Red Hat Security Advisory: OpenShift Container Platform 4.18.35 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2b498b9231f37cc2950166fbfd245c406e5def73b6b4d4e9f11e85106a4b2d1e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:49be0fee3515aca013ed5ec670147999ac78dee50590093ca486216fac4939a8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d7277d6b7efc974196b7dc06ef0d9f3eea75dc17173fcf2915d66983a90c8e3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e00a86c095aa8fb842e4e16b1be65da5fa8c7cb68ac54359fd3145351f4125d9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8bd7e68a704e3cc6ebb5de662482569ebe353f6fe32d774adfbcbfa17ddf5d55_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:987f733bf42ad58716951c02183b4f2f4779bb74133c9da26330161e4cd546fb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b699697bf2ec4f91673f9a8f6055fc266350338bf84e74418d5186de17c2046d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f69581c282f494b1dcfba07663cd6c1063f1405767ad9d3b62c050e1fe5cf676_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:033a0acbc78b3f3240d7d6e038a2ba3a15b6ab3c47e4531530ba50b6fa6b9646_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:08caf8aaa957986de7580fbdee4462cd8c7c154b82580be3f998275647fd3db4_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9d8c8e54876da2a6c93722c200c15a2d9872be0eebaf52d0a997a27b53bb11e7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e80b46ee07e53894d9255cb89b33bc0c3b7aec73d1ed5060a74ed85234641ee5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4ca233a7fd7230e05a423c9beb35a21ba6d2c1a74e4dbcbe57d01cb868d31758_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:aa9ea6bc34c139e0651d8aa9a7e1d4fbf325c93eed387dd6d7e7137043ca6804_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b6140aa21678d5652c4d09e21eab5dfad35af30902b705c70f72a384e43868ac_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:cfe1861bed23be7cf1f4778e14ebeba3b7eddba03c4bc1636f56a140ade5137e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:12099eb7367774e928a12dd346a36a4b5a981c9f6ada9c212f28c1228492c914_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2aca8083cb9d1ab43fb45e0905545ded7834027e21b344e5fe476c581c3bcafe_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:994c7fee6318cc9c233354387c8847ef645d9874c60727d0d26aa8ad570a2d6a_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:bb863f226d09a6aae0de5ea6bf64034643a18e802a54ddd3a44a89ffdb6865f5_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5bcc4e2a673ee6ff9f8bb9334faad4d2d2cb9dd30c4afad373ffa7df2abd6b91_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:697468ba01644ff1598cfa54869be0a1ea674e78e699d9a3b60c19e4fecb1fc8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:80aa8a7d884c52a7989cd1549b0272f51eb31e2498e8c04774c7bda965650651_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c3d778b7df101a24275b3b054aeaf6c5ea93c8fa49903ae4c8919a060130e473_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1dd1dd97a363face566e4a10095f5ff53e44467da8f9367f65a1a1b21cc25ad6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:21b4c9cf268bb7abef7af187cd775d3f74d0bd33626250095428d53b705ee946_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5d20c860eda843393250930c00ca1d4af7b5e13c0c393fcf7c59c6fdcbacb04b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:9b8cfa56f31d97c4e1705d5e5f5795cb745893541b22766a3f65b0dbe462a90c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:0c130cb9e3fad0f7390eb0fc0cd91be363c4840a955c510a46b493dc30f5610b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:59727c4b3fef19e5149675cf3350735bbfe2c6588a57654b2e4552dd719f58b1 (For s390x architecture) The image digest is sha256:990383bd551e781327ce7972144fc0c9a614c048d7ccbde562548e07f85192b3 (For ppc64le architecture) The image digest is sha256:5e284927ceb1b59b986ac80acf1e4d097b09587f0751c65c5488c2c29dd51d8c (For aarch64 architecture) The image digest is sha256:0a43bf979ac93078a64c99f078b6097634920909f9acbaa18d494b7203b33a52 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:3905
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3905.json