Red Hat Security Advisory: OpenShift Container Platform 4.17.28 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-55549 — libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) CVE-2025-24855 — libxslt: Use-After-Free in libxslt numbers.c CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:03c4ffb6e1ca068624a9bcaa5ca21f0b67fc60508f382ae95521c6a03ae8afb4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:9ba0c5d8195237e7cc9e37ae735a7841a3fcab2fe12e6ef106da61a6e09db0cf_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:d94dc7200bafdfb39d5d7ce555b36d59d17a0add1091babd769f33dfdb854cda_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:e97e40543c09b130e3d36eeb5800d9d4ee989f5b16314f33534b32a2b11b39b6_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:08021be0c69cec642238d8c152f39957660651ec5714d7ed17f2f27c31e3db6b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:a8c81f1ea15f8625cee9ad826d2263d09c17b6fe7b2941579f8914ab6ead1689_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:a9fa50ec982340d9e61f130c74457bf6809d843c13a266d140617f17ac1bec0d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:cc38a9ba49ae414e03acd79e4d3b97977fe53872870612073fa569f6ab702939_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:2a6eb863736abf5c2d7a3f7c2f324e71e25a7dd9a0d5219bd9666c136e0fa863_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:5153ada0a44b00eabb71606b7144de94c4d5de7eb27dc54cbc9b729bd2a5093b_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:698211795dbabe068f87d21f624e09d28742483015be770b1cdb5c6138283b69_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:b5ed6c1824fa24f8dbed30ccc81428285823d97e15496c43c433db55985fd9c2_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3bb7db321e0bcbb3dadc7a1c9f350e69657249f4823e46184c7001f17aac7d1d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:44ab8531897438f9b25f0b6d90e5b224e3928a3f12f8b24dd18113d7bbb40ece_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:4c57864ec6554cf452d24947d6d1387f8c4e10a0b89508279b1bdc12a1a1f50e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:6fee0ae68857abb3ac5357aeee9fda4cf8cfa60e061b6240d2cc266156092d07_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:8edadcbdbe43b80cea7a3076897e893c8e3d974c6cea165cd8ecb00e03d1ce78_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:b676dc0dbf6c39a7b3b68d3ef21cef981927255ba8ea45e9d1715396dcfe29ff_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:c9e05849c3438f54571b43555c775401f5a97abcf7d328c6b04387e8c1d0b312_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:ca540412965a47b91836a1137e49720be6ee3ebc2b7c54b67864beaea76c2e6b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:07d4ba54630d432f37576929be29cf02ef09a47bee91a63f58001f9cd4acfc92_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:9d5ce7ba2746d808b7bda9c491ecbaa158917b2659546eb9be7752d14a79f845_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:deecbd903551fa42eba84fbe2051794146cfc426cf6f151a2d8b0e26d99909b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:e2acac628dad896c7b4ee0617847b6e5d8051b5cc0a0add05734b2f179afcb59_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:382bd4ab43e8572f129c0cccb7778c0c35e1648cc48d142fcc4f908cefb56a39_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:530a9dff7076b84825ddbb0fdc1320140ee5f01de559b2ad166032d58dad6dc2_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:6f7e5612f7cb6c85db355eeba15164a0445fa58857b857506cf65b873e4b8174_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:ca10f64ab5f5d9c5f2dfdb5241fed009ec9f37bfd7126ad790a07f9c1a418a3b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:233be71aea1d6daf6162eb3a7f91c2f052b47e3ad1d8778e519761c678a32327_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:035baf97e4c715fc1afb681a9f789d99ebaf568b2656584d59f72962e0d14bcd (For s390x architecture) The image digest is sha256:ae63030ebb847f17ac0d2273f55d5db43df6b9f324197573bd9d2fbb7403036a (For ppc64le architecture) The image digest is sha256:c693db40e8d19847cd4bce1541344cc93d828221c029dc7ddeee4c829a351a12 (For aarch64 architecture) The image digest is sha256:61a46e56e230e5869af207484585a5e61141e322d539616422ec7e61bc4ad137 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2025:4431
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2350190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352484
- externalhttps://issues.redhat.com/browse/OCPBUGS-52314
- externalhttps://issues.redhat.com/browse/OCPBUGS-54830
- externalhttps://issues.redhat.com/browse/OCPBUGS-55118
- externalhttps://issues.redhat.com/browse/OCPBUGS-55184
- externalhttps://issues.redhat.com/browse/OCPBUGS-55202
- externalhttps://issues.redhat.com/browse/OCPBUGS-55239
- externalhttps://issues.redhat.com/browse/OCPBUGS-55344
- externalhttps://issues.redhat.com/browse/OCPBUGS-55355
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4431.json