Red Hat Security Advisory: OpenShift Container Platform 4.16.43 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-8676 — cri-o: Checkpoint restore can be triggered from different namespaces CVE-2024-45497 — openshift-api: openshift-controller-manager/build: Build Process in OpenShift Allows Overwriting of Node Pull Credentials CVE-2025-4802 — glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:0ad58509ee1d9173b6ea3766c27f092fdc5e1fb3df624099c9d4894d627e0ad9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:2684dff77b68b4f2f32c2377f16f3f5eb13ad2f7531280537f54974c4036d752_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:bb43a0a335f735306e0b908d71eeeb6392863f4990f162ca223513af0c1c6564_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:bbb24537ead072d537c0043f12e04b6bba58460fdb13febe7f6ee03cbed6da37_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:52640a00479f439ebdfbe765ad905657ccb1b116988037c6f4638988469c3e45_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:55c41d0b4067933e275d44a4a67c1f98e9a4b91f038b264c3a8451b28362d6de_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:59875954a1a06ba0019a07cdadd65822f8907753d4f152d238a3b11906a099c8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:c3f532cbea98805ba57662a61bcaa09fe4b916a03dea4f8b847a4fdc5d3872be_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:2f7ea5cbc6ab18eb239e5763fdd26eb38171b9c83570e62f23c69310f01229bb_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:9ab0d815297020ef9779d2903faf6a7968c7ed3fbdb46aa324567aa760219104_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:9ccb9a125a0b2ae8e314dba8fdd4f9463670518cf9777cdeb3ac720ef58a7348_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:bf2dca1e36fe8ee1c3980deea39402309e651cb107480b84c90f49ff5d8fcdc7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:172c28e0f4061d849557faeb506ff0d41059073e1dd7b0c72b87874a904ab29e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:543e819599d655137cdbecfd604698f508df42af76a8bffeccf0b457527f259f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:588d2911b50ec8aaedc56a87531c3202193c8c49258a285841f9ae5a73306bb9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:6b65189c55a43eae1fa9037e01344b926060e95182c299d855b55202da437f49_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:ac76302fc9b593f0e9f0e0158c9632703b674f091903e6c16f61e1eb3d041d60_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:df243e8f797990d424089382ee03c1b898481849f5dfc2918188cf7e7dce9364_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:e5a144bcf4ae2edeca2e2ebc063705e71f41a368f5e33a68e0eb8b778aecc22b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:e865413b838f7c779112768c6831545e9cd5c17ff58a8fdbafe0af208c8481cb_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:00673df16a9ef2cb85b0150edd83d6fd785db94cb7008f3dc3da611778d6e97a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:06a2d1bbdd175f5ac8a17064f97d429bd6a9929dc34fcc1d56f055495e396623_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:5eb5a95a0f552115da354eaf2fcd7ce6d63c0fd05651529d86ea2a3b38edab6f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:9bd8eea072928494ae36a68d89d940ae4d33c03cea153ce67436f97cee491ca6_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:3c60aed00bfd87b7cf2573b5cbfddb80fea5093371b4b8ec0f96ce3b77af996f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:8a4d27e448165c923365427922709b6addc21ba50a46ae7023e480b8b0a46f5a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:f1d8b825c569b207a7bb680f88775eca2516c12afcd91f24ae5899c5edbbb660_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:fd119ffb68f0a34f092194e94031876507b292c4117f158836c0a3504e0d1d3b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:5c423ba7446ec3a39b5ce2551f8ccef03dc3bb6f3984936174a52c56133d6c03_s390x as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8597a1a05b1792619cf56734de97fabe5f7ff77a100060924b4f5740ec10f2e1 (For s390x architecture) The image digest is sha256:379c66f3c9f8aac11cdaa74614fd8d2b2c8a4626c3604f641d2ea7ee0d46be70 (For ppc64le architecture) The image digest is sha256:5a5897081b628d1330e7d23dd3bd3de71cb647152fb1ed3a4fc10a85c4265ce1 (For aarch64 architecture) The image digest is sha256:235fd4e1df9a004001768ee48ff44d102634c08b789cc37a329ad6a52f6ce13a All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2025:9765
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367468
- externalhttps://issues.redhat.com/browse/OCPBUGS-14749
- externalhttps://issues.redhat.com/browse/OCPBUGS-48121
- externalhttps://issues.redhat.com/browse/OCPBUGS-48283
- externalhttps://issues.redhat.com/browse/OCPBUGS-49391
- externalhttps://issues.redhat.com/browse/OCPBUGS-54457
- externalhttps://issues.redhat.com/browse/OCPBUGS-55282
- externalhttps://issues.redhat.com/browse/OCPBUGS-55697
- externalhttps://issues.redhat.com/browse/OCPBUGS-56242
- externalhttps://issues.redhat.com/browse/OCPBUGS-56704
- externalhttps://issues.redhat.com/browse/OCPBUGS-56812
- externalhttps://issues.redhat.com/browse/OCPBUGS-56981
- externalhttps://issues.redhat.com/browse/OCPBUGS-57096
- externalhttps://issues.redhat.com/browse/OCPBUGS-57203
- externalhttps://issues.redhat.com/browse/OCPBUGS-57270
- externalhttps://issues.redhat.com/browse/OCPBUGS-57290
- externalhttps://issues.redhat.com/browse/OCPBUGS-57326
- externalhttps://issues.redhat.com/browse/OCPBUGS-57494
- externalhttps://issues.redhat.com/browse/OCPBUGS-58028
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9765.json