RHSA-2025:8704HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift for Windows Containers 10.17.1 product release

Published
June 9, 2025
Last Modified
September 7, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-9042 — kubelet: Command Injection affecting Windows nodes via nodes/*/logs/query API CVE-2025-22869 — golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh

🎯 Affected products3

  • OpenShift Windows Machine Config Operator 10.17
  • registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:17e4816ce48fe9e387503f3fece60dce901070c7923ed5e956dbb0080360b4a5_amd64 as a component of OpenShift Windows Machine Config Operator 10.17
  • registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:ba892f84e923e83a32d5f66dd6f61ff5a6b51cdeba1ef3ae2b250d822b1b0482_amd64 as a component of OpenShift Windows Machine Config Operator 10.17

✅ Remediation

For Windows Machine Config Operator upgrades, see the following documentation: https://docs.openshift.com/container-platform/latest/windows_containers/windows-node-upgrades.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated when using the client only connecting to trusted servers.

🔗 References (6)