Red Hat Security Advisory: OpenShift Container Platform 4.19.23 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3342e71e34ccbfc89109ce1c2da32e0c48752e2a19068764429488565e49ce04_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:beeb5580052b57f65f4528987fa21f12447a52a5db35f765920f23aff17e486a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ce0dfcca1dd6b843b75e647aa381fdc0f4118971f24b901ad867ee92d69153a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d6e8745266e29e4b2b951494ec60e4c1d7f61c6f17a4a8437ebbe9c7bfa7f3c9_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6bcbf7a305c20975af1640b5d230e6d3cc7aab9916c950917784363db745e127_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b8f25c2a48b4e546b89284e51dc3f3112d090633d5c2cae53477c36568e77fa4_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c480343e01e07f7397a6804cec053f0d9198b87c8bdea13d650d79a1658b360c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e287cab1cbc33589f78282e82a459e42fc0d561a07c692862e4b85aecc949f97_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1e6230de12a43c5ee8cf5ac79657fecefb6ebb88d461ff37703024399e7835d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:87d7d405f0791eadd0c3ea6e04c51866e2c10a63774007360e09b4377b97dd31_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9141776d06d746609a60b99a15cc09f0d8c4dffb933452d8ff53d8d02f727ed8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e22ee74efa66de0812f93542ce8f55538cd4cfc5a78652c752d6ede249151748_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:09e373c4dd0dd2f1bbf02ca3e40ac4252189e3b9161873a4a9dc56c86c39b9f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:129996b426e156447bb3835d527548e9029bf73608ce0de6d86af0b8ae0779e0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6bbb9be6178469a4770345d0731db2f8a2be687c79fbda51f79ce106ed69307d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d563a05b4b0d8ad3715acbe625544c9c15fc65790ee436986d00cb830182855e_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0b832bc33a20f269f870b984d88580f61f88e2a300e924cbb664b71b4d8f5fdf_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:16f6d2f09ee0c96fe6e5090b8af4ff39e68890930980b06408900384f94be052_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6a62440861587d81c85b06178f7103101c928966eacda60b5127562040bd1024_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:fd9772c2534bb6804a375dcfb917ede038f3a8efe503a8c6a30b4cbb1f87779a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1b0d9de80345e9689862a1fc07622143d1d353102849c0614fef12aabcde7146_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2eb91fa7a57db0aab2a7c8750209e16a0f1760be6e8d54de77f67b206a2534b0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7833dfda0e928a543641c300d1f3e34e3959b6c8735672a9b48d79cc6f7da7f5_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f4d9fb89168484b7b46c03d1df30753d745200206d7a536b0ca8e1008e38e924_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:714ef73f2bda6c314516a90eb10b03d9625d3324a2c2542d7fe59c422ed17950_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bf4d40bd877cf166cb56f663447ab8ff5bc623f13396b6b36c8b6d82aa3aca44_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cb1cadd341bc1797818a1f9405afa606c60fe9029916dca92b44fe49cdb3c29f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ef7a1ddc06a88addd5d2aa61c27d79f6b405f74875546c748df44962d1c1ecb1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1f2f2c9eb8e08a21d6cea95b682665ee39ecd252b1282186da3d31bd6c32ee27_s390x as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7bf7c5dabc70518b89130ff7cfe62d14a61ed800adb418359bd9dcaa17b50206 (For s390x architecture) The image digest is sha256:7b2eb7420e10ac8d5e1e5698393235bcad236172c49e688dff2ee651668caf29 (For ppc64le architecture) The image digest is sha256:7213776b521925f53a6a2dfac72adb9a6f9df9710dd39c8847bd6ef211aad63c (For aarch64 architecture) The image digest is sha256:369335090d5f4f5b4853e22c750ef7749ae18320be610d50f7314bb917e2b617 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:1552
- externalhttps://access.redhat.com/security/cve/CVE-2025-15284
- externalhttps://access.redhat.com/security/cve/CVE-2025-58068
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_1552.json