RHSA-2026:0316HighCVSS 8.8
Red Hat Security Advisory: OpenShift Container Platform 4.12.84 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-4953 — podman: Build Context Bind Mount CVE-2025-8677 — bind: Resource exhaustion via malformed DNSKEY handling CVE-2025-11561 — sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs CVE-2025-40780 — bind: Cache poisoning due to weak PRNG CVE-2025-52881 — runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects CVE-2025-59375 — firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:0316
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367235
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2395108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2402727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2404715
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405827
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405830
- externalhttps://issues.redhat.com/browse/OCPBUGS-65982
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0316.json