RHSA-2025:9136MediumCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift for Windows Containers 10.16.2 product release

Published
June 16, 2025
Last Modified
September 8, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-9042 — kubelet: Command Injection affecting Windows nodes via nodes/*/logs/query API CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2025-22869 — golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh

🎯 Affected products3

  • OpenShift Windows Machine Config Operator 10.16
  • registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:ba052e0c411a5a43fe52eba3156701f8e6d1d11b987a9de617280f056bc804c4_amd64 as a component of OpenShift Windows Machine Config Operator 10.16
  • registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:c9a6166158e1ccb1764007d79c6e0f879505c3546eb45cbbe79ebeefcc78a728_amd64 as a component of OpenShift Windows Machine Config Operator 10.16

✅ Remediation

For Windows Machine Config Operator upgrades, see the following documentation: https://docs.openshift.com/container-platform/latest/windows_containers/windows-node-upgrades.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated when using the client only connecting to trusted servers.

🔗 References (5)