Red Hat Security Advisory: OpenShift Container Platform 4.15.61 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:19f137ed29809ef38639c615cd242c3d6ff56e5c89773aba18793dcff735aff8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:6dcd6797196366bc3c46595062cb6421e9c54a328e178168db407f823bfbae9f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:d25d0bfe3192d3af00d134afd0d1a9db1562c6c753dd41c7d1f5832244742c7d_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:dec48cd6948004142bb5a7fa23213e1953935b94ab10840d63a6a88fc6d7535b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1804c77a4da1726b5efa6e325a0c77d255e38ad062d92d3b6dbcee171e09d415_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7c88fe58f7554600091ec517471cb2d177bc753e698ecfc2995de00e1b5bc938_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e42819904f501c552594c4df5e7f282cfda6887ba29d8146f11f853c10644057_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f00065c4d5e568444573d0754fe1da9eefab42bae09034c126c6e72353e0f6f2_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:316ce41c439be00eb7df2a73cbbe737c8047f2759360c1c3e4f9c172017b7080_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:a30c61230e57253aa11972ea02c3dddbffbd22cf50892f622715108693f84f3d_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:e21df7ff986b0005ff4940c00320cdaa88122a91ac34b6004115d7783c630ca1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:ffa15a3d60aa3456fbe3fe854982a4cbc89bc2a04a8063a3ef834f16e6e1758c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:13c39e18eb3eb98c2402092030fecd5436b91938a83cf792a335d043bf15c0ca_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:acf80c4eea2dbb99f5e3db56118fe574219e96a9d0cb735b2812e3ee6826acfb_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:dd5a86e3bc711694b0fdb2910e4edc1fc15eda7c306b077cd493bac93a6af3f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:ebac517fad6b7032cd734e0c8cdab783d836afbb4fa3f7513d739a3f1ed3aa0b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:04b7eeb54e153d5e0d13bf3da219380dfb236ca90f505977b6bde6eebd78392a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:2787bf06cf170f820ebf63c191cf8142d9eabf7a22aa0e43fbb228782cf24876_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:bfde04ceca284f2b97b134384d860fbfc1d4938d8ce071dae270703590287554_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:f3d64a782df24f99e1fafbee522e9ef55808abb34818b0475fb49fa86c2b5419_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:047d08cf4f96586d174d4518b095d4310761d481d0382a3defe04f10d781d090_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:7eec0335f27539997176c71a5bce5e2d88bc276bea1fa3796013af5aeb486e83_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:8e7935f4baa65515a3398d6f0d755be68c58dff18b66578edc722b59c5da31ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:a0e1e893cf29241060b05333a2bd2fa01a42f8d9e296ad8fa23a41512945a87f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:07cc880165e6037c41f1254618cafce55c49733377084b1ef1a93e67007bd872_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:64a9e1df0aa78746f9f5e9ab031dee1e3a48f6dc24002e22e2b6d440e1e9ed6a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:74d85e41f1fb8ffb8b25f9529317ba512cbe7080ae87cac4dc253e2f47ea7eca_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:bf9b176844dc71b813c1f2ddbf5ff9135ac9f586415a4cc7399321556c67dcbd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:5efab9a9a9f702e8f03e8fa1db72b5710532db869578b8b6b9444acc5e1057f6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d517885ee59d46c2aca8be69fdcf916f78a510ae76a5a9f7875c1c5ab3cfc3c1 (For s390x architecture) The image digest is sha256:3a4a7c87e8ca5f4e3803f8f203599b25055276a532df8e0b66ec4ec2ebc51f4c (For ppc64le architecture) The image digest is sha256:f34818181660a9f58a59e06dbe58f24de82dcbb688e5f940a41e62e08f1edf94 (For aarch64 architecture) The image digest is sha256:24eeb2ea15ac709ed08df9b6f1a5d1ac334c4f7335c0ae5249e17298ab297517 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:1549
- externalhttps://access.redhat.com/security/cve/CVE-2025-58068
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_1549.json