Red Hat Security Advisory: RHODF-4.18-RHEL-9 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-29041 — express: cause malformed URLs to be evaluated CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-22869 — golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products109
- RHODF 4.18 for RHEL 9
- odf4/cephcsi-operator-bundle@sha256:8fe453c13e2512584f376df5e68b0349279ae48b3d80bf30853d0e29114172d1_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-operator-bundle@sha256:b7b818d10993d363959d6dc050267122e3151a3cf1e2dc33e9e3da000a309892_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-operator-bundle@sha256:c70c3bf6f04381731a7c8b362e84c0562db8bfd035b0830876da9867c61d5913_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9-operator@sha256:0468019ad7726920c8b8308a4e2b23e833d1447d78e4a7994297899eaf96cd67_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9-operator@sha256:8801eb57d77777f95346f2d544650952fb89c3c364d77b775b20d203974a0325_arm64 as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9-operator@sha256:cb751b6f6f0384e16d7764df1d9240d7dc4b7deb3d9a58a4ffbdb67cea3932d3_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9-operator@sha256:e627398b6cd1f4eae720de593a826d6a8ff7dec4acfcb01a1003592044c59c8a_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9@sha256:5bce68f3ecb18da15dd044ef9d83cc3be06ff4d35f0d8958e166197dc300b5a7_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9@sha256:6a5a346682e532a42d0d1df3e11d8c16e01a8c22d03a65743b70c8bef2ef17d4_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/cephcsi-rhel9@sha256:b12969001d0ccbdea864ae2b95cf2df109a9644ba294171a2e286a4e24261717_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-core-rhel9@sha256:20f211424d72d67d9e05e0c5fe0a27291673ff0f4223677a8f25d8bf333eaf3a_arm64 as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-core-rhel9@sha256:838edd5022e35412215026b3fd7f87a681c7f6925d927074005c34d88ff991ae_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-core-rhel9@sha256:ad5b8a59f261bb6d5d82327cfbb8d90771dc0df4daf6daec163214c8f09b116b_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-core-rhel9@sha256:cef0430b3f1f3e1b0f728a5384c73492f9addbc8690868285be07e7eaa04c534_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-operator-bundle@sha256:9034d6f37fb5bc4fc0a5e3b58a995f25a502f0d396c918f18d81a6d8d852e741_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-operator-bundle@sha256:980b36c7905338b274045078a5ebfac2e20a52c7a9d6133dd104ff47c19a95d8_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-operator-bundle@sha256:f7981eb58f8f965e1eef8fef50bf58e6fbf92c54fc5c376d34adeff39427db68_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:3d46991237b01a405cabf10e15072edd1fafefc0641b120a6578b40bebf62efa_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:851cf1c9d24083d806a9da2c4f8dc25ef67dfdf18ad882bf0980fab0d7d824d1_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:f1c7a74c9580a7d6725f1fef5aea3467e3bc6548c947e9804b9b9d6b9c56eb1e_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:fc9475589ce8ca4f74014d43a7692a91cd1b2b30c9d3b73f38155224734fb4e8_arm64 as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:00e88ad3e5d29ac067163e93cb1ee716e8bf63bf90cd2ff09020a217d055db28_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:398d2529a7a226cfae3aeba3a83c9d4e1a92bc5439fdc37f98fff895ad1efd7e_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:acbffcf670ccd88666bf75b2d8b2be1e38dfa990b6ddd56a586ca7c74df7b37b_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:4a8a9b9f0f910df0c03bade56acd47f4027cb2a603cfb710dbd95b366d56992d_s390x as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:a7785285506015834c240a5cfd2416865d77d5bf261d6a8b9f5bc4431f22cb2c_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:c182b55222bec9f15aa56cc479eb701bb8fb91a291a5d6ba5c3511a9f0a10866_ppc64le as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:755db8e93622c0edf5eddacb005d2411d09384425dcfa10690400c6dcdc5228e_amd64 as a component of RHODF 4.18 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:dc4db8e33107450531de8c9bd1ce22bddccbb6bead8fe784f8bed7107ec32733_arm64 as a component of RHODF 4.18 for RHEL 9
- +79 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: This flaw can be mitigated when using the client only connecting to trusted servers. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2025:4511
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2347423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348367
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/DFBUGS-1798
- externalhttps://issues.redhat.com/browse/DFBUGS-269
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4511.json