RHSA-2025:1907HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.16.37 security update

Published
March 5, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-11187 — bind: bind9: Many records in the additional section cause CPU exhaustion CVE-2024-12705 — bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:2fb32b6d7f7c2a8fae0b518b14fc868d7fc9ca5b1eee874c78d8d856ab337f87_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:6db0a5b193a76f4eeec50aca60683a78f13079ba19d93d12f31e92c789016eca_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:7d1c9b423b5b755a982847530af7723f2e437100b99576571d30062413bf93f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:bfb5419f9cf0e60064dac3d587901f3deb762199b82cc9b95ee7be76be1d6287_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:007c9dcd0906ba993c2bedcbfde4152ffeeaf51f37d118827ca38d82a4125871_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:4c1b3331776009de5283ca63018eed48e4067b48985b6dd7b1ae044d716e33f0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:a4fff7956a00ca072589de2724ea99ef75659ae54bcb74fe20140424c3d456bc_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:f17eb65bd04a15588640cba855c1c9f3459d3e520c130b7946edf815a26736f0_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:2110392f8363da2f596b09049f05b2417f43b86b35f6a4de9975d2a30aa052e8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:4cc458c62921125861fab1fa82b83c3d0b466f0c66a08d1a353f11299b690aa0_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:c39028d4e55b5aa0118ec23d338976d6411f94fecdd6d397c3610ffa8c838cbb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:dfb8f0147d67675ebdd2520bdab3f549f6129a3969e745ffba7360986bab37a9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:35a9f89ce014cc8dddc1a182d637f0a82560f775eaf2e5011422d894a5a35681_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:abcc5da8398a6239087bdebf477815e21d4a64305ee12bb4b968a34b9a6ea24d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:b43921c3d97f1b211d211c55c501e4386263214914035a22b764c653e7182d26_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:cb4d22ac518b2bf100896559269703aa477c66125fc8c1d8939a8521c2c1ecc2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:25b453e1798919488706fd02fdaa99f806248efcf391684221334fc37010f0f8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:482c3fe219374650c5769f5b5155a4430573155db6b1cee657e6ef28955d241e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:c5ceb09545e157e108fc3cbca1dced4f5b6eeb7dbda7384743473113bae19c99_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:f3c4512c604703a931c804a6d7acfe3b30df683445bd6562ebc95c48e3db141d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:8226726b04516291c8c427c2ce2a1ef09839ae03624f0102d7a212bac191fb82_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:b518b6ff0cee09ebb27aef0d78bd3020d0e6bdf3620de369d6454bde7d199dfd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:dee928a4260e83feb1a684171ca21a9646e0cde379ba65e17454f7810b98a3f3_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:fb1587df07fd8865b74b362605cce2762d020f4cff57e1c1577dfb905233d472_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:4e5d9c36e29e24ef5697055a1c13115d5abb70d641de95aeb839f95f7c6cf9c4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:a3212a4e794a7d6f154dee96cc9aec82f5c8290c880288edb16dfe8401f6d1d1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:a81a611a7bdd0d5e29cfb4abf662108cd96009cb3a7fe69a90a62021786f4f1b_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:c3402e8863dac839709dd10dd274f3aa028f5c893d3faa768dc3b04e504fe163_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:8f86da03d5a012b9e029fc1903736e7f1cfd2f704bc3c32c630f1e301dd8d86d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0065822bf39b11e3a3113eb2dee4bddf0a07fe0967892498771bd9728e145ad0 (For s390x architecture) The image digest is sha256:8decf869391dabf7487a3c531675813a15abeadbd542f1d287a9e2a5b5598f2a (For ppc64le architecture) The image digest is sha256:9b45e5b3617ef97ecd5cc03ad142c209f26ce00940c1c9bb6220649c7d697855 (For aarch64 architecture) The image digest is sha256:24c0f2c999616ef69af9a587b1d4b23cad39f376c8e5d784b030ec4644b5938c All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Users can set the option `minimal-responses yes;`in the configuration file located at `/etc/named.conf`to mitigate this vulnerability. Workaround: If the feature is not needed, disable DNS-over-HTTPS (DoH) in your bind config. Otherwise, we recommend upgrading to a patched version of bind.

🔗 References (14)