RHSA-2025:3775HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.18.9 bug fix and security update

Published
April 16, 2025
Last Modified
June 3, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-11187 — bind: bind9: Many records in the additional section cause CPU exhaustion CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🔗 References (28)