Red Hat Security Advisory: OpenShift Container Platform 4.16.60 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4b0358e16d845b50b56a29ddbdc0ef6f1ba6861f14f49976a8dd4306e003195b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:bf947291c5d93818efbfb9ae7c29e01d1c9700e549c8606d6f3c252759c0aa61_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c52719498f8ac30160b0e77234ab27ecfd7d3b3b6e37d4c401f620b2a353abcd_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fbf8ef1f4b1b3b353de8024db821d36a4eb015414d9feadf6219fb71df567ca7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6dab0b2fb9b6a8233574e2b6755602ab240bb391d199eed032cf3f6ae8e34892_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a13ed9382d3422bd0b0a6d9e3a346ad6528df5643f5bf81d305f45da8c1dc4c9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b774ddc29d0a1f10d76dd2231b8db55d9bbdbaebe35224da220e2f44009d80b3_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cae8edd9caffb4de8cf29747cb77c4bd58aecf0ba391ac0903b056f661e9eb27_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0d59aa8bed4a9038d9dfed2a6b33c1b7cd8ae8bac90afd8edf6e96ea968a1400_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3e40adf22c8efc9ab30c8cd921347ed70a3548c5190ee1eab8384cf67b3ab4aa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8885e771c6d88d5d5c8f223f2503eb17cb35e0db74d0b154251685cddc22032b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d9578af47ab0520b3a95e7c625c4627b7e60414c9cb8046c3aa32242facb35d9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:21326785a6c32bdc6983b9d3b3c0e6971cd395601ad4b278d2e9c36b6f2550df_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:61fa7067d33c45979deb31d69f5de418130031dd3f0c7c5dec844f0bd9d448ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9ad957be82b1d213df763416bbed293f3e3f5cc82c18423123565b4de7d048a3_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a577262406f4334ffd2392ed35df5d0a5929cf47ec60d07c44326a786f17515d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:10165db053c61ac5ce3f46039f75704bbef95131180f17b1e9f31cc126fb1f37_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:23cd9b669ae27cdee743d9e93b87590037b5a5b48d6b62c41985043794d4b397_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c2f1780909d556c79d3dd1284ebc9eae5dfb85f0115e642b633d17a80a0f3fb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dada4345a37d75dc57b9affaf61365836a954cb216528522e23609f92bebb03c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:4defdcddd562a517db65d5fc15a02b71cdab4dcdcb1e180982cf2ae7f8911d8b_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:59e5c8f011e73731509dc671c65047463f5a5ee6c189c0d60b11b67b4240817c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:bcc93d031538370b93208aa4b402114ee6129df27ef0f09c3ce217627f6920b6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:fedf04db6bea594305e0319bcc05734f4af1f3eee14855b86e4c5b82fcdb0216_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:7f9f837afbb4e165d4727e7c80602a12302faf5961049fc48fc3d98e6fdb4e53_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:8f02e0ff7179473fbfcd08104de535676df06c8371ec911d175c8555451d0696_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:ed37d969a33abb64a3c02a6936ac8ea1168c7bd55618f4926b9f94a1b7b97f93_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:efe2026e032533d325ecfca2bc97e1abf6b68deb531ed434cd69fae57c83ecc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:4c8faafd66e50b26e290905b5f7d11dc696c8067b12ddbc349a1f22d53284363_s390x as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8f474f0cbba5f3f13bcee65257ac42d602fbe9ef9878f1c848d5ccb5e76e869e (For s390x architecture) The image digest is sha256:862abccd03619ecf96dee802e8b945ba8c312bba2001f2c4bbd5f9b0219a6d24 (For ppc64le architecture) The image digest is sha256:09e9c280deb2d95a99dde8e55b29c12b997fe4a005d66b5a7dccfb0266ea516f (For aarch64 architecture) The image digest is sha256:9be7ab09eca0d08dcc08b5488392451881c509b94a9a28f8cedd23da05be27d4 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:10104
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61732
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10104.json