Red Hat Security Advisory: OpenShift Container Platform 4.18.10 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-25210 — helm: shows secrets with --dry-run option in clear text CVE-2024-45801 — dompurify: XSS vulnerability via prototype pollution CVE-2024-53150 — kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:02823182a8f48f5f5ff90f7b83044ed365b74af958dd13063e9a03f8fc585535_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:70372b85aa5c54dbc60f71aa73dcb126cad2968443d945ea127ad60a248142ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:fc7c59b5b6c3ad6535a63960a5fbd793b6d9789bee6b0f99b594b3b7839a9727_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:fdf91c6f89d8e6febe92aac823a4bd873ece4fe2e62294b43cb94b24e038108f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:45720cdcae49f526dced6f51c56622b7f092962dc7530478a3f4f526cdf42436_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:651fd0f6c8d9e089b748a68aa6a88de40f5309cc40ba0486cabbf00cb223eadc_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9a292ca85fd0a1d5cc7ed3a7dbfc4f5b279f4d6f84de82170807bbdf96760441_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:eb385a4f1647995b4a7c59cc3f136d03237211cefe6b1571456ca81a6e2eaa83_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:0c73c50921b298f5e56e693bb7a734db89e83a41286496ef58575722aa979410_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:a41132d1908b695f958cda661424e8f54de3787600b04c063a0dd04e9998f6cf_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:c81ee749ab797930db73be470c88a0bea0e509c88077cfe9d06f65b315ab6245_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:d4bd7acd425fbf9c66cff2aaec1eaed24a536e0265a9432e1cfc8c4b7625419e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:0d91465bef37cee12646401e25d5c30b76e856858608e194051b6e25e469d84f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:48d60eebdf5b5c6f0f535508c05da5db6ab681cc147d545a6e7dd35963484eac_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:5d23e95efc585bd8ddd81e978c0b4fcfb4986477f637ac3fb91d7affe18ca1f4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:858ae1b77d4d7fa1dfdbfb6978be2d76935cdc8278ff2facc8f3983932716164_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:15897ba723f67d5c348eeac4458e5c9dbda4cf537d653cd56dfe8f091a7ebe60_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:2a2493259a0ccfd02db18bc445cb6b8e347f79a59cc8634dbb8fa9deaf44adff_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:b32b3fad3c1852b946380c9c75c512999c218f633eb7c6c6831b5e3251b99781_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f4f5fe6faa2eebb8e948d01f466cc3c90b09280756ded712ee52327634eac056_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:2c071155ab600ae33d4d38c9fbd3283f279e29b3cbb1b5e152122132ca7fee0b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:a61237a389ac9e52841468a5540f810b50f33e9106d9817eb1e1e04cf6064ce8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:d3072a89cb8a4dcfbceca4ee5467eb833c48461b8c19919e78f61c041f24a99f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:fa547afd481775225028e96c1274a8c173a307df5ea18d4673450438ec7ce0d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:31222d3bea86d20d5ff6f6823bee7a7c36df224c2558b877f6d562e1365a6a78_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:3d6319e627452289167eec3522555f2e287f6d2d65edeb4f746e9a629f84b412_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:7410f4854094d4c67aced670163c2d7ce8986d03784807d4004947fd92d5ffb8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:d8a8bd55d80b5bf98ecd3962aa9360c8609f3b761ee5b9ed66fc6e38a9e7a646_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:2178fc1a10ee10dcce9bd708e7c3c9cf2caf2e3fab98df182cdace8feac49791_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:be8bcea2ab176321a4e1e54caab4709f9024bc437e52ca5bc088e729367cd0cf (For s390x architecture) The image digest is sha256:2cadb761d088d19c9bef8cfd5cf0ea2fdae330571b56d374acb1282424f4392d (For ppc64le architecture) The image digest is sha256:08293cf3bf188962572563b4680833a86d0263cf95c0ca0abdc644e0672b04f8 (For aarch64 architecture) The image digest is sha256:2a6ef9f17b82e31a465f3134ecad7e06dd07c70245fae69ccb135c7076ecc33a All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (61)
