RHSA-2025:11681HighCVSS 8.3

Red Hat Security Advisory: OpenShift Container Platform 4.16.45 bug fix and security update

Published
July 30, 2025
Last Modified
September 17, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-45339 — github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog CVE-2024-51744 — golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt CVE-2025-6032 — podman: podman missing TLS verification CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2025-48060 — jq: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:7f7d477690a58e512d2e97533b402b88fb1ef7b6045f411dd02a4d105639bd99_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:b73244e66d7a331abf705631ea7d56fda5198264c3a848e3ca9150c2ee07118a_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:d78d788e6fe14a0221876f27d9ea3fe97edf0087e561926e9c602d5b366dea8c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:dec7bbe83e4732325d7ab1bbfadb5606da73c3ec376679cc871373b26e1dcb38_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:2bfbcb624fd72474171754668225033a8f8fdf45d45ded9936d92968584f2fef_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:b86ede895e1776337a843b396283d0ccc12f84416854a57aa5c093fd5bda6f42_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:bf4924008b5289a7209d72e2b93382f198fa56e82a1cea2e24cb4e592afe11db_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:de46f27293fb01a073df765a297a5e2bb4e74a8899803b75c0ed4c6dbf5c4403_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:49d7b5fad42dfdeabedad0757ff4564721338c2470c229cd12439efbb03aabe2_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:8b0f1b69651e612adbc371a73c88d92d74a04427e0c6a9a199e1ea3ebadea8c6_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:b443c4ac887efca9c7ae1e6a65872364de39a5d2788ffdc709755fbaafe260d0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:c1a2d3cfcb412ae5fb452cc55353bc2a3fb984cc6975b1174cd46962b09a5efe_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:03b63291901a3b3f607331df3b5b83a94276bb4afd257955e60a9a523509b66a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:0d42b1837a862fbad60ac14a65c6fc4f445d810755c2ade1f2ce4e96c09ec16c_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:946bfbd2008ff588958a2913fdbbf8ff97cbb90abda49c0a1bb2d8f50d6a033c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:fade63780e8638d839f53def17c1000c3003748e2ac40d93dcd1e477e503edd9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:b6cef4799c08d8147f533f76940fd2c2e6c264ae959808caa2b647c46c9e833d_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:d1a5c78f6a3a1baeea0f60600d34e355c2515988e22d839c9904f61fc6e46793_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:dc2f629937dc71551b3dc34dabeac85959bbcd5470b16cbfafee6ea1c41780f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:ee43220403364edaca196c35e5d89f72ede5d15ab79001f5ecda76177b9578a7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:43c5aa821980c69f21fc17215c5ef46d9d0a6304c59505ad0861eb642c6184b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:582d12af040d11118d86c0a4d1577de1b9aa100fb4468d991c7ae2572135f5c0_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:8cb0e1f1775d8b51a89cfc94731c318a1caa2da19a4ca7d9f3055f1e1d6184c6_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:a52d9c0ab9f4c98d21037681952ad8eb9b5e93f98097337fbaee5a2034f19d45_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:12d8bfbef5e5789c6ad3bbb2eb4946145d25ad528ca44dbfe1c73a6612f908bc_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:3396d714833a114dbd18fe785298879e375bcaca6bfe31d147965870be29e18b_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:b33f8a413b18d48c6e80e692add3d8f11fdb6e7ae24ae1c378b17360c3025cd7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:d4908d34f2fb261c7b4307baed51205860e0525dbed105e7802240b298c387ff_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:064262cb1d2e1db7b47f55611bed149a418313ee4e84a17a85e5ee8f07b49089_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6d097cefdcc369ba328e25fdfbfcdeaabcecad38be4b3c12a99f2222f384a31c (For s390x architecture) The image digest is sha256:a9d25b325df380289d1db3efc8f253a5438542e6f9edd8e68b7dd626b0efe74c (For ppc64le architecture) The image digest is sha256:26507363830ba7e1f25a1c5e611aad7aeba4b9abde7823695aa8545195cdc9eb (For aarch64 architecture) The image digest is sha256:4eefb51e3a09b5260f27ad1a93ce3f4034925f0a6b2837aba7eedf2346724dbf All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Download the VM image manually with another tool that verifies the TLS certificate and then pass the local image as a file path to podman, for example: # podman machine init --image <local-image-path> Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Do not process untrusted input with the jq command line JSON processor.

🔗 References (17)