Red Hat Security Advisory: OpenShift Container Platform 4.17.25 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-11218 — podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:07e9064c198deca838a726f72824f72eae8d51f6ab3dbfb2d6f4fdf02f4e2b6c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1186e99090e8de31f006a324b6e513ddcc73ed4a0798f24a06345d0a032124d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:6e4901c84aafe26992962be07fb9a8afcfc11702e3f6680ac6a4ab7704938209_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:d26df6da864250997c4e8c33a42fa2930c6d7b1be77554b07a10d71d5996274c_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:0c98a6a49c9b0f249f3e967ed73350067ad1a35d0a067694e5613a131813c3b4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:19fcd99ab87475f95ddeaea52020a2accc83d039fb35a6661420f3fb49af8677_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:f3931f10f4f0d0720be3b9fda688564fcdb73d537c2b806490fd34625fc88db1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:f552cc9c6de68e8a77006bdba956c919d572071b347b2ef0b7be0eb8911a632e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:33db4a9d2eccb90794bfb4532b7bea8ad6749fba442c3762a89d005683c40f12_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:6d64ab67f85e6f8ab80b34b78ceecb85e748a8894a14e6218385cecb1297526b_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:c4f6fce114e511b976dbbdd832eb911d31cca2c83e30d24938b31865d7a0e983_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:faa768ce69f63466e06273581799cdf307551ec39fad899c65726166a0cf43d8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3524fbf63e70e4f87d4aafa6c35cd6bba3cad91e0e1f25f6cf08bec30cbab761_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:7ba6459886824407d6fb8369850e2a04d0e70f6407ff229b6e183b6ecba7b2d8_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:81d09f5533068d01707108e3d359041c48c50dab0b6cc7204437b3479d243a5a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:e9fccde3e7b351700c914e06cb9a1a818ffb0f14664a6edc98238c12222c3b87_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:4dc79c38c0e1709ef26943f4234b4713e5e5995a1733abb217fa5e9ec5a2709d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:70af7a7927e2ea27deb3eac805000bbeeb6a3af2e3f0f383b74bbd89be07055e_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:7ffad895d0389f61a9fa734976b9c1ab2135d33f59031b2fe52c30d9460b9afc_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:d4a8fc0577c5ab2e787eb9c7d8b5d36922979916af917e67f825171e952a1f8e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:3750df99ee6d1fbb58f049d0ab7587193ae0e594f263e691eb7a52754a9ebcb9_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:53688dccfcf4a3b3320c950b36f3d4ab5ce95f27df7de3b7105cc87892aef13e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:6670b48ded6569aad1faf35e7a3306e57c24fa7a0e977679b47d94f8a3a625ca_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:e4a196c2a24ec2964c699da176f4e37e5f153c18c458f4ff5942fc647b3eb8a6_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:398d1192533ea6b18ef409528a6c1d978f7b70435c4c5ce46ce67f7d7ecda802_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:83d200b6f4c6f2eed759338dd85754e592553fc46b3a559e030e46dadd526fc0_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:8dbaf1180a66e476caefabc085abc86a662d6adab353bdc66906ac2f8d833d57_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:f3109eaff3e8aa13160d0b5710ca225dc9bdfaaeb3c417f818b3e53dd12d1b4b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:313c95865c9fc9f9522844e37d2038aecafba7e4dd7d8b7539b7dbc7c6dd8492_s390x as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:61b5415f1395d5b1266621031ff0d57969f7d086d1da5847e60b6ef549d692f6 (For s390x architecture) The image digest is sha256:94fe0e427e0e735b002c85c548b614c3991832f011e6416c144121e32e9c95b7 (For ppc64le architecture) The image digest is sha256:992523048257d51a46a80fd2870a26629deb2e436c18edb8841d9be994d9c787 (For aarch64 architecture) The image digest is sha256:81c11a4fad75f06d136b0ce4f639321aa47776f3076f1b4dff4c766bd17d36b9 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mandatory access controls should limit the access of the process performing the build, on systems where they are enabled. SELinux enforces strict access controls by confining the build process (e.g., Podman) to specific domains like container_t. This prevents unauthorized access to sensitive host files and directories, even if a malicious Containerfile tries to exploit the --mount flag. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2025:3798
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2326231
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2342118
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-47471
- externalhttps://issues.redhat.com/browse/OCPBUGS-52188
- externalhttps://issues.redhat.com/browse/OCPBUGS-53415
- externalhttps://issues.redhat.com/browse/OCPBUGS-54211
- externalhttps://issues.redhat.com/browse/OCPBUGS-54325
- externalhttps://issues.redhat.com/browse/OCPBUGS-54343
- externalhttps://issues.redhat.com/browse/OCPBUGS-54542
- externalhttps://issues.redhat.com/browse/OCPBUGS-54631
- externalhttps://issues.redhat.com/browse/OCPBUGS-54693
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3798.json