RHSA-2025:4008HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.16.39 bug fix and security update

Published
April 23, 2025
Last Modified
September 7, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-53150 — kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:3fdf38a6c9c3cd6703dadceb9ad1690ef31f851b0ea4bbfbd607cb486a298daa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:3fed228f6df12a6d7a6c7e305ebcf3613f38f970353dacde083f76bd76ff8138_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:8874a2399a1dcf050d18f07558dace49782f068a55e6e40dd105b36f9cf133df_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:f8846ba8e2438bd4a35f2babc6fe1075a4a0f42277fe5c2db7c02823f9edbe20_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:31ddb30dbc4e71005b26e7eb1f8beae9144147ea484a32989b753dd3c6542efe_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:72e82af1ebb6110f637423f4ae5941314d48d82b72013fe73cc044b1711164a8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:9372f509d3a6a635a11a448950b7dbd1b84af6b606e76347fffbc4e68c967c05_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:bb05922075bea2df68a4d17fcca9ea4cf85994dc816053adc36d6477eb1521b1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:4de5f15c268539ff9d6c9b31644458139cdda461852c74eeb14c30e3b0a6782f_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:ae43c88077bef7ed661e133c93642497cb5a45c744f9314569e9869eed972df9_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:be803311c79353164f9edc4218429f677889ed558ca8d9168fe206d28769fef2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:fff15d813c59d1c16cbf2b6f8d2f04c5b69cd0b1f385dd1a95c428a6a8e166c2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:3775509b0797c7208249b2153bba16d4efbb1c848e42dd20356c0d694046a94d_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:8f7aedff39e4b7ec1d0f4626c286488f9ee5b0359520ca09c12bb383967331cd_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:d85e43e6bcf161adc27a06404a6083bcb944c2d47bfa157ebfdaf09f4ec8b4dd_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:e8f26e875ced725b664ff086886b8cb6ec3dda5af09851d551974f0dd269b12f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:86b47c1d767f9e3989c47987fcf88399b633f2302bcc45dd154b1f2243e40e43_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:bb481ea76604e05346669d20f302a15c8e494df96ee9f1b652cc197b63253a82_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:e4f6f2d24e86c3d1ac2e4aea49e7f5bf548b33caf3c1333f409e5aa133851dd6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:e95cf2ef4ab684c25b6c6fa27ed184b9005e294f2db177fe1f4b3362ff58830d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:33471c3b012e0651214d123127742b4563a9c06b8751b0c3fa3f6178d3632826_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:43f698336eaa38e1b1d9fdae9503228e60f1cc67e91d08ad182f64ef30968d96_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:b1339270f30a7d69889aa37c8cdd7329cacd4d47fb1ed4fc86c80db4e5cec9b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:dbdae58ac3ac7a5b30388c95be1eb8b382edc82b9732f3e9d38654f03589bd63_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:2e990448cfcc3d806c1c4c8b79c6b11c5f1e121b1bb9011128264dc6b236ac87_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:5698a58d4f791f8f303d6dd07a37104e6f987712eb5e770df1368f4245e25bea_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:ab8bf844b8a5f589ee2e221ea2142e5950ac60a0417d7b7c285d5866b7963af5_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:e91f6b1f19031a789b6c8edaec0746eaf976ed0b42c8a0d1889d9fb335c5c278_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:0c18902265ac3992603777e6903cb29313b2e4016962c3ef359ce42ede9ca7d4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:2754cd66072e633063b6bf26446978102f27dd19d4668b20df2c7553ef9ee4cf (For s390x architecture) The image digest is sha256:20890989fe4639d8b2540d4e3fa16ff6009f724c27a12ed5e0be4f2e61a5632f (For ppc64le architecture) The image digest is sha256:51f701f5bedb90965d09f342d4bbdda07dac6ae8af3bb24de615dc8d2629550c (For aarch64 architecture) The image digest is sha256:9c76dd8c323b5a981b158d1a56ae52dc1e5e238feee59caa95bf274ddf4766d8 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (21)