RHSA-2025:4409HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.12.76 bug fix and security update

Published
May 8, 2025
Last Modified
September 8, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-53150 — kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources CVE-2025-27363 — freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products193

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:7f40b2a5dde36d8c726cb2b312c7ef7fd363b5d036e5f0aef94c521de463cff3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/driver-toolkit-rhel8@sha256:b18f761b39d142758edebd3cb37203dd3031a9b3ad9f7cc8e07ef6f7a9a989bc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:fab339849c8fbca9f7847bd31d8557c6e93e7c9d3333bbb8361945be4c3c35dd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:55d46c9878c70215d75ee3fbe7b48f6702fd06779cde2c03c613ccef2bf7cbcc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:93a117b3fdf152805fb93d562c17c78827818cd14afe94f108e73752c98fa0e9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/oc-mirror-plugin-rhel8@sha256:0a01cce2857df92a74b5a13f50422d443f6f733b313e8aa2356e8843535ec8ff_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:40a0c64780cbb824241c280d40d224d03ededc9a7fd76e38a3bdbdfd5bc2dbac_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:ee24c404e52f820dbb34ccd51e11a05b84a92f3498e9d038d2d97fcbd76c8e0f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:fb28bba816b84f7b05aa8c35a5d8c7f8dcc6f1094d7e1d4a96fd10a20de76632_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:08e7a6a0d3f4f50c8782dc27b044fc2c8c58b032928b83ae8d9ca05a6464b87d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-orchestrator-rhel8@sha256:60ddd157799fb4592081ab35ff9110d6a1cec3cdedb8083868016b330c933b9f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:74dc6c8bdbae98a3be7206377b299f931f62f32b4792a00b1dae4433e166e665_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:5eb6ae905d3203f0dac30e3e9c51205b20c55059e15333cbe85e7bdcd540cd29_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:51f5a9813bbf7e3a095635c158d35b97cb8a0a5225bd6365cda82c5e560b4ce7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-alibaba-machine-controllers-rhel8@sha256:c5c6436a304955608e2382c636ccfee91df4c17a17138dafcba7131ec7e7a4a3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:0024cc61828fb57ef16873fe426ecaa5665da8a29dd68294e29053610d21d98e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:fa882cd5206c2303a0ea51d266508689a1c0fe6e8db5c6081b641c1b83cfbf61_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:fdd3e6202bb383238f8cb779c603bd2499097cd5b3e8afa167c7df2ed379ef3a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:02f9a92c0322e6c0a012a36f64437b39bb8c12725102898471affe3afaebcce3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:347741e5975be4d0744ca6dae490266f06673794c65a423de86bf970b40bc166_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:ab3103ae4298881d4fa51c8adea9f08c490dd37f36e2c1bd1b5167d70267ff96_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:f9587ba8b422232e58b37e0a8a20d33042fdf64b1f8146e7e01e532255cc70e0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cloud-node-manager-rhel8@sha256:3a639c59f0a47d8450bf612860f4e8ffa499af311273fd092f62940f323c1cd6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:656b327f27729a15b584eae44ae4aeb0f7912bd9820b35748c1e5c00bd816807_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:9e6e1badd9131a469375ce6edaa43ca2e0f1248a8ddae86cca3833e7d05f9298_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:8266e1eefdd7b0fb38a63f6dc6454d082382fb15abb8e070b4ab155b3daa248b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:642ac87486d308cf209a250c02dfa76916c714ae6b0b652c9ac91804ef5d51c2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-azure-file-csi-driver-rhel8@sha256:856512de601132c696fb6e32560b86465eb4b81c20728df5e8f7f476772e4224_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-baremetal-installer-rhel8@sha256:9b58258f073cb9500f882fe1206ebb505a457931a9c9dfe053c8563570d99222_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +163 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for the x86_64 architecture. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is: (For x86_64 architecture) The image digest is sha256:07dfb0210dbe48ec222a9ffcad4bcf1e5b7e5e32140f911e753fe90dcfd4cd12 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: By restricting the sources from which font files can be loaded allowing only fonts from trusted sources, as well as validating the input for font files to avoid malformed font structures or any data which could trigger the vulnerability would reduce the risk and mitigate this vulnerability until the fix is provided. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (11)