Red Hat Security Advisory: OpenShift Container Platform 4.16.58 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1def581f4e6a2cf110ba6fd010bdab185f3a6cc66481dce51470de2c328cc0af_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:68bb00aa995a4a0e58ab4bc629264e1fdb300b2ced3578ccc15a54a312cfe0a7_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:70ec524ee357f174ee497fabc9a46b29568419dfbff699d1bb37e3a1408677c4_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ef609e555be1f77c0eb9b9d5a0331afd05419921b91c05628c0dc7589b175705_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7289314dc3e2cb9ea034cac0a68eb981a414719fa7dc7d6d3d65fc10a328b041_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b4e381697c9d34e3cf0e15eb85f2af1004ee6daa878ba2fe8b3331c7b51d6d3b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d14b07a119101d89f79798f341ee81c90b331b5bffa50e8a97bf2e7752fb1e09_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f18c6d00f96284d8921522dda6ddb3aa0732944f2a42ed69dd34e53ff3ade839_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0cc2203b20c754d27d27b03197c1dbfaf420f08bb1e0b0b1b38054dea00841e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7eb0af3f2a2acfb6208be87db0f7add78cf7940b8c9ad4416be6ac5876afdbd2_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:82cc2ef1d342a6bd8e48dd03488a6edbfa9960a430f04ca2205b936446171503_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b9a5d263b6ac6ab8f4dd34fc529049f46aa1555bbcf6d9aca4bf3dabfc688341_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2e45b8fde9044c7cee67a5cd443a7cac2c82d27b34f3f523ce3d98efb92b5324_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3840e6288c86aa99cd0e224606ea39452b26080049c09cc53ddb1ada13352eb8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:73eebf08ad62e6d95393daa8ebcefcae733836631c71a54b6b58c9f399265374_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9a0987a5a479de321a99fcd07508a0aa89c53e97e04d0049a020ebd8f0b27b1b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:50813612571d7aa2bb3b0d8b1480c822e68bcfa8102a58ae24a8e40bb4211327_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:71d93e8358a0e294a62cbf33d6a5e5aacc240dc35d495a2b5b24d75b69222ead_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:72767945ae367b20b13a092c1fc7652cc1fc0056ba9757884e2fd6b41cb671aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c95f5d392f4c4775c235e17853363309390e9fa43ad723b5326c4e7e23abd716_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1e75949db2c07b5d422c3d6d02d625afcc4d0a5ff0f8047e5d39fb952a962524_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5cca5b11f6282eb19cbb9712af7fa9bc989034dd744a735da711fa8b9c3e8f89_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:91e70a6f14f8b76da792aca78457ba750c09bcd8034cd66f72a34c8a7e28f6c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:c215f30fc84952daddec2468a55c27ea85e71091a7973d0cd63184543b2e2266_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:2498146ffc7c059c5a4eb6397ab658241368a83960bae86acb3f6499e3092263_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:772d4c092279159369c477bc05a459ef6a8076bd068fa3e87412c0a2ca4bfb1a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:8df2fdac052045bf406e7af5737b7540bf5eb053c923ce17aa4981055847c8bb_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:a2166ac9e26b1fdc8a5c0b187b24e58912d7da5bccaa770f4afe2dac3d266e12_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:142fa3d0bb0da58b1f7682d7261911dbbe16cc5b39809010cb7b3a66fddaf5ad_s390x as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:c9e3973d54f71b4ff23c397b645a51cd47c010d103e921630bda5028d04ff3d8 (For s390x architecture) The image digest is sha256:1aa9016d22c8d1583a551c6781e08edebf28fab83fa9260a2004bcb0632dc6bf (For ppc64le architecture) The image digest is sha256:ac6b3774ae09bc158fe6cecf4da0eb365197a61d3bf51ee1adfbe91ded39f3ea (For aarch64 architecture) The image digest is sha256:eead1994f8221d432dffa6441cc42390a6c7dafe4d1e38cb85c6c14d50f91317 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:4482
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4482.json