Red Hat Security Advisory: OpenShift Container Platform 4.17.32 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2016-9840 — zlib: Out-of-bound pointer arithmetic in inftrees.c CVE-2024-6538 — openshift-console: OpenShift Console: Server-Side Request Forgery CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:3f5afb071e564ed9fb7cae5a50e55ac26acb66f334dda510e8489615a1d01c3f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:57e020a67c4a158da35b62ef7c39703938d9f41f8a18de3b4b617c12a5440928_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:601c9693fc929aee8d5f305e85c3b2a5a97d1e559be5af6bf7f468d183c27ec5_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:920cc169b47649760745bd80e6c9dd968ae01d4b03f8d295bd8ffea3848182b1_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:78d94886626144c918c1d8b4704e8ec5c7ab4eda434c80da6c667112de8b7e21_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:8f542c0a41dc4fbc5e51fec8fa1c0929507f437b7d3bba406945844bdb5a6804_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:c73162ae943aacc3a6a3c7b4d2d8ba75a2cfa58937516c45058287dfc919dc5c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:c90556fd5b1401af9168d2a1c40005722143bbc125eaf2dd6e34a52e13918f6a_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:1cd3274aead792eca5909891c681fe520cd617a8fba0a995812a3a8f92966606_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:23030ae8673000d28eb7fd205bfd0a4b86468494acb4d9a193f030bb9323c282_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:4735e057328b982526b46028922092629695daf81dae3d20092c6805a5769a8f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:94be933da1912535a74116d829a0ff1bcad2edbaf990688d038f78fe7edffb58_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:21755ed0771b3999ab9a939b06b72094d3b4734d6ea579153d0f46611e7798aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:2cb718207e75e3c5a3411804c688b5e314c85c79082522b079859a58c2ad2604_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:993455a44ba3479548f91c45a22b948cad9df1465cf788a2509cea5a887ff8d4_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:cd702ce26ad3ffa98fbd09db626777a75b3554958e66c2bfa6669ee6fff414e7_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:2edc74f04b33defafad63550cf657cdc0c1d405f7772415830765ef739fa77fb_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:308e10a81db2993cb5fde68f3bf85de024001292fd5e2cb8e0c9a72310220b33_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:5719ff2644c8aa1b61610c1a1f42a2a6b7c0f8b9bdd08050aaeb515a7a202162_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:d39bf09e44b81e1a0fdd8cc86fc73c22afe6a199f239c9247c57e63ad969e6b3_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:d23995ef06f00360b2b20bf509bc712bf8a00cd7982727fced44a3fbc1b87b09_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:ea68623e012218b9397649e5e8c03d35ce45571c8e1c15330c9afb9bf8929049_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:f48c26ae9d1da14d547a7270978909be5febebfac684d6360615cff160f7b634_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:f84106054334a75c780ebbacdb8b7bb1349af5d704f23f95411e9d3052ad3b04_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:14a929647086730c3ef6282f88bc8d96c4ed0e079447ee5cd93452f4229ffb06_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:2cfcc0a5b7baa867d5ddf8d13dd0d2556307f01e0a509f01a6562d92faae0351_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:bb1bb7afa6a415879a694ff4a624b158a7b7d23c0c6bbbd58ad5874bdd73d592_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:e8b0149993b215d53d9a2c12716f6973df1e13ac8b635f814f4565262042cb03_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:0f4bee4fb66708b50d10d6e1f4e8284d0fcbedda5f2195421f31520b69c25027_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0c2421a241e95f56895906885e7f7e53cb1520ee6a82db5cdeea98f5f65457d7 (For s390x architecture) The image digest is sha256:542000db3d3c126ab0c88f24e7e238de66a743026b95b603d311204dcb36132e (For ppc64le architecture) The image digest is sha256:7482c48c0cdefbe9f88e0ddd748a6f00e1d2cc1fbd395a8270425a48d758a0c2 (For aarch64 architecture) The image digest is sha256:930640a1fabd9bd84756bd35e5e5518e3e5576d5a22954698b6456729fb996e8 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2025:8280
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1402345
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2296057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://issues.redhat.com/browse/OCPBUGS-49390
- externalhttps://issues.redhat.com/browse/OCPBUGS-54664
- externalhttps://issues.redhat.com/browse/OCPBUGS-55740
- externalhttps://issues.redhat.com/browse/OCPBUGS-55756
- externalhttps://issues.redhat.com/browse/OCPBUGS-55795
- externalhttps://issues.redhat.com/browse/OCPBUGS-55800
- externalhttps://issues.redhat.com/browse/OCPBUGS-55841
- externalhttps://issues.redhat.com/browse/OCPBUGS-56395
- externalhttps://issues.redhat.com/browse/OCPBUGS-56573
- externalhttps://issues.redhat.com/browse/OCPBUGS-56574
- externalhttps://issues.redhat.com/browse/OCPBUGS-56655
- externalhttps://issues.redhat.com/browse/OCPBUGS-56665
- externalhttps://issues.redhat.com/browse/OCPBUGS-56738
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8280.json