Red Hat Security Advisory: OpenShift Container Platform 4.18.14 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-6538 — openshift-console: OpenShift Console: Server-Side Request Forgery CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
🎯 Affected products140
- Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:086edacc5707c7c1d84d2c716117ba68cff797f47ed40a400619afbd92d8564a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:47fe136f669b3d955d395e858e3d680ff0d469e773cdde128d05a113fbc13990_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:ad57630097283d18769018e1478677e835c10ad6d0cadb95b48ab9a18fd5da70_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:b414bb420fe3716a152ebe59b56e579a267d8d4484cec0776abe24f9c7e11deb_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:4341fad46f04641d4f336ffe51c92ce93ea526c829f7afd8a6670c857f2ada17_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:486af66ad642cb566491c240480e804a6e3d75fbfd87323f7894380c8bba7983_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:9bc7aaaa39d0ced36151be27c935ff123e7bbe4d9d4fd51db59ae29f16fd6b3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:f81140ebe7cf898ffaf651ab502464e9429c5c87df764a0dac1171101eb8a0ce_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:25f7d57926de4dc94a2a195ee1798a8858bf1fd124f44d0591c002037fb9a550_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:3c5d5f4f7418fbcef8fd9a671282f854bb3219d973cc547fa2097ae156a6faff_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:c2f8e992757d5a2303f97791b4fdbe5b1222f9185662d8a694083b825755920e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:d3c8c610752b2ce6b8c87240707cb3b6cb7f3bcdda5df3424cad1cd964f1e984_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:214235b1f8069c5e5e72917e467f971724d33fc6b56384174a32e9b38adbf5b0_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:a82505c4d1cd8d054c3436da5662d0e4087a23a865938e4d5856104357962939_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:d4cdf49415d2cb1570eb0dab209fcf2f44db3b36ef60168538fee4ad361e40e9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/network-tools-rhel9@sha256:d7005f1be8bb8fbfaf4dda24fe868fcfd08962d405d5af3887082acb50adb342_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/openshift-route-controller-manager-rhel9@sha256:65de5c5213d3e3ec2e7e86b371f0e49a5a32a006285762baa4ee00f861bd0cbf_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/openshift-route-controller-manager-rhel9@sha256:c2083f795f9435c85f247a2ab32a4e94e81b0abedc9d1c8f469771388aaf99ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/openshift-route-controller-manager-rhel9@sha256:dd6f74d8ff592eee1970526b7b195702cf70d57a88d3c1e47fafeb232ba51f0f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/openshift-route-controller-manager-rhel9@sha256:f3cf3c838bffebcb68b100b7be16ea254ef8106105ac654b00b2c8c358eee036_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:251f7cafc72beb9104184eee54bcc788d863f61ab5560fa43c9c00929b95f81c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:3625369852f13c306b00fe87855619d3766ec347bc10475a0510269799582ff3_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:bd12dea0f6825918e7098c39d381b663a821c610e7ebf1fceb200e14b3c6b21d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-api-server-rhel9@sha256:eebc71b8b3e87fe7e3aaa083e7844ab916cfdde625959a77656126cfdd800824_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:13b9a223ab5a5395b21577edd33ab6f48df56f82f63b05738826996e7b63645b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:3c3ee5a176abf333d440b2277795b90da67bc3cc733eb0d37c15f60cf722575f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:63b3db54f9c432ca7bed2952266e4f6faa50e6f9aff3d3aac6e84b64f2f86da2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:6816b5f3a4fc63f4b14a2a78aebc0c2ea5d4ec76023e832679d413feb7f167d5_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/ose-agent-installer-utils-rhel9@sha256:67ce51307fa2125f69e7df6d0a9d91de48e49f0ce99945baf8a52fa19734a7fe_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +110 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:78c0475ba249e03b0ed5b3d3cca619020a2996fb75efb9e7b5a2d5972fbdac7c (For s390x architecture) The image digest is sha256:78c0475ba249e03b0ed5b3d3cca619020a2996fb75efb9e7b5a2d5972fbdac7c (For ppc64le architecture) The image digest is sha256:b8fd429a9b3013450a156c636e7e6569f5c1ecf95a8cfa5d2554275a9665054b (For aarch64 architecture) The image digest is sha256:57e7ac3ce11ec15b2e1ca16ecbe06e903a6699cdd7a0bc4d2720128c71138959 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2025:7863
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2296057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://issues.redhat.com/browse/OCPBUGS-50628
- externalhttps://issues.redhat.com/browse/OCPBUGS-50840
- externalhttps://issues.redhat.com/browse/OCPBUGS-51144
- externalhttps://issues.redhat.com/browse/OCPBUGS-53172
- externalhttps://issues.redhat.com/browse/OCPBUGS-53221
- externalhttps://issues.redhat.com/browse/OCPBUGS-54663
- externalhttps://issues.redhat.com/browse/OCPBUGS-54899
- externalhttps://issues.redhat.com/browse/OCPBUGS-55016
- externalhttps://issues.redhat.com/browse/OCPBUGS-55158
- externalhttps://issues.redhat.com/browse/OCPBUGS-55267
- externalhttps://issues.redhat.com/browse/OCPBUGS-55338
- externalhttps://issues.redhat.com/browse/OCPBUGS-55383
- externalhttps://issues.redhat.com/browse/OCPBUGS-55639
- externalhttps://issues.redhat.com/browse/OCPBUGS-55667
- externalhttps://issues.redhat.com/browse/OCPBUGS-55699
- externalhttps://issues.redhat.com/browse/OCPBUGS-55794
- externalhttps://issues.redhat.com/browse/OCPBUGS-55938
- externalhttps://issues.redhat.com/browse/OCPBUGS-56098
- externalhttps://issues.redhat.com/browse/OCPBUGS-56110
- externalhttps://issues.redhat.com/browse/OCPBUGS-56156
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_7863.json