Red Hat Security Advisory: OpenShift Container Platform 4.18.16 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2016-9840 — zlib: Out-of-bound pointer arithmetic in inftrees.c CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:31865d831511aead0aaa5f7353ea98a330d9f835586f8f6583dca96ff63fd9c3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:3f859f86b958592aa005e8acc931bb18f226bfb6ac8685229a8738656dc6427a_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:45a555c0b7cb3f61703f4d43dfcb66d7a9021db11ae1bc1352a95685b60a28e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:9d81bd49689c47bb68018471eb075a1abb69b2af4240d6bb57c93e7cd685c77b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:3dfba853ba93140da5ed9159f8edd54aed9b22970b7f4bb71df5c0df36a0541f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:86235b10d68dc66849dfd95d4a9a55d3910d679c6aeb47e8c1b47ad954e9f548_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:c733a73d7ec3afb3d5e2f8e8687caadaf4eb29114656fffbd547e970f43615c7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ca9696f6e36d538e9f1073842532a664ea63448d42466440c0b3de6bfd3e69de_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:0c8fd1a23824b17fd5eff36e54b9e776ec3d6b6d530882296a1a31fc73cf86be_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:36d14f8a2e7d69509c3586b6e50933398d478c830144861e08a20ee381b49ef8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:67730bb18074f5142142f33c1c19148bf7411b6a9d9af6a4a9b16b6b46dbdc1f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:c03d201c94d29e88970637ac1d6191b98ccac3e4f03f5c0a2e69ac0373ecbad2_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:8af7db47a1dc69c74c9930fb6962a2714f62ae68eb6db0da142eb3fee9e92648_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:e6eedfe873e473844568480545b608fa933d7a675f734555e468901cd2e81817_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:f5e79fa99b35e700122482e3cd0bb7cb089503a6f2e24b26a633500441946cf9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:fcdb9f755e0da9fb75afddb20c4ba45849c15409c4711f842df2430a1aff6d67_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:4afacf3f23e29ebe2afa334204abbc45a1c4c1cc47112bf6fc96aa5fa6c3452c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:7959afa9e21337fade7f6f002115282872b58fe9ace0fdc265a213756d575666_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:7bc36fab97c2dd4082f4629624df6be155a65909ff5261ecbad9d8f49a84ba8c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f2330886fe32a2a817492d03acb361ff94d996bf3e9e2e29546d0c77fc8454f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:51dc4cda49731ae6afa191b5a5973b5fc2ac51931553adbc7af850c70c279133_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:7d0234b52e232a849c2081aaa8be60c44a4ac3929b6156b1fcfbbc104f7a5881_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:879d1480cb7a591b592eefb4001c8916088e4c8ba4e55196b1258761e562cadf_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:894ab9733c5707a5eacd0bbc67ebe9b21d21a00796c8c0cad784895204b10c5d_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:00a9ef348c6b4b75859a4892e4c7a981873bfe4d77485b799522bc278dd76707_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:7df0591840d11fab900284faed28ae111c811b3eeefa47d4defdfdf65fd988a9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:98051884acf0e2ff933c6af016af37382e7b0fa98ca5dc6589995b6c2a1e51a9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:cabfedcd5708974f3005f0ada92cdc71ea3420e09a92c2c9c7a8a9f8f51a08d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:2e266af6949610606502deb739826ff26e8c97841e05ebb9961fbeae2ef8d70d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0dac222584991f89a123d85e8c3055f0056e5876fc209b8d4bea7a59e7504d59 (For s390x architecture) The image digest is sha256:33f8af4513fc5394c3210f5a3b447f4920cc9bd099830479d05f3799ae80f0a5 (For ppc64le architecture) The image digest is sha256:8e522017e74e046cf57a76545fe6cc2cd742a79ff17bc22d66eee5126e5907c4 (For aarch64 architecture) The image digest is sha256:12d59fd82eb938b06896679cc9a821651a2b05fdf74d0d23e528977f0fb11461 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2025:8284
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1402345
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://issues.redhat.com/browse/OCPBUGS-52189
- externalhttps://issues.redhat.com/browse/OCPBUGS-53142
- externalhttps://issues.redhat.com/browse/OCPBUGS-54337
- externalhttps://issues.redhat.com/browse/OCPBUGS-54532
- externalhttps://issues.redhat.com/browse/OCPBUGS-55638
- externalhttps://issues.redhat.com/browse/OCPBUGS-55840
- externalhttps://issues.redhat.com/browse/OCPBUGS-56043
- externalhttps://issues.redhat.com/browse/OCPBUGS-56097
- externalhttps://issues.redhat.com/browse/OCPBUGS-56217
- externalhttps://issues.redhat.com/browse/OCPBUGS-56401
- externalhttps://issues.redhat.com/browse/OCPBUGS-56431
- externalhttps://issues.redhat.com/browse/OCPBUGS-56524
- externalhttps://issues.redhat.com/browse/OCPBUGS-56627
- externalhttps://issues.redhat.com/browse/OCPBUGS-56654
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8284.json