Red Hat Security Advisory: OpenShift Container Platform 4.19.2 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-4802 — glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
🎯 Affected products119
- Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:520ae2fe7bbadf3d0c04ebd64e1786c32cd144ce917f32f533fe55a7a470cddf_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:57c9625472ab37891d19688039e4f485f81f9f9a601836e16bd3ebf81dc2cf24_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:a2e4335df2b122954243943a58f600b3a17e5cf8c42a17797ecacef9dfef6129_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/driver-toolkit-rhel9@sha256:f95fb97a84a2cb445ba3beefb1877c7a4033516a421c04b34c499b64e803fe25_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:549f2d56864a79356e616fa7b103cbdb13f727ff04ad49f9f6419b4cf5c8048c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:74b03d3722e5eb5a2dbf336f3c11e5559dcc69edfd5f8e0f9130db2bc5b48bd0_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:d6d476fea02046dac2fa1885745b1be8d05b6b79ff4e5a9b88f97cbdc81a8873_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/frr-rhel9@sha256:dab16bc099cc43c5dda06d88200416efe8721bf2c8fda52d1e1ebb41c9ca15c6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:0102a21fad9d70a791275b7ab149d5584150f36cbab119424a99d8dd861d1cab_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:6245ae2b785e058839cbe3bf4da7222931634e54a279ebe75ffde33b4d005cf4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:744c78bc2493c833fb87c4baa87344aeaebda40c36cb98c190668a4b200fa9da_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/network-tools-rhel9@sha256:ecc0bb3d51523814194cfcb216e2321bf58f377a3e08435e4ef6557de866b8be_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:0a25fa9bb5b7007f0d10cfff7ebb597a63c4bac8b91e56e3a1357a1c1ce51705_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:1281461baeea0bf58df27d5c761b814dbe68f43afd3e491b5d85b849d2c64a75_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:72bbdc3b9aa2fd7af609ebc31744fabc4f295a460f0c376fcda716f47690b1da_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/oc-mirror-plugin-rhel9@sha256:83c3d01313637b19bb3c1b4b0e97cec5802d0b2983d3fe16804a3ea95ffb668c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:3401d73937e072b1e3a368e413a2a07effc5cb456c0fc444569f5ee3c835d3fc_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:4a15cf118574e55d6dfe70f29275e9b806cc1afbe3a49153bc6ae31a21a2e4ad_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:69ccad03c58b0aa077b25346f83ea0bac21f76fa7d02d5c33339754891df98bb_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-api-server-rhel9@sha256:be5ed2cc1f533031c682860b97651ee4e0c6fdfff1e9387afaa7d1820fbf6e1e_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:22d84354035ecdb156db419708df1e9b00ede4b19f1b411d6fb59878ebfba8b0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:540a83e62e529c6c1c20732d4a1b7aac0007623241ce34be1ab0cd55c9f994eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:82b2ff405384389a2a411f272388fb3f4c9baaf7bd1bec014ee0509f9f7e00de_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:cc26caf84c49a582f3b658e646b356db0c1d2abf72ffd323ce1a2e678c57046d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:46006bd7649dfde4a30585ab96d5071e03af4bc8921e5c7951d3ad218872189f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:4891714c1f93747e26de73fc0a7a07d42ccfdfa86f5f0e83b4e2d70e621e4aad_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:89c57ca82a28ce42ef813d84c84f6ce5d0b51beb48396dc605a6326f66d6720a_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-agent-installer-utils-rhel9@sha256:dd0ffdefcc3d7403d6bad848b80f61e1489cb66f97e831b563ab9a2c03d532e2_s390x as a component of Red Hat OpenShift Container Platform 4.19
- openshift4/ose-baremetal-installer-rhel9@sha256:5b39dfaee0bbd8708f46fcb5c76a2ec2c4d055c2b7adae315e5d4399804fc68e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- +89 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:1293f5ccad2a2776241344faecaf7320f60ee91882df4e24b309f3a7cefc04be (For s390x architecture) The image digest is sha256:36d81f05d22a9b8755b887793bacbd49d2ca0ce38197598bac692a4fb0e55ae7 (For ppc64le architecture) The image digest is sha256:be3ec05343d4bf403b0e6cc1fb91cc05079314406d74cd52105342d7973919c4 (For aarch64 architecture) The image digest is sha256:6bbbb8b93ae0b49d46e479ba6f37da92f8177309b2776a414a8f128ab67dbb41 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2025:9750
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367468
- externalhttps://issues.redhat.com/browse/OCPBUGS-55928
- externalhttps://issues.redhat.com/browse/OCPBUGS-56020
- externalhttps://issues.redhat.com/browse/OCPBUGS-56623
- externalhttps://issues.redhat.com/browse/OCPBUGS-56825
- externalhttps://issues.redhat.com/browse/OCPBUGS-57062
- externalhttps://issues.redhat.com/browse/OCPBUGS-57064
- externalhttps://issues.redhat.com/browse/OCPBUGS-57113
- externalhttps://issues.redhat.com/browse/OCPBUGS-57148
- externalhttps://issues.redhat.com/browse/OCPBUGS-57217
- externalhttps://issues.redhat.com/browse/OCPBUGS-57390
- externalhttps://issues.redhat.com/browse/OCPBUGS-57391
- externalhttps://issues.redhat.com/browse/OCPBUGS-57394
- externalhttps://issues.redhat.com/browse/OCPBUGS-57451
- externalhttps://issues.redhat.com/browse/OCPBUGS-57485
- externalhttps://issues.redhat.com/browse/OCPBUGS-57689
- externalhttps://issues.redhat.com/browse/OCPBUGS-57755
- externalhttps://issues.redhat.com/browse/OCPBUGS-57784
- externalhttps://issues.redhat.com/browse/OCPBUGS-57786
- externalhttps://issues.redhat.com/browse/OCPBUGS-57796
- externalhttps://issues.redhat.com/browse/OCPBUGS-57799
- externalhttps://issues.redhat.com/browse/OCPBUGS-57891
- externalhttps://issues.redhat.com/browse/OCPBUGS-57929
- externalhttps://issues.redhat.com/browse/OCPBUGS-57930
- externalhttps://issues.redhat.com/browse/OCPBUGS-57937
- externalhttps://issues.redhat.com/browse/OCPBUGS-58060
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9750.json