RHSA-2025:9895HighCVSS 8.1
Red Hat Security Advisory: Red Hat Service Interconnect security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-12797 — openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2
🎯 Affected products7
- 9Base-Service-Interconnect-1.4
- service-interconnect/skupper-config-sync-rhel9@sha256:a8e4ab9a71183698ccead00ac54c354e6e749b0e85d82b6b3216c4e686944aff_amd64 as a component of 9Base-Service-Interconnect-1.4
- service-interconnect/skupper-flow-collector-rhel9@sha256:51f9a24e3dc9b1d47c474fec5389e1e166f1a52f49940ca637755ea4fe5fd204_amd64 as a component of 9Base-Service-Interconnect-1.4
- service-interconnect/skupper-operator-bundle@sha256:0f6c6faf7fdf7b6d69bc5cc4b0266064d0035e295d0562b957d95c8c81699f2b_amd64 as a component of 9Base-Service-Interconnect-1.4
- service-interconnect/skupper-router-rhel9@sha256:84ea16f6b12159c0941d149dde8bc09739bfc5313f9d04a0ae8008aec25cd4af_amd64 as a component of 9Base-Service-Interconnect-1.4
- service-interconnect/skupper-service-controller-rhel9@sha256:aa8406cdd6f52d3262575989db783e165986054152b24a82260fa493a93eb297_amd64 as a component of 9Base-Service-Interconnect-1.4
- service-interconnect/skupper-site-controller-rhel9@sha256:5b6d67ddcb01f1ad961f1593bd29458d758b28c4166901d0a0d87fbb937b34a9_amd64 as a component of 9Base-Service-Interconnect-1.4
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:9895
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_service_interconnect/1.4
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2342757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346421
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9895.json