Red Hat Security Advisory: OpenShift Container Platform 4.18.19 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-4802 — glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:077cfc5a0537ae3c0c186580b16321b10d3cfc1d9dd0f67e93a72f173b8a9b5f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:ab5887c1c3a4b2649d816cbc7c320c763a9babdf5a237e5c9eedfcc2ade448aa_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:cd36c30b373c5a4c2fa6d6d8b8ec2ed69444aa23c19e687f2e2f4f889a3ee852_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/aws-kms-encryption-provider-rhel9@sha256:ea27e2d5291e4db7042210a7da6d72d7592bf0bd8077644a258f2c2f038ecb98_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:3ad7f6be9d2785e078976e4e7af54d614e9bc83f67bd8c6fd7734db1814ad17a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:5c58a52bf441ff4c66ab954e23b4bc742c7e8df50a5586fcf35411089d716b3e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:cef0fbfcf9a7e0df921b28d2c26473301670732b5fee7a4553083fdabb5effbf_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-kms-encryption-provider-rhel9@sha256:de1ef5c19b835c35072481cc64e53d2d35575759223f91fbb6318575b5ca9c90_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:5d361f6f450dca80098f836aa3e140d3f0fb764bacc82da3d3baa5fe33b2b6d4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:81daddc136ac3a010b8c9d318f2d49c07b5533809a702a82c29c1a678deb7471_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:928ff1d4ea6a9df273de718a83398c4c282d8a4480f5349051428e96ff93a6b7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/azure-service-rhel9-operator@sha256:968342787f707b7f0b81fe9d439b14f40a5c4a7fb3baefd394cb3ca3dc6de3c9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:5012ae4d78bd398bfd8412be108a7734297b478bfe52dbe9e4ec39a6cf030dbf_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:c9148bc3b0b4f53ad45d400fba97a360024decf7c97f7a1e6859bb5ff366ec8c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:d9b98677f52d1b35faefaedcd66a1f0f8c439fcce97958c928e4dca5000298ca_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/cloud-network-config-controller-rhel9@sha256:e2835ac82b793c865650648cd34e97dd4767f01d70d258b58a51be55fb12a6c1_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:27045fba765495ea9b886a01814233445c5206972eac15758795961eb0c37fdf_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:6ab6325cf12fca94e430b80362b029cba62c5df018b7e36703b8d9d1c39fbd0e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:8a75b28bfb9d41f8e80325d3ab18fab6faca842a85bbe64a177a4d5c7da8b0df_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f45c4ad81fd71f90f90e00ca1b3131a33fd4f6c7e089a1efea66cec4f9e80b78_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:216f1902be9420b73201ce769b297de8a1dc113aa74e8de8c107f42774c88460_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:67066a9c9b373cdfdc9a3a8e7ff0edd108bfe7e7d3b0833ebd97266c30df1184_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:c18f30037661406842453c08f3e0032e6021dbea466f93f03698d6be3af03e00_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/driver-toolkit-rhel9@sha256:cd20c17401d4a13672a0ae64122a0e5dcaf8fd87c785cb5919d953d608998a81_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:5f63001478b5ba7cd0f3587a1ff3b933f624b396f3c664a538589c4d2fa4d69d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:626117a78794708ea05f49fbe70b0cdd416ce7901b8216f830b7f535eb1974ce_s390x as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:c8b18db7e6ab14c3b0992d80653e7467e5e90c667afd94557f41147155f9b2e9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/egress-router-cni-rhel9@sha256:d5d68ccd167f8befaa5d20afe28d735225eeef82d5f2733eeca4adfab1231dec_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- openshift4/frr-rhel9@sha256:044cbd22a1c38148cff8746f07c2aa7a03829fdc3b950be22a31c450157efba7_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e6d80b9ab85b17b47e90cb8de1b9ad0e3fe457780148629d329d532ef902d222 (For s390x architecture) The image digest is sha256:f9e0774cbbbd6e8cef31bb00b1bd13fc4e8ca94c552dacad15d7b90384b4bf9e (For ppc64le architecture) The image digest is sha256:a412f58cf7f7459c37a9352079ccb4c22b271c6b544bc992e8a2a92b3f020df8 (For aarch64 architecture) The image digest is sha256:db9ffaf79548b7a3d5399ce98c0375c4bf9b8a4039cce46b6ebe8d1ac102d149 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2025:9725
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367468
- externalhttps://issues.redhat.com/browse/OCPBUGS-36173
- externalhttps://issues.redhat.com/browse/OCPBUGS-44458
- externalhttps://issues.redhat.com/browse/OCPBUGS-45869
- externalhttps://issues.redhat.com/browse/OCPBUGS-54463
- externalhttps://issues.redhat.com/browse/OCPBUGS-56251
- externalhttps://issues.redhat.com/browse/OCPBUGS-56797
- externalhttps://issues.redhat.com/browse/OCPBUGS-57106
- externalhttps://issues.redhat.com/browse/OCPBUGS-57329
- externalhttps://issues.redhat.com/browse/OCPBUGS-57507
- externalhttps://issues.redhat.com/browse/OCPBUGS-57580
- externalhttps://issues.redhat.com/browse/OCPBUGS-57743
- externalhttps://issues.redhat.com/browse/OCPBUGS-57900
- externalhttps://issues.redhat.com/browse/OCPBUGS-58047
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9725.json