Red Hat Security Advisory: OpenShift Container Platform 4.19.5 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-6032 — podman: podman missing TLS verification CVE-2025-48060 — jq: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
🎯 Affected products152
- Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:07106d65599c4a591c5a9522346e8c5d2b234a714a37693dccc5fe8024a45d78_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:539d8c4658c32354366e0fb6bb3d9cf65f0686ffa8be9b98ae695e1855c5b170_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:863c8c0cc043ddd27481ce6555567f4ddda86b83f198bcf5f9fdfb98787f6f95_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:e5981ecd70bd44e5ba7c0d42efdd0bdc31f323075db5ee94b68dd12ce4541d91_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:ac61d97f2ff655600e14616fac52bce70ddcbef6116b4f6b4486ae9d3c63ef0d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:d8865fd6877534e1b66f81a52774fa65a28b3bd1f3a34b9dbedd908d92b70cda_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:e5d279c0e69345bf474f5f8645ea9800467be3cec70a2c520dc3e16ac48fa50b_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:e77cdf7d2ba5635ab07a7a7582dfd6d41411bc277537557594c1ae68bd3d63de_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:23c2ce1c5705b1ad6c5ee257f5804b6f4e6e0f4cc15c18cc9c23cccf64cadf58_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:6c91c0e79209794a916dcfc564127af64b3484a525770082dd4d147d0f2e385e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:ebdf3c06ec71500bc756efa1e706161a4f6b201194517191edcc1dbecb2f2b96_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:fa9f3cfa1245fcd1b96fc1bb437c3f5b426e4f02c6fb54a10395e09fc527c4fa_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:07f7d04e05253b7e0e58fb8babb75dd1d56f87ec08efdbac81b1c1f6f669c4e9_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:0e852b9f729dbf8a848e8e549c14ae1dcd7c0ebf9b1b216e1778eb8ff15a73e8_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:3c973448ebac91957f7a3fb8a793820bc0121ae008f7f40daf881153d3b3a8f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:8cd565d61f6aa4756d98d3bb7323da8956a8c226b1c86be5350959b2dac12893_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:1afb9d429f33677aa3b4fbb69ef0244f9d10e1a60764eec66d076592a9c097c2_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:2e6edfab361c2e1d3f75e644634465a3602921f8cebcf84eca8d47bd41da8836_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:54ce2a58d18cc4a4c7580611fce89bf471cf6b8dfeb5f397381b4b5e01b9f385_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:c457dc62227e652bcf83fb8db401bd7bea03b3f5476a9be6ad146299ba107b0f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:0de4d8989170a15d1b0bdd4c8b06695157adcfe33c6d6bab28b864030ab32fd1_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:17d0b32811332a743636c33d84a5df79a0b034d95cef47329ccca0e1b0f7b264_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:c83d14fcc0350983b43efe2793397a2fdb2878a878bd6409176cb73e04d15f3d_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:f5783ee3a898959be8f590615f6e7a0fc88a664eda061093dc989da0d356e447_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:0d4d965a600b6be91ca6dff723567ade65f0a8bd26d8e192776b3095a4e865d7_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:5bcf3877aa9c7b5d106751fbbada7bc039aa86840ffb25bbb747fde9e1975561_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:a3ce78f548af674969a60dc136b05b59c8c8733304a62fae0af0f8eb36a3290a_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:ecec4bbd19ef9894e17cb3ad801a099a53a8a083854f530364b09d6158f8eaf6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-aws-ebs-csi-driver-rhel9@sha256:1937a4281eab1b4c137c0a2f4f0706f180174368004007bf157b692b36bd857e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- +122 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:bc79be35e8b8a3719a3e16c91b64e5945c6c4ff1a9c9d0816339f14e2b004385 (For s390x architecture) The image digest is sha256:d7795a505d2649ad021a0f00b3457eb0da509103abd9d8d3504ad8fc908d1648 (For ppc64le architecture) The image digest is sha256:c5764d94ea6feb0ad594bdd8f0ed6b175ed4d9b33fd2cd353c284ab822057eec (For aarch64 architecture) The image digest is sha256:6946de834cbca6c2398096db961ee6821d3859b5ad3523d5325b0ec6a0265c94 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Download the VM image manually with another tool that verifies the TLS certificate and then pass the local image as a file path to podman, for example: # podman machine init --image <local-image-path> Workaround: Do not process untrusted input with the jq command line JSON processor.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2025:11363
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372501
- externalhttps://issues.redhat.com/browse/OCPBUGS-52592
- externalhttps://issues.redhat.com/browse/OCPBUGS-56728
- externalhttps://issues.redhat.com/browse/OCPBUGS-56765
- externalhttps://issues.redhat.com/browse/OCPBUGS-56845
- externalhttps://issues.redhat.com/browse/OCPBUGS-57660
- externalhttps://issues.redhat.com/browse/OCPBUGS-57886
- externalhttps://issues.redhat.com/browse/OCPBUGS-57951
- externalhttps://issues.redhat.com/browse/OCPBUGS-58144
- externalhttps://issues.redhat.com/browse/OCPBUGS-58183
- externalhttps://issues.redhat.com/browse/OCPBUGS-58217
- externalhttps://issues.redhat.com/browse/OCPBUGS-58341
- externalhttps://issues.redhat.com/browse/OCPBUGS-58402
- externalhttps://issues.redhat.com/browse/OCPBUGS-58894
- externalhttps://issues.redhat.com/browse/OCPBUGS-59101
- externalhttps://issues.redhat.com/browse/OCPBUGS-59228
- externalhttps://issues.redhat.com/browse/OCPBUGS-59229
- externalhttps://issues.redhat.com/browse/OCPBUGS-59234
- externalhttps://issues.redhat.com/browse/OCPBUGS-59258
- externalhttps://issues.redhat.com/browse/OCPBUGS-59350
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_11363.json