Red Hat Security Advisory: OpenShift Container Platform 4.14.53 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-45497 — openshift-api: openshift-controller-manager/build: Build Process in OpenShift Allows Overwriting of Node Pull Credentials CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:2ef7c2d7c840726c5f825ddb4a2e5117809680d4cc644ed9577295730e5846d7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:658291d0dc571ae460e1f6e23aaeae40ef3680d0d82b0286edceb0773283a748_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:d38d531fbebd8c37653a9be49ebfef8cf8bace3a6ce46c9ae7735bdf2101a1f4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:daa79d07801022a1305efe54bc4cfffc82c37484e8934d5bf3123b0b43ab73c3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:1a78c0b5b39b6a580f50687916bbeedc5747ef2e11c70c1a6f39c7bc8c3eafea_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:1d7252834bc4b64813733d30d807399ec53a951654acbcf8a4120b392a569b4f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:8ca5192d10b438e42102219cc54611fa39b11708948826f523db054c57a2e758_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:deff3d24ae487cedb2faafcfbdb158a704ecc3b5e12150ed3b5ed3ba713808e5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:090bcba5f37ce2cd3fb82559516400058f9fb900a2fe4f0105b0f2c3c75600c0_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:19fffa3f8d554cde2cb91147ad11f1c36fe3572918a2aa7d51154d72f6ddb427_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:39983d7422ad8deb4f81aeafc161316296eff7c754001ef8afdd8ab724bd0db5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7458910d96981fa9f6d5409f1311f882a3773985bea8ca0de66d43d2196583a0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:4b57cb7fff67b4a161f718092acb2ec9978025675b0841b3570436e8992540d9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:979d0ab8299710e7e45183190a588d6f754dba8a5cac0b1a84c1d2e14068be7a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:aebebe46a9d93347cf3f4bb32d4975894dacb91ab6428b29e2914c9782b4669b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:bfeec5802eb2264b256aa96c1e4590465e2aeda8efb0b29d0e6bbdc7f16d6b1e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:183da35026cdb13b0e0647655bf2b10ec31de95d65f2906bd4b257fb0afec6c3_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:3ebb54caf6e4222d1d7950bd8fc5ea6b4d785c83e360764405d62603dce88c69_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:7542dc2c28f3c480bff5e45c16912b0ca06a6adf21e2ad46d928c5c78c2588fc_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:9f54d925ab415e4a99fd83a76594f37daa6103dc8a46a8174a208050495e75d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:566238ea75e8afc123f66c0c37f30e8db9b9526515dd75a482741a52cd090640_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:5c01829fc0f9785ea0351481c9246da64cc587fc29bb1520280653ed1670d435_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:d98377144d288f8e5a1de120ce8c94d3f0b0a62567a2fd438b12174db6414057_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:e24652f4432be469383c50cbe35e07bc290963e035cd6e7d2c407d1eff396102_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:58c22545d6c9a6f06e8feb9e58dd380440b140c3933c14299757229960a72474_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:82d68d06bd124305f6ef4534e12a561e40e9638426013e27c55605e09af627f6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e021615947b55061ed20391f9510e96b84d6c7a4e8f91505e7af94ceb53b3cf8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e8800421f25f68cfe9aab7c3e6a6fe670b5322070bdbedc4f5db8074a817bbeb_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0bbefbb5cb7745a33fa7db589a2d8affd0a61e459655de019d76ca2e88ec5054_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:c71d99a4996a4d09e5005a0045a7de7b3fe316080e5fc3a26619f7010dd70d0e (For s390x architecture) The image digest is sha256:5aaebef8f79bbe32d1b9eed094cfabd47a69e601290df434bdc3223c577f953f (For ppc64le architecture) The image digest is sha256:a189ab95534f40cd2e4d5b29aab9e1ee370b518f3c592344e0d449debf976600 (For aarch64 architecture) The image digest is sha256:daa4d609254247877b698076a3120b215c1b1043f6ece8eed81235885d030e27 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2025:9759
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://issues.redhat.com/browse/OCPBUGS-43743
- externalhttps://issues.redhat.com/browse/OCPBUGS-55467
- externalhttps://issues.redhat.com/browse/OCPBUGS-55620
- externalhttps://issues.redhat.com/browse/OCPBUGS-55936
- externalhttps://issues.redhat.com/browse/OCPBUGS-56127
- externalhttps://issues.redhat.com/browse/OCPBUGS-56194
- externalhttps://issues.redhat.com/browse/OCPBUGS-56548
- externalhttps://issues.redhat.com/browse/OCPBUGS-56951
- externalhttps://issues.redhat.com/browse/OCPBUGS-57099
- externalhttps://issues.redhat.com/browse/OCPBUGS-57321
- externalhttps://issues.redhat.com/browse/OCPBUGS-57341
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9759.json