Red Hat Security Advisory: OpenShift Container Platform 4.18.38 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7730305917ad0d133d5bbff44ab8a68df9464a6d8dfe32ba139616f1d52ccc10_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c8f1cea9c41c0bbb9ea058e3b5f74b4e56c30c6faabb9d2ec4707edcb43856dd_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:eb79ae6f6f5fbfb20a1ee0a16815ff94d8277e68df93d20e10f299aaae143a7f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fd7dd321828cce7c47251eae937910a50c9bd01a17b998480b9ac4535df8d3e4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:04513be32a32fabbd9c59fcd279eb79c7acb8036d29d51e79ef7a04cd0803b95_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:41c70c82d8a2cc1d3b7ab10fb9dab686d673843dddc8bd38c2135bc9f4cb3b51_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b3fd3a00bc2c4e348e4490544eaca11db0073c83d3a0423fd186c4c7cdc1e0d8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f34121eebba4b9f30ffdb0a1eec67810206ff7055328e31f738a89a8d6741392_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0d978e2c17755cbf9322cec88e943466e0342741b5d185056835228c097f84bf_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:504723879a18e3f46e04ce9a6527beeb1ae12a91d9f7d6bd82cae9a99f152405_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:8140effdd2181ce3e706fd35ab06e1672950c9f0b4505766415a805e9cd6211f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b169771c1c247b14982e9c8621b7724a6743f2acd21543320dba399fa08721a4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:309549afaccd8e0e56fd187c8ba37931ce0b7b005a8cb484e32a61589e64231d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8c39eb24a9220d1c468c33822b59bc90ee97fc198dfbb23e1692fb9e60f58a36_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ebc98d92647c9c69789e6160b946cea09877d0bf609354e8dc21f50584972f3a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ec58a8c1d41e17411cab8bdb39786903434b2de275b88af32c95827c2d0a36c9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1fb2c5fbb86f7f3325011d6d70ab85a514752ea572771a1e99ab102e239592c9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3ae56e7a9a1b1520d0f61c0e041d2f99de3235f6800a7ee55eaf49cbd65849ab_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4489ebdb5380905e5f80c4b341bb4e0cabe1f6768406416c6b21c07cb54b7649_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fc7876b2587d33282189bfa34573232c8b0e34497f4ca76eb67791cf12579564_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2acff799d4687ab7b2f6acf70e18bbd30fd6c88e9da8d794706ac8b0a3debf60_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:51b9fd203c2f82c787b2b3e1ce77e54751ef6776c7b155ee6f52303989456d36_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ad573042d164266723dc7ef7f7de15bcb5282f85ec59657678dd9fe4005d2438_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f45797f8fce75623c15199ba051f973dcfb722a1375d523a0cbc4f2147864ef5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0bcb4e050cbc2093368c50bd9ba7400aa5d2b75cd0b06984d3a57714ce9b1020_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5f835241d9414d8a3d028d5746e70748caf824d7ea18cadf8811b4d363ee87f8_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a63f0a5ccf9e8fcc377526c611a86c5b8ef0ddba8a4e55f783d5f6beeec078f0_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:c57e43cfeac143fa18252002b43f24ff8ad4bc16805ded95c836326080431ed0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:3aac25a36f3387e6a0350cfc2332eb0f08824177710f2c635f9e88603fa0120b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:deacb4132f024a8c364ab8589b7b3f391b887ca4ae92bd4b37df2efa5b1e2145 (For s390x architecture) The image digest is sha256:15c373c763a87889521edd3bcfd1adde0503dedc03e0923b27b4aca67c712f79 (For ppc64le architecture) The image digest is sha256:c0ad2b1cd05475031978f791e9fefa14d25c362c5d533febf59d7e0f6245a0cc (For aarch64 architecture) The image digest is sha256:14581b093df0b4f6f01009454f7e999f7415066ea3ce21ade572d42dd0bd2955 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:8448
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61732
- externalhttps://access.redhat.com/security/cve/CVE-2025-61731
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8448.json