Red Hat Security Advisory: OpenShift Container Platform 4.16.57 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:31a0ff47aa1a017d18773be577a1dc3296001154c7c40de20cbc3cc767b0c16b_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:41564206c906171df891ccc7c92274cb7998f29687ff7d2e44399242e38682b0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:71f36e93f7195b10639a5c7db58e2f396f1272c6dbaba651e78a4c9ce955c427_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ab71874b013fdb05845e94a9b4e3432d865a6157cff72725b1ea7589c6717b9e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:34b678523168aca5571ba1e631a458addc39ea9aaea3eff355fbe091e859b30f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7cc0d1bbc241ac63a5f45a949a439d54316c23c7045659a9d44771e5541e7e17_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7dfa6966d81447102d92f49b7256c7b47955f1d2b60e5b9dc133f71a1b2c8033_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b07a724845d8acbb842e9c96ebe2ab5355f266ae382d703c0f92a84c6d79de20_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3d124f0dfefa90e249b024817c37087e6294880030bf95333bdf0b39bb1db696_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:580b4036071c17c8551b3171c31ecaeb61aea5dd431d147f036a832565531948_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5e9203d284843bf5a5a3e7178104fbaa3b4a620bc6f889b36c6c077aa93f56e4_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ccb8be0ede2d9ecffd5bd7b4c9c555156b826cd864f5eaae87b3c1c58c7ede31_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:17d2506a96ba4da62c33738d9798c651658555531ba721f277b95b9c5283df84_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3e6f6f0d6ceed5244d82b17442e473729421d59ec5cd1a71deacc15531f2929c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8ebf277d8c153fa0be2825ebade894a87f61ba26c198225e4fd714302be26ef2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e0ead7eca26924691145465af2c5c06efae71a197f68043730e56d5cd63aaa59_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2d9397f611cb4830f7b9bb67e7e35af224c0f121e4fe884c98c7c4807ef84855_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:79e8c5b1e61683f9c78e8d1022c90ce13c4b3c438dc373773c8d174b9835c862_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e104e90349ec069f6b4fbf749dd261ce91b21237b367c421bfcec3dfbe1bbbb9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ef70455cbaeae026e8b15538a2a1d159bbb35e47427ea97e13f5e5a7cdf27dcc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1683b25c778adadab73dab246e98caa2ee21c561fa57b1f2ca7211eae88876ae_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5c875e3f0f2b0c11b8ba123f0716e007fa09b21ee696dce0c71ba774c1a2c7c4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6b96865aa6187e5d1d46bb64717dfcd42a1cc17f33bbb96be9021d8b61f6465f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6d1451124fcfb4ef7a5a4c673e06603443f538c6ff781f10706e8814245ff056_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:3cc3d7622e92973a3e7c5807ee254195082fb9808132838ac28a357e66e892c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:685d78a491e935d0b4e7a8eea29df7863976a60800d1e08c3bd3faaeafad5a25_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:88b54af358d720bcc453fc09511bdfc7793b211dce0014648eea9ab01fc623f8_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:b6a234ddf1c93f87ab0ba77b6dfbb1ae9ff2a1b130224daded0de20781a1f650_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:68c09233701045a0512a7310d21be057e1baeab5eab74e246770e148daa87c53_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9be78983e01f2fd4a8652543a3a997923818f2d62e0968f15ff30d0084233b49 (For s390x architecture) The image digest is sha256:62344078c5d27a8b4a230cb69f800be2e7bace1ba0683ad48c219be850549abc (For ppc64le architecture) The image digest is sha256:8dc7e7317bb32a320281248503bda3dea8262c671d99acb75b83eda1e6b3695e (For aarch64 architecture) The image digest is sha256:e179e1d1ed72417286499f8f075a00c43ef9ddb96de9bf0234dd3a28e448c5f1 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:2661
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-58068
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2661.json