RHSA-2025:0140HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.16.30 bug fix and security update

Published
January 15, 2025
Last Modified
September 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-8508 — unbound: Unbounded name compression could lead to Denial of Service CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-50312 — GraphQL: Information Disclosure via GraphQL Introspection in OpenShift

🎯 Affected products77

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:0788cc893f3c3fe13776a3b74e733eaef22fb376a50b41cb2a4064098f494f89_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:3692078bf6c849f201050f0d66239638cdde56ea574a3e66cad6815244edd9aa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:37bc4b1f8fdbb3702e6b6ef15e3ca7bee4bf9902fbe6922ec06cb640188b2b87_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:c5d791f47678270136183fce850a87e21e60410e1c88a1040b82348ee3480eaf_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:2e540e9ed4ccc9321249d2f40cc9c6a6477720031b1eb5c6f0ba9e3c4fdc3e84_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:3355d618a7608b72caf5a20a156070c9a780307d75ac8c13c50b4c53c0adadf6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:406c5f0ef3287123d14d117db603ced651e80a790f3e79c443255b09f9201798_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:e574f1077ed39453679c274e8f025a49b3ab630f9fc69c5843ecf16bf17d2f26_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:0afad7b7c0b70f382c5af08ffbc7960e6cec4c7a4a77ef0412654b66b9409dd0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:50cfe0a16ab572a75870daa9dcfada0a830ff6cb39a7e895d3eaa6c239e8df55_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-azure-cloud-node-manager-rhel9@sha256:0e9a6290982e2cb93066c839c8ff6390e58decef8959af4ed8e6da089aae7001_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-azure-cloud-node-manager-rhel9@sha256:2b96b1a91f370232db32e47446062435aee2dec7e4a776a955836dfb76e0429a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:710767d4394156f89a8081e0f760d547f806e8c0d5593863a01c6e86baeffea2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:7f570a2ea837869b57ff32a0e58ce28a4f1bd8f750fc056dd7a4a8139d738a10_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:bc197126cec1a9f6c3525be72be1dcc755b8cb891320c6076548d7ef6a3028f3_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cloud-credential-rhel9-operator@sha256:fb38c15cdcb6443826a209377481bc0e64fbddea2d72f5854f0abfeee6bb7b0a_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-machine-approver-rhel9@sha256:088633bb25394ac6595c6120213962ab5df5f919f6b2564a79dcc6d162c00f79_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-machine-approver-rhel9@sha256:55ddb7dae8e366fd10f8069bd19d6171c0e7b3622dbb53109bf40ea190cddc30_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-machine-approver-rhel9@sha256:b37207e27a4ff7449cc09a75868c8d8425fffb7989e6f2caca459dc6a3009521_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-machine-approver-rhel9@sha256:e8ad85471a599a15384118ad84e5fe04c1066966267ada590c9596fda1a26d57_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-network-rhel9-operator@sha256:0978fbdf465d7b9ea5502d502156011c355ab83cb4511f578c938566896404c1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-network-rhel9-operator@sha256:30b717387c360535ec0c7196c22018fa18e1d9a6f7c6c13097b04b45ad168e04_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-network-rhel9-operator@sha256:33bab056241314bc10b5acf9851c6232e1ba44ae50474f028d76e3c0b8907819_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-network-rhel9-operator@sha256:9ff45306e5c5fc5a45f2d7dfac65b4504ccab952d80c1f69499d0eb5f2b68655_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:491d8b1d8e08708427c2625f4b10108fcd706a833bc02435d9ebcdd4e239f7d5_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:7df61fe55463528ec68f2fa8e3230d9a4ee6b5e57860fff8b3a494981ecb11e6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:8890e1d96d5bb7be3e0c61d2df3e46df16f27c5ab83f5d5777bc1c520a13cd52_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:ebd626c92e011d7260e50bb3cd8c13b656e883ec9e483ba227c91c9c142fe39f_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-console-rhel9@sha256:1d7cf74ed566cc2737f80167180828f426f17f6835c2d30fb7d47232befd2ade_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +47 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7aacace57ab6ec468dd98b0b3e0f3fc440b29afce21b90bd716fed0db487e9e9 (For s390x architecture) The image digest is sha256:83d85abae03310d7875f484ea2ba5d0224fe9196d7be0556032feb9685282472 (For ppc64le architecture) The image digest is sha256:e9a6f42c118d20b1e81dcd17c4a2166becdd558dd55d5badd33a36cdda5118fa (For aarch64 architecture) The image digest is sha256:184c6892722a60f87a0efea8eaca8fbbca3cebfc7c0eb6496005c241ce383a22 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: GraphQL Introspection should be disabled. Users should not have the ability to view all available queries, mutations, and data types.

🔗 References (14)