Red Hat Security Advisory: OpenShift Container Platform 4.16.40 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-55549 — libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) CVE-2025-22869 — golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh CVE-2025-24855 — libxslt: Use-After-Free in libxslt numbers.c CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products126
- Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:860ce0a83db151e3b13f8c01b568074bbaa85eb0de52cf50daedf822d377b269_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:a9d19540219faa65f48a4e94177e6fd8da3c358e6e2ac05be96619c580193dd9_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:b295b56aa74cdc389411ef6ded30ff786795692fdcb75aebe7bdeeaff0dcfab1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:d65c47bfe03dcb3567d8063fd7fc0c94caf176d517163e54a3c988a6ea5ad10b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:261465289dc4d63a530f77027dd35bf504dc2652174be990c92eee8987b939d0_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:46459c77907193a033e9da0126ece251b587fdfe021ebea5b04e3634d9b879c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:7d6dbb421a4af40f2ff22f3835fa62f186723459c5d72b53dc79873388bad802_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:a7fd3d4836c4839b3229bcf91b51070e5f7f75535f92aff9088043299719c418_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/openshift-route-controller-manager-rhel9@sha256:081900c035d3b229b7addc2cfe371144eced313162d7c6b6c6bcd644f1023f36_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/openshift-route-controller-manager-rhel9@sha256:7c83d4bf0a7bd4a501268c9587fcbc0fbcab005821dec3dd16d665c4fd980840_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/openshift-route-controller-manager-rhel9@sha256:7f22893f2dc997fbf488c1d3149de6c405c5e9b12c80f0e443132ea016a3adf3_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/openshift-route-controller-manager-rhel9@sha256:964c654492fb56da61e38f0e3cbbd4f57adbf0db93e204de42556ddcfd3d3e7e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:2a9db51050d91e01c42d97066c453c6d092c63a80774e2f7b5e3a843e1f437e7_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:7b4386e6a2988a618dce651a0ff4054e3c42f1f4d26b6a3fce2e432f0f80f875_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:b47452eb4d6c7c4ac659ee8c1f40e5af24569d3533d8e445b187348d6db44b58_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:fb29de1b8e2c8cb210758886c40cc788190c6fb1e94daea6dd7a7c4d01ac1d25_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:057838eb4463cf16b2fa968074fe0e9edd062bd68d144bfb6ee768f1cc5c67ef_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:2d2af14b1c1e75bf65bd8b8740a3a13328fb2cc9268bb39d52e220d86175dc5c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:6072f07967b310d115cadbfbd9c67d9afe60b57cef3618726ad74a1b0bfcbd79_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:de5e93288c8ae6cfc17191d4e1c8f815d129594e5264e3a7684db48bb7ea29d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:1423b60b44a2124fa11036763e27567cb2b75bcaf8feb145b569adb96c244ec5_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:92f3e7a8cc1130f04544080ab3d1ad78d5a7a9cf32f5312f916ab21c74cfdca9_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:9510614b7dfc0e77a5da768bad7a5ba20f2d152158d6bbefa9db65a8af9549cb_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:c50264f7bd22f054dcbc3d69aead131c768f08653bea2e264225c6dff3add762_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:528fa34b576ab6db4422214dd7a9d28b736c0daa71aa14d7410cecab61069011_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:9f693168cd9f36f7a838d4e54bde81701aee7da059581ef67cbb03c7683e03f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:e201d43af48d9cb61f8e9cbc4227d7c2b4dc193e045102ca75b3f96952201d2f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:f9d94d6da2f014ed2301efc2d0f591c5a18bc219a175e97cc96a3556acaadde2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-utils-rhel9@sha256:30e0a477fa0468046efa7bc0dfa1532e0ccdf834e616623ac50b6a7bec94746d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- +96 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9871f990d9f956d735e85e2040101377d5fd7cc4e62e8f54feb62650190216c9 (For s390x architecture) The image digest is sha256:851bac58b8ba11752792467aca680d41a1b306ba9e4973dca4b79d4adba93e55 (For ppc64le architecture) The image digest is sha256:cbd719c4e8627d894621ffbfca8adc31669ccfd63411889b58810111bcf34b00 (For aarch64 architecture) The image digest is sha256:9cd61312dbd5619bed52ea20afb0fb6b6634f4c76394fea5b5187fc4083e8027 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16]/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated when using the client only connecting to trusted servers. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2025:4731
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352484
- externalhttps://issues.redhat.com/browse/OCPBUGS-35040
- externalhttps://issues.redhat.com/browse/OCPBUGS-35921
- externalhttps://issues.redhat.com/browse/OCPBUGS-45142
- externalhttps://issues.redhat.com/browse/OCPBUGS-50581
- externalhttps://issues.redhat.com/browse/OCPBUGS-53317
- externalhttps://issues.redhat.com/browse/OCPBUGS-54786
- externalhttps://issues.redhat.com/browse/OCPBUGS-54818
- externalhttps://issues.redhat.com/browse/OCPBUGS-54914
- externalhttps://issues.redhat.com/browse/OCPBUGS-54942
- externalhttps://issues.redhat.com/browse/OCPBUGS-54990
- externalhttps://issues.redhat.com/browse/OCPBUGS-55119
- externalhttps://issues.redhat.com/browse/OCPBUGS-55124
- externalhttps://issues.redhat.com/browse/OCPBUGS-55156
- externalhttps://issues.redhat.com/browse/OCPBUGS-55163
- externalhttps://issues.redhat.com/browse/OCPBUGS-55171
- externalhttps://issues.redhat.com/browse/OCPBUGS-55201
- externalhttps://issues.redhat.com/browse/OCPBUGS-55248
- externalhttps://issues.redhat.com/browse/OCPBUGS-55345
- externalhttps://issues.redhat.com/browse/OCPBUGS-55378
- externalhttps://issues.redhat.com/browse/OCPBUGS-55684
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4731.json