RHSA-2025:8556HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.16.42 bug fix and security update

Published
June 13, 2025
Last Modified
September 8, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-6538 — openshift-console: OpenShift Console: Server-Side Request Forgery CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:69d803beefab079806a7e194bd7f3f6a76a5f8a4c1dc1a26790639e77bdbe06b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:9cd1cb8a1e0b06e7103b0d14b7ca92a489bf8b29466c7dbcb7db58e70bf92b7d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:afd4a024ce06b870932c6cc3dc81f1e33be26cb501044d080e3a2157f3ce9902_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:d9a3fcb4f17ab174ac211815bdff12aaaee98788d32bd00ee7fa134b6a466ad4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:3f1a8e09731948f301fcf8da68e178b1b1246e1ac4eaf6fc94364cfc2180ce60_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:9791d79b5e134f3c523f08ea56e1ee352d16170bd6917e67f970080039eb5606_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:d1b5238adc6d4ca5c7946554dc8d8fc63652659c3f39ec302e574f8aeb963072_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:de6af9d60fa061b2f0ff3f1b22ae3b0d30e5e561296bb9e8a859083d1ce0d281_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:169409c7ede97ae0e2eeffab2839957aa83bfdead82732eff32b1749d97e7bd6_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:456e7554cd9ddb098c502f5751eeee5ad4869fb4474ecbcd45f1634de6a311b7_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:50e97ce4ee956eeb74b4e2af7d9be4b207185be330a95e78f457305f2b991b6c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:8fa593ca6e1af7aa5ed21dfd3227a4cfcf64a766789fd91ee3b28f81400e728a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:5158b86271e284e4fb438e8c14029357d85898449eaf71b4e43af1173234205a_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:68498de6f4e2493aff4ade27a55b662d83581184bbe08d37fa0234544d73f239_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:89f90a001006f4f0a3a82458cee4594237e027d85a6b36c795c94b4751c4552b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:afae916b038eab8a73576537a1946150e164ccb062cf579a7b73207e02e321af_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:0dac9d81ce695982138ea9745654cf9bef763cb0bc375ea0414565be6c1b351b_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:6e22d9c90f344452e0952b8a74d088772bde5693ef3d229d39f6714378f41304_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:94074607aae43d71f1e652d6282c61459ee74562eb1f38a680e02627036440de_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:a4995d3f1f25030e5af6d0f3ab9fe0a84d5e7e12c6c9b780874b93ffe13a0b89_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:8544763e0050ec4e2939040c6864f6ee9d0161fc8a5f93af10fce28d337ab7b0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:889c82a9208b62a0af09dc1267d7e8346f52e9df618b2d0f6d83dec5f351e413_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:ef208e191294ba6ffd9258e6bf45305d9995ac6acea52d5104613872d664ff98_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:ff0959df625f89617011bbdcdeffe5a77431a09db5c1cf21632178ba30fce59e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:10f84b6724f62ad89159718613750e418b932e889b18baa40c3544914ab2da1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:33c1555521b677241fef01879e0d2f4d4cd1a068d895ab4aeb2ec964000d41bf_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:6c6e29eeb20a40b578149718e5a5ec283ce449e14b058224510e80b616bb80b6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:91a9f6a72d56aeafd4387f633e8b7e049492aed49305c5ff9de0dcc2f3890fa0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:132cca7fbd9dfb1fdf75fe5ec89b04257da4a05e1ae8515d18187c85dd245403_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2fa965ede9ab6530be8a2e780b484d487c2b3ea4354e84cec680c22823c255ab (For s390x architecture) The image digest is sha256:8e59e0fe81ef2928aeae8f2ec07fa7953d50c32bc73ddd8596b784027f2aa2e1 (For ppc64le architecture) The image digest is sha256:c8cfaa3eace6cf14df1cbcc0f9233db687b604416828f561b899a7b653c60a77 (For aarch64 architecture) The image digest is sha256:53e34991043e4f76b4c4f6b604205a1c37918367e674c8350567da5794bc4619 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (20)