Red Hat Security Advisory: OpenShift Container Platform 4.14.63 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:0d851b87057ce9d97e22a5ce8f1882bf9725559d90ce8abc03cf5c7e87eeffc8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:32fcc04d439cea68026c8c5733329dd72e684c74c61fd2e93c324f372c5fb764_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:5132d41a1c8695302713f845091fed76f86330a3b16a17d135fb75ec117facdd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:ac531f2a7530dddcb50efe1a421b0fdd7894eba4588a4ce0342044fedc34a902_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:56243cb5d17e31eed408e575f7e40521a163787def6884be063fc3e80f07bf77_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7232b2210ef20f1eefa4207a78a1f8d395ff89f1df4be0225b6e6d7223108d85_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8b398807f887ef2f4e823c24bbf46e79f872b390f3a8765e89e98d89d58c0270_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f2ebee0f33ba52de65b31d2b157b548736c41073b5e625e28bef7ce9c7f229fc_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:244f3f2e06a65a58423175f50075630db2314cc7d2a0da0132784ced93cfeb76_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:51143689abb20cfd5b8bddcfcef776626b307b563cbddae037c3f1862ea454ed_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:d2a80fae30b6b37a702532991445a72995b8941ecc65cc64cc692cecd437de55_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:f1284e3bc937c446ecb94da3d3b38be5ed0d384f5af8865e6ee18c275830199a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:2feaa23080542d356591c8c58e47acf85fc7abd0334a83b338db8fb84f596909_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:64461686a5064389326121018b2d219559434aa12d708c5d810a69e05aa88866_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:c68f06da9d4b35858a0ce5c38d6a2bcfdb45cdb7fe9a12050efab662b8f2f26a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:d00c400d6582aaa84bfcae94521d46637a3af2f6ec76f0f1235a0e90d859e297_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:05aa061acaf2cf26c24b66ce22a295a60cdc447396426f57c9bb6c1000b9cdd2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:087b5ef2c1867e732a3e0894ee381314d47fd67735271aedb1e777c76d7a2dff_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:f171f5841a84fb8a79478ee709a5015f2b4e4ebc79affe14064309997c3340a6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:f1b0dbcc2d458d9961e68395c8364c78b2b741a162bc0377ad42c96141b46157_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:1227175cdda9d83e3545121a94cb191ba6340edf1e1b22b46eae51191ae4dcd0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:1cc8c76dc9a1c77b2d5f0880951acc8a07233aed0ba11213df63d39aeb38d28b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:9e9a8e392960ccadd86fd9d7e00ebdd80be989e0904217573c39ff0d9f3d052a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:cec2bec8d540b5a2812051082731fe8d4decdbf014de73d3ebf585529fad1d01_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:4b4705cf89e7606046e8a2ee7d2db19ba2c2afc21c4bb619ccbe312a0b6ed89e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:83976af29b501a1d630839ec7d794c0b66b794c5f7bdd79e1e9b0e241339ae90_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ae45309bedda46cca83093eb0a35ea4690f7c9336f69431ebb81b5366410f676_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ed135c275173104cd6a628ee3d23c5883fd5da83c588da83089e514186734d4a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:27068457036b7afa2a9764e872dd7f96603c25d9b54b9dae8116e688b4e353ec_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d41fd6ac8eae1c7512722550c3848c389b2a307d3f45db63d4237e24c4bfed49 (For s390x architecture) The image digest is sha256:6807ce129f530731f1d5e8102cc3b4ac60e150ec5448dfc4d63fea2c9a2fd13b (For ppc64le architecture) The image digest is sha256:f2d930fb3d83d010f9eb0e3408eb5a223517a041040a0d44e612abb090208c28 (For aarch64 architecture) The image digest is sha256:dd65304f2a52194a0ee6f0f05e6f65c2f0a36175d3e5f0e582a968de2bfbd86a All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:5107
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5107.json