RHSA-2025:4422HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.15.50 bug fix and security update

Published
May 8, 2025
Last Modified
August 27, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-53150 — kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources CVE-2024-55549 — libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) CVE-2025-0624 — grub2: net: Out-of-bounds write in grub_net_search_config_file() CVE-2025-24855 — libxslt: Use-After-Free in libxslt numbers.c CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:19387bfb724614ba6127ad4a620fb9c8b88f7ada1b37d506928c6b5db9097b8b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:8a7e0b85f776b2e9525634029391f6cc540d1b01250762b4680bf0c76c9c5f9b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:a797673c4b52d3d79f4516c7f23135c91bbcea4d19cbcf716aa8454ba8e50883_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:b02f926c838bdc198919179bdfccde1097636b4e54b20d45336ffb4a82871528_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:166806f6124fac102fb471d98c377ffcffab47adc1ccde662789302257776204_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:2cf49f0e42bd92c16ba5f7716f3a87516d9822f13a994bbd9ef538fadf0a398d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:9177579ee269152b19e2a9c3e2bc84ea74840fe5b7d3ec0d2d6ef68c08fdd281_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:a95f2de4e963747748b103661994b081ca8c6a7b2b287c2fee4fbffb0a9d3419_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:367545bc05460a244dc198127d743371f5ef64601e96a230da469e044b3d3a88_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:75fb41c9430b104c52ea70653918ba691443599ae96c5ebb403475dcb9719886_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:7745b4b0e7e28460df6e0175b1e59aaedd6817d3cc9dfae0c2b0521015cbccbb_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:c74ef6c37245018867734f82cb4e9eaf28d2d90265cbc5ed696a0934afd0193e_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:442e6ee67a317c75c59623771f9ab524e6ce49b3317d534d6d1b660be06997d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:8c5f53d5b662e7a2e4e4115a5717f69cd5bbf631b11eca9ec31b8176a50a2081_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:9d262f80fbc9123001f7a3c8f919f9e2cbb2b9b8421e6d4a857a4bda5007a4ce_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:b000efc90a81aeb3f77a2080022e3378788654feae53f2c72f0cf5735188fd70_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:4cc49dbb50ed4bf130654afdc91ed0e4ee55a3daf61dc1d2dbe2a4270e9e404e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:673c5dcf394f5930302cb7dc3c97e4c4f197ab733294df337becb7421ccb00bd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:8622881f519c0a1e438b0a5b57dd2e546e51bc58665ef0302937e9abb5b60cf8_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:c02babc233646bd773581f8c71e97b7948e2d52e2cc9cf69e3dedb625b22601d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:4b24c1e8bacec4509defc68afaada55bea4111a1e5a32fc9a5c769d1f0b1b0cd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:7e21370f9909183b823b05d6dc4db092d7b34bffabc761a2b747adc0af98d8b6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:8e6b817cfd3dc057b8ac5720b5881bf3952c2136e9b122fcc609067e97204cd9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:f101f3effb89121c26e5f9289797ffdfdac91b62847bfb93d443bc3e5cca107c_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:97fd4270ea2f4a9cc1b7414fe9da61779941aff51402ceded10dead15b327ad2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:c49e3c386593ff538e255251a4ff3454f36154961a5f1687ef4d6eb855051bf2_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:e98c8cb5b34a5ec28c80f805469690759fa696f10c4293c75a16812f0a13021d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:f810077e49f89ca207fbaaf249a629e08830c518aa851993d5829de8b262bb5f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:0362049338b73546167636623ff24e855bba704ae359671af7a974dde848f6d8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f0421eafd1ab27c694f6bfc6ec8a8641636030485a3a4c80071ce7fa1a1bf04c (For s390x architecture) The image digest is sha256:49188f681f854dda12f1c3e72b5066d957f5903705ca6d060bb54399838272e3 (For ppc64le architecture) The image digest is sha256:4e464e5377d636c2f14838b0965af486949b410a31be742b7ca2e5116954d304 (For aarch64 architecture) The image digest is sha256:06f68ebf40881e9c7e29b94883a840e1119ed104e33676d2c15f5ad066339306 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (16)