Red Hat Security Advisory: OpenShift Container Platform 4.14.51 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-26147 — helm: Missing YAML Content Leads To Panic CVE-2024-53150 — kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:04770db175f55d80063e0cf6e6a07b98ee2d58a9751310fb5d70c5dbace91937_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:1c80a83be0a918f022db7248efb3ac61560173bf2c73f5c6b46690b4bcaa5a71_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:603b80b38f0d06ec7339fe446a878fa58baee5e05f79bc803af3ab049a63f28f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:dcfc2aca44943074e70db403c70743c21ca27e0c1bee33c09668521ecac92806_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:2f8967562b898fea32511dfe58a5d0e65c4e4765475642f837863898ae2ab0ff_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:827e422da392c0d681352e4d94363d7a5a408f1a618e6cec34f80a9793d19ca6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:ed98998c2874314c09a30fda11a7786922f15a2bcdcdd3cc89edd46501e19c28_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:f961071cb98fa80489a7aec8229bca308cce2dad1301b7486a466af937eb6d67_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:01d58deab9fc40e71a30206633c5ad1e720987e2be63bfa1bf59d037ea8a56bc_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7c5f80c7c45f2c53d2b3fe8ac71b645bae50ecdcbaa6a04c0d346559b5ecd7a8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:d8c5dabc5bd659bc5319e810714360c94b287a7675c83a580290557a8f732b01_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:e7c0bbec037da77a0708b1ad7ba949b3db12683494ef1b1eb5c6d6ba9729fc31_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:0fca65621c7fe5985431f2bb6dbb848a3be3a26dac3af83663ef9d2c0a021cbb_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:ccd0302792229941577efd83a1cdfca48e3018ac6622cd770f71a3640abe65ba_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:d3d20ab8087b1cfeadc19f590a5b912a2cd4d5e2bf4846144cb7c1052cf9e68d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:f2da9274136cf3ce681ce47c3330798a11e62b6aef29d52e417b959000d2ad98_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:118ea9df340b914a5ddfc6bfb405323d07a2b5575993ea15c83592ed14e8ec35_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:6bd8a22d420377cd00c4d41bef33b44bab7580629b5d543bdcdac2acd20c5262_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:82b32cbe9d6ff5736ee782b130f6548da7ac68a94e007ece2302fa7aa6cd3dae_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:88f13170640fbc391b8dc64f395459c33bea522197978e87172a70ed5e34a57d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:02924effcf0ac396714a921bce86c1bab0cc475681bd400f09437e8a85618a39_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:4783898d95a7e2a3f4aba5386258352b311f8887d373437a9fc62b97d17ebcf7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:7b76e64f14fce14066b4bc2db99fccebed836b8a218ac5ef37e947021ef967d8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:81d32cd35fc61992992421c8699045cdbb31dc39f88b223c44486671699f82b0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:15db7d7a9e6efcd505d798e59d46dda60f30badde4f96e9d92c2363b32bb69bb_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:19416992df96e32b23d987032c83185021b1a0fbf94065aa52f370a5c9a33afb_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:3f202e980ab575d7415c9baf8c276a1dcf6cecf6d34e46649b862c17055119ab_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:cd1a05feb2e83d4b408fb4edecdf79237ce87b4cdea03fecd46dc2550f947b6f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:26743aeadfaa90599d353951b672f83c79a03daed2d08ecdaaee9ed363bcfae9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8ba5619d0cd45f27ab5f6ec4ff098620719871368b776190e77764a72b5d49b1 (For s390x architecture) The image digest is sha256:e72a83e935fe3a40d64937bcea300ae360d19e16f81ce722bf2334c23a2a1a7e (For ppc64le architecture) The image digest is sha256:63a5e8ad466cbd0c0f02cda0a9d422f218297b3f7c4f9aded9a5d3b4b388629d (For aarch64 architecture) The image digest is sha256:91b376eaf1bc845e5f32befcee70fe48fcf3acc2412208ffe930de536f8d671c All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2025:4177
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-50584
- externalhttps://issues.redhat.com/browse/OCPBUGS-50592
- externalhttps://issues.redhat.com/browse/OCPBUGS-53210
- externalhttps://issues.redhat.com/browse/OCPBUGS-53418
- externalhttps://issues.redhat.com/browse/OCPBUGS-53433
- externalhttps://issues.redhat.com/browse/OCPBUGS-53437
- externalhttps://issues.redhat.com/browse/OCPBUGS-54264
- externalhttps://issues.redhat.com/browse/OCPBUGS-54770
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4177.json