Red Hat Security Advisory: OpenShift Container Platform 4.17.51 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:224e244785887e87f57459b79e1a8494b3e790ba5be60905b9c134aeb34f60af_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:328d7740dc2a87d91fc6f01cdd7588b7b8976d666692ec7ce7064ab1422ee812_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a5a51d3a0e6765439984454a1e01a0fb6ee8946f89b81b79ad6bb4dc2b59bf39_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a75ce30dc9503ebcee526d5f85a4c70b2eb696c1c7493326dc517b5695b6a0ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:099de79af64c801575de55cb8d6fb5427ae150bd9fc61c60cf8297a159572f31_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:27381055b6bc478bdee76d2c4a44d31bef2474c25703c938af7454ee43c99e84_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6bc8204b2be62a10c368200e3369514a1c55ab22327f5788f563c759e7c6bf04_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b8579bc40a27844a8332d83a170d3271b547c4a0951decd989c8199b6088d677_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:01243d64ad06e92d80d837ac3575f43c3517cafc140f7120910f473b84c1c2cf_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4cd82aa56bf81539013fbbc27156ef77481d5376f0ceac7a7f101f3b9e42a658_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:80d51ba3c1718b65730317b2cdc40e588f4eedfd34ec1e48de030f905f3888b5_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b3ee14b678c5a472d46bf1ab5c6965660d4011db0f58e525bd7f62aa4ffea2a9_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1c0a520d5fb66b12ac0a6f39170b5e009073c790184d9f6640b1b243301d5b05_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2f3642da55a09eeb592ee0168c31da87ffd84c02b525d59a91db6d780e3d7bc3_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:49a2c683b9ac1fb18c214c409159945184d0cd9b6c93bf00ac100ac7ed712e57_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:647070f6ad6552c73ca4f617dd32a4fe2055eb40363c48cf31d11e1469638112_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:08932a088dc85bfab1986380509b0eb5d238d8f05efacdc06934ad4992844f8e_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:291198b4234e46b7e6a10a5d06a2d3304e1f1b7b8c18a9ab48eecbc2107e4271_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cf6646bbf3854250a6c815964894c08a64da1fe91eb02bb5ada08a09bd70d884_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dbff70fd5dfad8ffece63db32a6963b22c72fce392e33b479720d72b0bbeae28_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:02d3bbf5506efd3b822d373d65d347cdcd153cdbbf2ec9c8b61f7591e8a9393b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5024e6a0e439f10c40e046c9f9b3bec5830d6378b69e48b6fdb1828eefa27de6_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:93c459687fc59ef789261ec5a538abf42e679cc57b722829f38c34bc6cfa9910_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:d0fabc48b0ff368d5bdd9e61badf4dc26097a17a9d013b0c78d8a1f7d9c13da5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:0f623fa4b97769fa9b424b539bb1aecd81eea796482273fd8e40fe695aeb38b1_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:52b25f4216131f3a6fb1f02e0039043215e11d426cd178c9294b2b45eedd6abb_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:99820b7d3e0df7224d08a4563692e7f628932efcbb13c3d4ba8ed220cf7f3bf4_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:9b58a6711b69dce1d00e99a092fdb39fd526138b8ef535d479fb5f4c216b650d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:5532a6b3b507edddc3e46990e98c23eacf19a44bb45f7b26d3a7fe0fb0ebf5c5_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:75dc5b2eeb18f5e46a7546e7206a6cb485971d77ca66cd34390f55c0d147ea89 (For s390x architecture) The image digest is sha256:68d213f51730607777fb492cd3b5d32fb58e8da880273d83f9d3046336584a09 (For ppc64le architecture) The image digest is sha256:f66cc69569c4af877c2fa74469c8f2f51e390088ef63bb38db55991b15075834 (For aarch64 architecture) The image digest is sha256:a623aa7ff677656407ae0b361fcff72b11fae6c580bda6714266a00a0f90f889 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:4510
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4510.json