Red Hat Security Advisory: OpenShift Container Platform 4.18.11 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-8676 — cri-o: Checkpoint restore can be triggered from different namespaces CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products101
- Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:289dc73acd93cd5bfd04477c6dfeb7eec46017559892907814ab179117a932a9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3e9f6b736227075a06c9d1b8916e97d26c80c2e382bfc93f8475781ea3c5ae5c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:41fd115d742759b989c241bca94fa34d24e59dc03849c01ab2f68fd6897ccdc8_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:e143e9994e3964e6b2507bea828e28f50387aeb2b9fecdf97ab3c7adaa59e981_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:1bc11884ceaea305e784dafe1f60da0420a72a1c52057cf45128fdaee5c348a0_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:58ef51f6fec2b18762580b0ca940e41d5d8b9ec9707f65e3d2c3babd918cec0c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:c5efcbd6d530163edb94aad0e794f4dceaa83fdda7ca3d008d1b5c74611d50ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:e7814049581a188aebb0b67508fdb379fe83a558a828c0005289e6599e281b2d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:8a8273175a50e43532bbacab2cfbf032c0b18bb34b61a50c2870ce7ea2aeecb2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:913cd5bd364015a6cfffd85720d1c25396c2525b59426cb7dc86b516d56dabaf_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:aa44b07e5578dec310f05c7e0939ba5445592c065a8669362cf46661b004ecfe_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/oc-mirror-plugin-rhel9@sha256:ed266eb27a3c3fb4c8616f69d6a805153f9427f512f91aa5e172f58f161e9541_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:5a0b56a5107b0c6465beb01afb08453741a09da5d49abe9cd478705833bac08e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:5c53a8993cc8b2328a610d4a5f55c81e3bb1134463056688f696b726521e3ddc_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:7dc20674a8bff07cd9d9ae464dedf938c8113b7f359c5cb0c21ee0254a3feb82_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:b0467ddc2c1455ee1ec379d175289fd2e4f23e68adc3ed023d49f4a1a4d11fc4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:4ae402da7186a91c24c7e5c93362146c3ed16b0ef6abc27addf1e7303acbe7cc_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:a80668a24c5a81de5c03941fe9e9ea05b71d103c5b56c31d762f60770db2850b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:ae82a10e8c3a1835b185db73c2b9c856c1e404a47f8932dd81cd0dbee7499084_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b07734b58a6f8f97b30e74b04550cb3032cd074d2639827c95d29e89127134d0_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-utils-rhel9@sha256:53c07057c7051d3dceda59a1e0ae8068303f3510b719a1d70aa24cb6179c09b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-utils-rhel9@sha256:75a30b2bac53f0133b8c29f68c76183023ed4b838cf860e6de66564db096f140_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-utils-rhel9@sha256:80f4d6cc91db37deb839306bafc34e65de3af170ab3e62eea526d26c83dc3769_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-utils-rhel9@sha256:e0952b148f958ab7f2d39ac2d6a4b71839d76f791ee35da909a886dd093b5ef6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:17e755a02eebfe364370b37f61f6ae15e7f4f1d11b5132d1d24296b6f2b7f64e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:3295441846b057c71fc9f90c760d953b80107beeb054e23476578202f3d5ccd7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:e399cf52d30a3972e49220813aa256175cd6815273e577773c229568113a66bf_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-baremetal-installer-rhel9@sha256:f04dcb2db986a3b5be641522b5028e4e4a8158fbb5e0794fac2ae975373e6ae2_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-cluster-etcd-rhel9-operator@sha256:306178f8a8399c6a0e338ec6af393972cc07534a07a66ec935ba6e29547b6c52_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- +71 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:b3c76706606940d84964095aaab1a8ed4eca0d1bd6833b4eb718115842ef6850 (For s390x architecture) The image digest is sha256:ba245bfdba7d81161971640e255f334e20b281ef15342dbf2587504bd30d3a94 (For ppc64le architecture) The image digest is ha256:749484f20536a9a75ce57e4fafd57f6216e596256ed2f712a769ebb3e7c785f4 (For aarch64 architecture) The image digest is sha256:b5c055b54ca8581f11a3acfd72bcace0319f6f9aca35f834996fa579b6543dd9 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2025:4211
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2347423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/OCPBUGS-36610
- externalhttps://issues.redhat.com/browse/OCPBUGS-39305
- externalhttps://issues.redhat.com/browse/OCPBUGS-53278
- externalhttps://issues.redhat.com/browse/OCPBUGS-54369
- externalhttps://issues.redhat.com/browse/OCPBUGS-54594
- externalhttps://issues.redhat.com/browse/OCPBUGS-54698
- externalhttps://issues.redhat.com/browse/OCPBUGS-54817
- externalhttps://issues.redhat.com/browse/OCPBUGS-54947
- externalhttps://issues.redhat.com/browse/OCPBUGS-55116
- externalhttps://issues.redhat.com/browse/OCPBUGS-55146
- externalhttps://issues.redhat.com/browse/OCPBUGS-55172
- externalhttps://issues.redhat.com/browse/OCPBUGS-55240
- externalhttps://issues.redhat.com/browse/OCPBUGS-55242
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4211.json