Red Hat Security Advisory: OpenShift Container Platform 4.15.62 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:1ccaa334614349094cbe4e6cc1a4b0b0f7520da8f4f19c910a139ad471426a47_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:7618237bd8bc1bc898fcf0df9c1f5e9b2f73df8590bebcb2cff90956ea0d7c0d_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:e2c2aa019971f1ee0ed4a00f041c0ff20fe7b5df0051fb96c61b0e3e4f4ceba9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:f5e0451b4daad962e2354a7eca5d853ef688a47fe59173de7006f5b258113611_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:415e460d47ea62b11dce6dce314195d643011bb373104c684a9ea145f00bd5a1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:642b7d3cccc81b1c8ca2272090ad7967a9bef48bbfb94c7848dc7906bd2ee833_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c3004eded586b39514686e599602b7a5ccd89a1d81ffe814ef9a46a4b11adea0_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:febba09732b01b39432ac13a77659bec9b8924ce73c92ebd27cdeae17aafc63b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:00ebbc5e47cb63f95861feffaa3bed947d15aa9b9515192b868811b6f7e5edab_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:4e4389384ad67e0b355b637d9388bbb17b8d4973ed108182fb60baf585946a3c_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:b474496954fcadfd4b717b9a44ac8651504c5ccbae4742377731539e1a97076c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:f8603a7b6bee306e845ff46949cad1375bd1aa636e2bef8c89f914c739a31ea2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:5032d74143246e38bd5ec13b3230d70a7cc8249a0650a0dcf75ad4f7b58c9c71_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:7e89af48be57342908d8935a6d8ef38097f6df74d1e6facbc6f7c2ed80542d40_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:910292db2bb21008afd27c4bceac283c5dbfb46ed7914f2db158f7924050f4f8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:c5b8c25f430b68e2ac6183c1bde5e13b876e01490d58cd628ec20b5ba7ca1911_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:097031e7511b65c55d5a90cbf90c5ca40fdb60146f6610de9b3974bac44f0d27_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:58d98c797e6518bae1f7ef0a46209d742a33d1e60f9ae591b20cab9d3208714d_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:c0b402f37fcd350eef2064e0a2d07759e3860f6da3bc45c753382f5e5c157528_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:f76445a3501a81fdc7e5f3ffc461228358c9a4358f9f32ff80a9da6c2e9df416_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:00e89278fda90023de4fb49f9010928d7ee9ff33c6df3ade753f1c7dbef5cbda_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:581688f998b02a2c4355652ef6771b4567ca8807affa3c2ea98b1615a3525684_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:6a916b3b562167c3360a209b180e6bbab4a065e2fac6d759982be75eaae24ba7_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:86a2046f234e8cf1d53069f2de2411f488e5d9445cc6ee6e14881f5299fd201a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:106d62bf8781e80f4164887effd75bc2b82eaec523a35e3890da9e014c0870f4_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:889ad33fabb9a40455668a39788dbafd08e82ade0613c0d0b7b1a24ab102db29_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:a8d69b3071bedf57cac6cf157fa2d6997044669c856ee8fa8d7aff2eca1c9a15_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:f90a98c226eb9b7be2f21cf0a0f1bcdd6bfec5153dc90fbe8e46a843c93b18ba_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:9e3274e9004ed456b44b5103f26141b55c660fac05e9486fc721109949ba4b5d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0301752d0cbc1d62336f5c467be4b63947e882750760243f513da5c6c003289e (For s390x architecture) The image digest is sha256:92ae7546248ac2341469a7bd801569e225bfab6177fae12a1aa90c990e96459b (For ppc64le architecture) The image digest is sha256:ba40e267f4ff9a6150513e3b2411032cbedbe4ffc0bed012f17675e5a40d473e (For aarch64 architecture) The image digest is sha256:a780ba0cb96fe8e52708f989caf17a7aebc38142cc43aec45d063e5520190761 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:4423
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4423.json