- selfhttps://access.redhat.com/errata/RHSA-2025:4019
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312631
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-33324
- externalhttps://issues.redhat.com/browse/OCPBUGS-35509
- externalhttps://issues.redhat.com/browse/OCPBUGS-36340
- externalhttps://issues.redhat.com/browse/OCPBUGS-36861
- externalhttps://issues.redhat.com/browse/OCPBUGS-38216
- externalhttps://issues.redhat.com/browse/OCPBUGS-38601
- externalhttps://issues.redhat.com/browse/OCPBUGS-38655
- externalhttps://issues.redhat.com/browse/OCPBUGS-38838
- externalhttps://issues.redhat.com/browse/OCPBUGS-38844
- externalhttps://issues.redhat.com/browse/OCPBUGS-38973
- externalhttps://issues.redhat.com/browse/OCPBUGS-39131
- externalhttps://issues.redhat.com/browse/OCPBUGS-39404
- externalhttps://issues.redhat.com/browse/OCPBUGS-39540
- externalhttps://issues.redhat.com/browse/OCPBUGS-41175
- externalhttps://issues.redhat.com/browse/OCPBUGS-41499
- externalhttps://issues.redhat.com/browse/OCPBUGS-41625
- externalhttps://issues.redhat.com/browse/OCPBUGS-41834
- externalhttps://issues.redhat.com/browse/OCPBUGS-41903
- externalhttps://issues.redhat.com/browse/OCPBUGS-42529
- externalhttps://issues.redhat.com/browse/OCPBUGS-42553
- externalhttps://issues.redhat.com/browse/OCPBUGS-42778
- externalhttps://issues.redhat.com/browse/OCPBUGS-42845
- externalhttps://issues.redhat.com/browse/OCPBUGS-42851
- externalhttps://issues.redhat.com/browse/OCPBUGS-43324
- externalhttps://issues.redhat.com/browse/OCPBUGS-43747
- externalhttps://issues.redhat.com/browse/OCPBUGS-44011
- externalhttps://issues.redhat.com/browse/OCPBUGS-44041
- externalhttps://issues.redhat.com/browse/OCPBUGS-45051
- externalhttps://issues.redhat.com/browse/OCPBUGS-45309
- externalhttps://issues.redhat.com/browse/OCPBUGS-45600
- externalhttps://issues.redhat.com/browse/OCPBUGS-46061
- externalhttps://issues.redhat.com/browse/OCPBUGS-47482
- externalhttps://issues.redhat.com/browse/OCPBUGS-47484
- externalhttps://issues.redhat.com/browse/OCPBUGS-48127
- externalhttps://issues.redhat.com/browse/OCPBUGS-48552
- externalhttps://issues.redhat.com/browse/OCPBUGS-49898
- externalhttps://issues.redhat.com/browse/OCPBUGS-50501
- externalhttps://issues.redhat.com/browse/OCPBUGS-50929
- externalhttps://issues.redhat.com/browse/OCPBUGS-50954
- externalhttps://issues.redhat.com/browse/OCPBUGS-51163
- externalhttps://issues.redhat.com/browse/OCPBUGS-52945
- externalhttps://issues.redhat.com/browse/OCPBUGS-53404
- externalhttps://issues.redhat.com/browse/OCPBUGS-54334
- externalhttps://issues.redhat.com/browse/OCPBUGS-54498
- externalhttps://issues.redhat.com/browse/OCPBUGS-54624
- externalhttps://issues.redhat.com/browse/OCPBUGS-54630
- externalhttps://issues.redhat.com/browse/OCPBUGS-54717
- externalhttps://issues.redhat.com/browse/OCPBUGS-54725
- externalhttps://issues.redhat.com/browse/OCPBUGS-54727
- externalhttps://issues.redhat.com/browse/OCPBUGS-54784
- externalhttps://issues.redhat.com/browse/OCPBUGS-54814
- externalhttps://issues.redhat.com/browse/OCPBUGS-54940
- externalhttps://issues.redhat.com/browse/OCPBUGS-55014
- externalhttps://issues.redhat.com/browse/OCPBUGS-55066
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4019.json