Red Hat Security Advisory: OpenShift Container Platform 4.18.37 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:26bc688ba4274646159be4401e90fe3a9133bdba80a6ba98281445935bb47a57_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3b35d574708fb00c479227aba40e3fffe79b631899681b16a08c76e91cd102b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d1b1566ee173b588dc65c3eabb9fcac1620e658db075f03b0b33ab0f10dc4202_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:da4e7a0c241f773b6d726979623aad6a45a3cf2b5833ffd0887ec8d893aa67eb_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:579a6c699e97e9796389e54c95424e2cfa71e5b0dd66908e8c5d6df1d51563ad_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b69b12366ce2027f54be0ddbd2e1db6d71485de6dfd2fa49fba4e4643087101e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:bfc42f3af0840e70fed345692f12d243aaa45f050e6141c5260adf5a57413008_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c5b5375cea86eb1941c7d2eb16b7147fd4343671df8d6a3603324f2d15f8e9c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:360bb7bca74dcddbd1c73a7c3bf8cd8684ee4bdf8f7a974bfde2852553abea78_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b9a0fed36ec0557a938659dae4ff53c7f29a686c884f622a2c2752dc79201000_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:de816051b024daa6bc18fba42f874e263e0fb337aa631a4af1c51ec6113adbc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:fbe617ccefb3cbac4da20c3f811128ee9a2b9a3cebda7e6ac0fb4c95b81ef3b6_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a8ae84b4d01a10a7052c6c1b79e3bd4a343724bf7f10c4785088b4b4bd0e579d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d514e5bd7b5877e53b1fadb19f007349af7e3ef87833b8328abff44fc9f26378_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e5bd54954580a5c99d2b5d2319820d5722677858921c40b974c59fedbe90e2f0_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:fddc3aa7aef27df8493be219998abc177d6269858d4b1f5f2be479fb93774425_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:25dc3e6d6f9b6db1091d79190a20d3c9cb1de2c44fbe9de52e29aaa8c47b5f2d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:32d3a85652bb15a38bfbf379050256b96cb9a7c96f7b1291ed00874d32efbf46_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:603116084aa76b58e42c6b438cf02e9627339e98943797592291f518dcf5fb06_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d50df86705384ae2023e4a16b3088b8eaa819765700e0c064034a06dddb1ad3a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1e6a2154b1d4d891c918d10db17d0ce235e2257c7384cda1d545d464c424441c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:36e392df69829eac83685515ed18c84dd70dc9e9bd2aba931668d5b7db6b139f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4925b1aecda512c045dfea6136d2c1766025bd2dc99fb50b43a229865c0a2a82_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e556e65e257dd11d584cd9422972e5b9d81006983581309648e62c44983ec082_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0423c2bc5bc949c627e9044a2666b29b65979a68fa0496aee63fda75edfb5d3d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0cd9bb93141429acbf479f538c7eb74d3abbf47cfb9bd3f505a7c384f4bd1a32_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:706068084847fcdfc8c20998c1b1d6f1082804bcfc94663415567a7f80bf8f89_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:bad9bbcfc852bfb9c5a976602893993bdb3a12f5050b4f22894b790a4fa5663e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:0b497874a312ae85151b4d0c0f3cfec07ce5ab2e7361d95d760b141fb00c7e7e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9b7068aa6f6087c2f0a7cefa241c5dbb0ede0efaad783607dff0da98cac432d2 (For s390x architecture) The image digest is sha256:71fc972c8f86d9ab444778a4ea4ff4a584acd987e656bd882f0b09f89eca8f69 (For ppc64le architecture) The image digest is sha256:c07f07c1ab1d2ff0b5c94e2df409fd021562bec9faf3ec1baffa045c9352c66b (For aarch64 architecture) The image digest is sha256:925290794f73498da77c7b536b266e0ddcc16b2a16f83f1f7c9ca31a199d735c All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:6554
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6554.json