Red Hat Security Advisory: OpenShift Container Platform 4.18.12 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-7128 — openshift-console: Unauthenticated Data Exposure CVE-2024-55549 — libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) CVE-2025-24855 — libxslt: Use-After-Free in libxslt numbers.c CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:06dbe75c33322cf7c58245de8da53eb0bbc640079fc809fade7480289e8a0697_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:09cad7e7084f401fe1e3c40c3710a9051676c78362e3b49d974106abe6b483ff_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:aa691d4ee37ec85a0e2bcfbfba60f8a8930a794df239f206ed25c233bf8fde66_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:cd90f59f0b1181b991dda0f161b6a5041f7dabb30142a53b9f053c0ec3d695af_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:0e596659038db2d79bfc9d87f5a1eeddd9107e6ad53c1443726fb6c95fa6f7a6_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:637b76f0955a4b255de30e3252bbfa39e112dad50b6c98ec873cf2d8c991a6fc_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:c52c61cac8abc52918931c02e6629ce1df8160b59902c52a67d8249e0dddda70_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:dc53149f7588569a340da4c1ae03c4b543e74ab76fb8c5538f762719fadc3eb9_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:4bba45fe06eb55a7fe586f5a7388ac6cfabd6a7cc7e2106344decd19a3a2e1a6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:55aaab2ac7e59331676694b9bf13125cc82e3cee4649466014cc228893ccb5a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:92523d67cceec7c7e848ab85cfad798b80ac99a9a2df5524830351f86319cf32_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:a68b657721060930c6ec88bedd320620e4a84d5001eeb6d10b4740ce02fb7221_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:26714b91ad8d79c62608829f68df256fb991f861c0994678b3215cc13fda7482_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:607c2d9b3b315984fbeb0a08655bd3b3e3c013d34f936c36769f01af91ec2f38_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:72a0594870372a1e3fabb1639a0681188c93cb15cff6ba0e90a1816664f5814b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:c110db5e346289e0febe314cf59de0cdb29e35b1158e5311bcfd4708f805689f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:1f308d25a0bb7d259424825f0e3ca8aa06374c9e91e3cb17aef9a394aa661ae3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:30bbe697042e86426695f71de19b871f8c58a61507defed82bba097dfbb8ce49_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:b783331bbff3e51a3ac1e14291bace18459f30f8f9287756728aab828c671829_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f2884d8545c67d02248f09a00361a39208f45da719862253698fcc5852c82e15_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:1173dc2c594be31f25fd736c5b8a19d6e7bd1364ab39a66e45220f58806c81fa_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:25ab129d2a46b74bc9024f0c6df336667fd847affa288972db593edbecc14c33_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:63fea1201156e1d85ae81f7f3c86395f39b055d47ec0b55a1d2acb2b3c07829b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:e18fda73ee985dd6198941d36742166ada3a66462fa9c50c84c0622d5a5da57c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:60e313c868a629d1c4e446fb8de1a3843c480710cf6dbd7e8a45590e7461ad0f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:91ea287bb9dabb7a2397313c5ee42cd42e6aedc12488a624401040c4451768c4_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:e1463d7a0e909e1c90dc276bcaa10b3bf8e7ed0eff2c6807c6a407166619a3d4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:f167a6137eecb7f762a615d082f57e521705635d880c48de7921133121e580dc_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:a48734a03f596fda35d6ac02f32e55233a58df236266b0afc78c564ab2eb14f2_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:31e8978d1f7a24c3e70dcc12c93dd5e73311b78e528f73beb020ddbe3270e07d (For s390x architecture) The image digest is sha256:7e6a77a66b2f93afb2108ada0617d26dceadb130b58a5d3070142a7f6aca4ade (For ppc64le architecture) The image digest is sha256:af37b07cf408da430bab837ba8a0083934fa99df14efd7855240b77d9e102f0e (For aarch64 architecture) The image digest is sha256:e5d7b0851e8cd4378bc810b2fd1f19489836ea186a6678eed1add4bed4f08b13 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2025:4427
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2347423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352484
- externalhttps://issues.redhat.com/browse/OCPBUGS-54737
- externalhttps://issues.redhat.com/browse/OCPBUGS-54946
- externalhttps://issues.redhat.com/browse/OCPBUGS-55148
- externalhttps://issues.redhat.com/browse/OCPBUGS-55195
- externalhttps://issues.redhat.com/browse/OCPBUGS-55270
- externalhttps://issues.redhat.com/browse/OCPBUGS-55290
- externalhttps://issues.redhat.com/browse/OCPBUGS-55293
- externalhttps://issues.redhat.com/browse/OCPBUGS-55343
- externalhttps://issues.redhat.com/browse/OCPBUGS-55346
- externalhttps://issues.redhat.com/browse/OCPBUGS-55361
- externalhttps://issues.redhat.com/browse/OCPBUGS-55364
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4427.json