_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:b595cd8b402efdf591ffc62ea346a18f96ec8f8e6e194e139d756978d054cd6a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:b5cbbd06d59fd41de8d16bda37d78ea8d8f27079bd86cf0ffb8425bffd9b4eeb_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:e943f01e88fb70c5748b876c64cccffb9d220d9182bab95bee3d51039324e056_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:f11be7670e6660aee110ed65371867643fb5b2e587e0e4bbc256a5937d876b73_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:37a1072697de27e8408a8ced23d40bc009b0e26d86293fdf08d640f415c5513d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:477942c73fc87653686d6bdeb29f569d3e50dd1d0d78932f37a00007313972e5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:73c803589b18dc70f0e69e4af5ed4fff447b81d452f13c7dd652c0389dcf7fbb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:cf67c077f2776bcddbd88dbcbc0db121bc2539d819ded106e67cad02015371fa_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:8e9a1ead7b13e5cb6e753eeb6e1e8a53d2e280624f010542b6ba6cae209f8d27_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:aaff37fa53af1c1f6cc39e2ba0fcfff3786c57f52681b91066cb48b36df66a00_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:b72a9a5ebf4363afc178c4bb8e55e2ec54fb58731cf7d2f011a4e6daab403c31_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:e86fed675246bb1890e5cdb373b9146aead1d93db781b1cafc170e120c71f49b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:14f71e0c9bdb2483ef69d40bb74a62db77f71a3c7b95d8b0e332bd4b4a438098_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:555775a64fd61d694ad2fdcf2914ccedacddb19dc8b74c09c56ab17785245f31_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:6a9b4fd887fa7f1729302fb0330c3c9a483197bf78becdcfda4235ec823a2c39_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:95d8fe8e6923d071fae762f820de949669a0f55b6082c4faa09213dadd95381b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:cb8cf87df9c179d4e14cf1ace985217a226e9bea9f9396a63731610479577cb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:720f89718effd16de7d77e5533c9608f1845295a2e00dfff543d0cf9aa09b2a0 (For s390x architecture) The image digest is sha256:d82ec502516460379739026329cb4a5231f8d27edbba8f23dff4d8ccff9b18f3 (For ppc64le architecture) The image digest is sha256:9006d776ad56184e1c486e470c9c486c0f5ade36835f4e20708c40b1a64c5929 (For aarch64 architecture) The image digest is sha256:c5991a00282e25fb0fb1fdf44ccc3c7a2a88d24015212cc8770b418422dc71c0 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Users can set the option `minimal-responses yes;`in the configuration file located at `/etc/named.conf`to mitigate this vulnerability. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2025:3775
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2342118
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2342879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346421
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2347423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2350190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-43724
- externalhttps://issues.redhat.com/browse/OCPBUGS-47470
- externalhttps://issues.redhat.com/browse/OCPBUGS-48790
- externalhttps://issues.redhat.com/browse/OCPBUGS-50965
- externalhttps://issues.redhat.com/browse/OCPBUGS-52837
- externalhttps://issues.redhat.com/browse/OCPBUGS-52956
- externalhttps://issues.redhat.com/browse/OCPBUGS-53015
- externalhttps://issues.redhat.com/browse/OCPBUGS-53241
- externalhttps://issues.redhat.com/browse/OCPBUGS-54342
- externalhttps://issues.redhat.com/browse/OCPBUGS-54383
- externalhttps://issues.redhat.com/browse/OCPBUGS-54411
- externalhttps://issues.redhat.com/browse/OCPBUGS-54581
- externalhttps://issues.redhat.com/browse/OCPBUGS-54609
- externalhttps://issues.redhat.com/browse/OCPBUGS-54625
- externalhttps://issues.redhat.com/browse/OCPBUGS-54627
- externalhttps://issues.redhat.com/browse/OCPBUGS-54671
- externalhttps://issues.redhat.com/browse/OCPBUGS-54680
- externalhttps://issues.redhat.com/browse/OCPBUGS-54701
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3775.json