RHSA-2025:3973HighCVSS 7.5

Red Hat Security Advisory: OpenShift Virtualization 4.16.7 Images

Published
April 17, 2025
Last Modified
September 7, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

🎯 Affected products109

  • CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-controller-rhel9@sha256:2fe1958c0a9c75f4056e3d0d40db40bbc0d1329b9d27ad1ef653e85b61703cc7_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-controller-rhel9@sha256:3f0217cae34d4b16df943560d4520dde4fb60df41e410e21dee2ae869ec727ae_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-operator-rhel9@sha256:7ba4837979d4bd1e87ed5c14ceab58592dfb00938df6cb6dde552252a339c064_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-operator-rhel9@sha256:a35aa1b21f5e6e793689e79d5b9499e8e951ac150f8e943d6052e898ff48aa5a_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-server-rhel9@sha256:622090a7dbba4f48417c2ebbd90a91e0d627a1bcfb14fc4f4321a96d1b8e2299_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-server-rhel9@sha256:cc16a023bfbed7de21571a295aed483806450f9a30731588f409054181241610_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:609083c8900b4523ba95f939d52b5de182a7c99fda096129bb7fb4f707b032e9_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:a5e2c8943582c7b162fbb1869054639c216867ca9299b6daf918cb2ceb80ff8b_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:8be81317a62550832b4eb68aed1460620079b1cc5c0da4b981a01aed5810b2c3_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:cb95a365a1cd31899580ca98f150e24ba24b717ff972b526402031feb967f7e4_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:506357bc4c539106aa90ba638231351a6d32848d099640bda19cec3993ea278f_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:532e565290b766087d82fcc42712b925a5ce52fe6fa7f10a571c135d04837c26_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:a1a7498520a48efaf205314353183b6d11a686044f1f83b76f1a63baa1530497_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:a573d94a7ecaf067e6c22348b540aa8712167d5a4a2f2810babd4c6859fc0282_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:2a1c93a7ceaa473510f7c30ebd14d390118f07297b9a0d330b2ae4e72970a48a_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:c654b470f8ca3c88f5f6f8045febb0bb652de5ec3a99ca4a513cbaefc7599c0a_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:05b7df27a2de873642e6a2b48782ee16d6e5fbaa5aca1601dabbe7321fafbf07_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:5b1f11354c7a1f3b793bd407e48ce994da6757693d8025e456b42682f1eebdb6_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:5a1e8e17784b874d64b03b3459c717766d17982266483e93952e567ec4630ad3_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:74e293534f946959b409aa5c070791bd50485661782ff3db77a4700686cffeb8_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:03108466f4e8b9e099dc6403147351995bfd80b8dd79731ca4cc0634a746998a_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:b577ae7ce09448e1889cb325d7e40e355a4e475b015f726b1404db0bdb932740_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:3fd9e637f55f7c894f020d7984cc6fe46b78e11ece404ba8e5e6eda2af3310b4_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:626396e60da1aba16b94d1776cd7c27fb3c852f601ef2eaf0b34310a0d8ba4e4_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:6b9a4e20f363ea5f7e46d238ed64bfdc2efeed90b45e59f05604aa0c4e12b53d_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:d02c0308eea8d7f31456ec008e45d2b372947d97e0f3e5a9e4975066efbd66f4_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:5dc4a96214f58ffab986f9c176b663995301925439e2c13497594863ac912a9d_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:f7e6b8d329006569d5f2aa0a12efbcf56ab5a69f74202dd66acc0ee94dfb116c_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:bbe868438feec94c0f1b1d19beed36ce43463f3eb857c571d4d8878ed63da849_arm64 as a component of CNV 4.16 for RHEL 9
  • +79 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (18)