RHSA-2025:17501HighCVSS 9.9

Red Hat Security Advisory: RHOAI 2.24.0 - Red Hat OpenShift AI

Published
October 7, 2025
Last Modified
September 5, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2025-7783 — form-data: Unsafe random function in form-data CVE-2025-10725 — openshift-ai: Overly Permissive ClusterRole Allows Authenticated Users to Escalate Privileges to Cluster Admin CVE-2025-55163 — netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability CVE-2025-57852 — openshift-ai: privilege escalation via excessive /etc/passwd permissions

🎯 Affected products119

  • Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:801fd3a439df5c91a5902f4416f8edf341aa677e92891f285e5dafa21f44d8c8_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:097c31a339c7397c7406f64f37faa2091db82e7a17a7c822054fd36256a41e1c_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:6e97342e17a2a4e0307a3e33b2a3d45520e58c158634d01b7e877e380b03dd23_s390x as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:7da8a91741479ed7d7d97d2bb40600226978cb5db6d58d6560197ae16d01f0e2_arm64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:ae83683db094671e552c272df963e24437bc56f06a5858fa164d204997b4040e_ppc64le as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:e4349107067c3a3bb54f81b710bac503b3eaf4b6a241ee6cfb7b8e09b96fa944_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:b3abe8908685f24a6cef83be8aa2daf1b3c6e84a77b27073fb5bcc27f5692946_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:6b88129b403b635739d9d24bd32fee139019f340b7a6417bc40f0bf431667f70_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:3efee1c3f565e2ad01f5fe6abe03a39e64ee90177b0a74eb65bbe6d0a2755306_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:0cae3e6e84b179cf6a304ddfe5948f53245dcf635e56cfdb6e5885e5fd86dba7_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:c1a20b2ec840ff8af1ee4f78c3dead85ab6c6464d61abc6b687ed587fb2b5050_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:fcefacdd2b822789c2144ce0e03460f3326cdb52d5da9f07c7f4b01ec7294915_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kf-notebook-controller-rhel9@sha256:03cd845985879dd838683d9ef9a52c107409942b0044184e7f111a849c91e427_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kf-notebook-controller-rhel9@sha256:0edc9f3c52359fb47be7c4c48c4ed62cefe5c23b5353d6b8cc491a242c9c9d54_ppc64le as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kf-notebook-controller-rhel9@sha256:5afd27a83cbbb306cad0274804d2834319ca73408e59025b949422c77dba5c28_s390x as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-agent-rhel9@sha256:4a795760fb94d2fe06b83095f92dd571d96271ae2dbbdb346a299aa2732d7326_ppc64le as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-agent-rhel9@sha256:51e90c01b406e5d8182ea9c88efbc8ebc61e391748f5b6d29ec644d49a8c64f5_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-agent-rhel9@sha256:bf6a73deda638bf03c0074acb94a83f62ebeb32a8879e76b3625371a2eacae0a_arm64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-agent-rhel9@sha256:c24fc0925a0257e846566074a0123da41562459b98c94b335fc08354da01eaf8_s390x as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-controller-rhel9@sha256:5806801f021a2a04cb6ae68a81e0efef81ef75f2bbcb97687c7149fb06a086d6_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-controller-rhel9@sha256:67966e9f12ecd15fa79d1a8dcad3e8a93754d814e101e34ae6587f06b37c1d78_ppc64le as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-controller-rhel9@sha256:920390eb920838a139cd4c51d8d58c8b9f6b34d684e7bc5e7f1023060418e6d4_s390x as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-controller-rhel9@sha256:a2dbbec45fb83d282f1696b6f613bede73b081b5e1ff793eaf876c3b8280a386_arm64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-router-rhel9@sha256:16499021c8a9cb044c8ede0de9b8da8b55601a2ac0a5c4563bc05860e6bd6d21_arm64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-router-rhel9@sha256:7e6036d271fb82426fb120f6c5ad8c077df72c71587aaf36a7bc091f612b1d9a_ppc64le as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-router-rhel9@sha256:921ea8f5f03b14200758257f20144656aed31c91d191d0baed35331a39d284b9_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-router-rhel9@sha256:cc01d759cf5251463edda6bc3ba57dc4988f05478e97a7a91173eb00b7e19bd4_s390x as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-storage-initializer-rhel9@sha256:167d591644feb8619a84c5f707b0736b0e06605af3192ddd9126c1a690fd27a1_amd64 as a component of Red Hat OpenShift AI 2.24
  • registry.redhat.io/rhoai/odh-kserve-storage-initializer-rhel9@sha256:3ecc440601695c42ab09dd2fdfa90c801da996b0a1ff35cad6b3017ced718ade_s390x as a component of Red Hat OpenShift AI 2.24
  • +89 more not shown

✅ Remediation

For Red Hat OpenShift AI 2.24.0 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: RHOAI versions 2.16.x The recommended fix is to upgrade to version 2.16.3. However, if Kueue features are not required, the Kueue component management state can be set to "Removed" in the RHOAI DataScienceCluster resource: ~~~ oc patch dsc default-dsc --type=merge -p='{"spec":{"components":{"kueue":{"managementState":"Removed"}}}}' -n redhat-ods-operator ~~~ RHOAI versions 2.19+ The recommended fix is to apply the available erratum. Alternatively, follow these steps: 1. Prevent the RHOAI operator from managing the kueue-batch-user-rolebinding by applying the necessary annotation: ~~~ oc patch clusterrolebinding kueue-batch-user-rolebinding -p '{"metadata":{"annotations": \{"opendatahub.io/managed":"false"}}}' ~~~ 2. Disable the ClusterRoleBinding by updating its subject to a different, non-existent, group: ~~~ oc patch clusterrolebinding kueue-batch-user-rolebinding \ -p '{ "subjects": [ { "kind": "Group", "name": "REPLACEME", "apiGroup": "rbac.authorization.k8s.io" } ] }' ~~~ It is important that the group used for the subject does not exist on the cluster to prevent the risk of unintentionally assigning these permissions to other non-privileged users. 3. Once updates providing fixes have been applied, it's recommended to remove the clusterrolebinding created in step 2 of the mitigation. ~~~ oc delete clusterrolebinding kueue-batch-user-rolebinding ~~~ Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

🔗 References (8)