Red Hat Security Advisory: OpenShift Container Platform 4.19.1 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-45497 — openshift-api: openshift-controller-manager/build: Build Process in OpenShift Allows Overwriting of Node Pull Credentials CVE-2024-55549 — libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http CVE-2025-24855 — libxslt: Use-After-Free in libxslt numbers.c CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:26be2295ef91410fdbb92bed41597f2052b4f73bfa4c44515b90aa4fb209cd3a_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:65809d0a2a0f839c42385356fc51334cea824774a70af081c1cb8df413c68e27_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:6f37f3798d8a36ddf054ebef1bb6e7c1526a82c3daa5a8a91601001ef7c04f32_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-karpenter-provider-aws-rhel9@sha256:ef5c386bf4d6aa6e83f7cd9df6ab9a497ca96a63d2df0847d5151ec6585dfc32_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:26629ae1b654050aaf7849eed509307ddd8c98bcb8e661cafbb941c809162268_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:375392742bb51ae5c577c92a81054d132b16a1607e2c1ab6115422b4f55194d4_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:aa7efd2c5e0c25e3b43e37e6180d44c1c4ac956ba0b6adb72233aa8682e30bac_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/aws-kms-encryption-provider-rhel9@sha256:e5eaacf4f8ed56333b319aea6dbf414a9fdd2e356a605923763bd71183a78221_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9e375e87f33b699b4c55d3ffe596b8e12d18c9ef8379672edee0835c2d821d58_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:b5427669c1c22c3b21333adf8f9e15efd254cb153fbe908a618553d71423bbf1_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:b598efa45cba137d37047f2b13ed458f194af16d3537854dc8eb04317616d423_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-kms-encryption-provider-rhel9@sha256:c3803dc3faa24cb74b8bc50c0607a514999dcde820c7d97dcc60486c06f0db69_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:06794f47a7eba42b2e0f159721de00fa0dcbdad1e59fec07f70198737982bc76_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:2380219a68dba49344e72b5dcc1e52865e16cde1bcf6c7205af0639d2e127ae3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:bf25fb9dbb6b71f39abfd419b9186f3be49e09f974d0ad22c6e3a7a63be8a950_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/azure-service-rhel9-operator@sha256:d9257ff72ebca623453f9453f3daf0abad4059b98cd4ea0289376f89a7289a95_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:1d937471f50508e56487ebfdd60985d57a69eca8790084ae81a596fabb884f2b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:21978a74c8bfd012cba236cfe9f93d78363bbc0842d7947cea1b97358f28c4f6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:22e41dbabfac8187a73be4958dfdc0cc098db00dc570773fb9dfd9fb7d3048bd_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/cloud-network-config-controller-rhel9@sha256:49713d2d5ee3accaace9a7182a6ac4700ca4bb64f131fc57fd6219b1318105fd_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:12efb4f1a5c9452a174ccdec4e1128dd9ed430830e2dc99df5b5e0cd89c21491_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:374761216d77e147873b48105ff0c436a8cdeb763f20a42201de14571c996fb3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3c58c276093f74187677cba3679f7e77192908ab74c7d2acfff88438130c9be5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/container-networking-plugins-microshift-rhel9@sha256:aba10a3b348add748f26590b47f064ce6203d7d9152746cdde4ab6674a9ca786_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:24d317b503677f188f37e88dd9a628b968afee231be37b84f582499b4b553a18_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:5cdac8cb91d24782a8b5a66ade3212558582a8b8bdd67519a60c2705f9317b1d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:979de1b86e8087cf35ed4b31227c97a25974fb7d1d08d14fbe96129fdf3642e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:f5c60c3ced1fa4027a1ad8b2d51f0b95f830d8e91ef06f07c8289763e4a9b4d8_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/egress-router-cni-rhel9@sha256:6a7a8303d54828c1b0e0931f5c28ecc6d2210d3b065c027e708449537c0ae0db_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:4d7f10e383deb0c5402f871bf66ebdcad6bb670cb3cf1668bfec5166c56f3196 (For s390x architecture) The image digest is sha256:d670092bd3e9c7449edf5b718ec5910a6982a38f34cb4106c8f0132cd56c416d (For ppc64le architecture) The image digest is sha256:da4444f073479d98a21394e497644cc0f5570ab79881575a4b58ad363f317057 (For aarch64 architecture) The image digest is sha256:b43a63a68f21da74ef93ed8abbb29237daa66d9df559d2071eb931d798041cd4 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (60)
- selfhttps://access.redhat.com/errata/RHSA-2025:9278
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358493
- externalhttps://issues.redhat.com/browse/OCPBUGS-55701
- externalhttps://issues.redhat.com/browse/OCPBUGS-55798
- externalhttps://issues.redhat.com/browse/OCPBUGS-56100
- externalhttps://issues.redhat.com/browse/OCPBUGS-56187
- externalhttps://issues.redhat.com/browse/OCPBUGS-56191
- externalhttps://issues.redhat.com/browse/OCPBUGS-56470
- externalhttps://issues.redhat.com/browse/OCPBUGS-56475
- externalhttps://issues.redhat.com/browse/OCPBUGS-56633
- externalhttps://issues.redhat.com/browse/OCPBUGS-56690
- externalhttps://issues.redhat.com/browse/OCPBUGS-56764
- externalhttps://issues.redhat.com/browse/OCPBUGS-56779
- externalhttps://issues.redhat.com/browse/OCPBUGS-56780
- externalhttps://issues.redhat.com/browse/OCPBUGS-56798
- externalhttps://issues.redhat.com/browse/OCPBUGS-56806
- externalhttps://issues.redhat.com/browse/OCPBUGS-56837
- externalhttps://issues.redhat.com/browse/OCPBUGS-56841
- externalhttps://issues.redhat.com/browse/OCPBUGS-56885
- externalhttps://issues.redhat.com/browse/OCPBUGS-56890
- externalhttps://issues.redhat.com/browse/OCPBUGS-56899
- externalhttps://issues.redhat.com/browse/OCPBUGS-56905
- externalhttps://issues.redhat.com/browse/OCPBUGS-56930
- externalhttps://issues.redhat.com/browse/OCPBUGS-56950
- externalhttps://issues.redhat.com/browse/OCPBUGS-56959
- externalhttps://issues.redhat.com/browse/OCPBUGS-56962
- externalhttps://issues.redhat.com/browse/OCPBUGS-56967
- externalhttps://issues.redhat.com/browse/OCPBUGS-56969
- externalhttps://issues.redhat.com/browse/OCPBUGS-56970
- externalhttps://issues.redhat.com/browse/OCPBUGS-56978
- externalhttps://issues.redhat.com/browse/OCPBUGS-56987
- externalhttps://issues.redhat.com/browse/OCPBUGS-56991
- externalhttps://issues.redhat.com/browse/OCPBUGS-57007
- externalhttps://issues.redhat.com/browse/OCPBUGS-57020
- externalhttps://issues.redhat.com/browse/OCPBUGS-57030
- externalhttps://issues.redhat.com/browse/OCPBUGS-57039
- externalhttps://issues.redhat.com/browse/OCPBUGS-57050
- externalhttps://issues.redhat.com/browse/OCPBUGS-57054
- externalhttps://issues.redhat.com/browse/OCPBUGS-57086
- externalhttps://issues.redhat.com/browse/OCPBUGS-57110
- externalhttps://issues.redhat.com/browse/OCPBUGS-57128
- externalhttps://issues.redhat.com/browse/OCPBUGS-57137
- externalhttps://issues.redhat.com/browse/OCPBUGS-57149
- externalhttps://issues.redhat.com/browse/OCPBUGS-57180
- externalhttps://issues.redhat.com/browse/OCPBUGS-57185
- externalhttps://issues.redhat.com/browse/OCPBUGS-57189
- externalhttps://issues.redhat.com/browse/OCPBUGS-57200
- externalhttps://issues.redhat.com/browse/OCPBUGS-57208
- externalhttps://issues.redhat.com/browse/OCPBUGS-57265
- externalhttps://issues.redhat.com/browse/OCPBUGS-57279
- externalhttps://issues.redhat.com/browse/OCPBUGS-57283
- externalhttps://issues.redhat.com/browse/OCPBUGS-57284
- externalhttps://issues.redhat.com/browse/OCPBUGS-57301
- externalhttps://issues.redhat.com/browse/OCPBUGS-57303
- externalhttps://issues.redhat.com/browse/OCPBUGS-57319
- externalhttps://issues.redhat.com/browse/OCPBUGS-57352
- externalhttps://issues.redhat.com/browse/OCPBUGS-57384
- externalhttps://issues.redhat.com/browse/OCPBUGS-57420
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9278.json