Red Hat Security Advisory: OpenShift Container Platform 4.21.1 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-55198 — helm.sh/helm/v3: Helm YAML Parsing Panic Vulnerability CVE-2025-55199 — helm.sh/helm/v3: Helm Chart JSON Schema Denial of Service CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:021a57a7ea58117b5942b474f8899924fe7ff170b234aaa301f86ff465726ce7_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:37283f08df56189fd19f7052523f5eda5a5eba0096c32fc3926eda3bc9398a8c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:459032d57026d4dbb2af370f796c28a69e2e30389a84cdab0e43de4435d980a2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:82ebaab991c00d42430890eed6322e9d060c3b4581ad563383a7d13172de4c08_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:244a4dfcd32e2a6bed90fd5e452b63822af9eb60375b9ac45c1864c2fccaf765_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4eda87164b71e7c6fd8b5a39ea77bb1bbf138f43d5732c08e314369b18e2509b_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d2d6b9b7d7cb72703bda76e6814e5714b101faa03b14f55507b82dddce6fa09a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f5f2d566546e640f59746e3616b98dab55eacdd33ea04b7cff887da6cafbe380_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:21cd6ff9f8ff53d747746f2d772344a8a9be9bd4582d641a0d6814da81e42dc7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c16a9db40d92bd605eb9843f2fb30f793e9f807e924a98f58bdfe9e8ff5598fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f7eaa545a5719eea518c0d48a5010a9e729ca7657f95712b86bd091c6906ed9d_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fbad6ec51decaf69511274952af912054493d07f8de4aeb044b0728e015e331b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4b6ce9a91e0408d0869e2d64ccfba93b8b0587c8c4514c024093e47d520b7b13_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5bab5f51374c260e261af4d094d6d834011bb00d20269e5f87c670ab2e5fc50f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b046acdbaee02a88bc76e80217864aa8a933b4c624abf504bf40b3b5700a3ddf_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:da7ec98aeffdf151279fbfd2d45163722323094e790ab1e5b14e3a75bebf7ba2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1320fee14f620ff211195e536a81bf80c41140d10d8493dca37f484b4803e1a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:69849de1ca4d23c9faf12777ff7f26deb7eaf3026725512e29e7cfbfcb5e30dd_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7ae48499c990a9bb0ccfd436de6e4586ba27e9fd4036b4efe76299aafc4520e0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bdb7981f8aadb7c27bdc448ce4baed28ddd8d08ae1a83af66255bc70d3b87d63_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:06477b1ed6e12b1088fa198f1158cedd852d51773f75622a652220d147aad66d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:73cd8858eb6e706064aa3fb5b397696ad2a8d264ed9380ceeb8d8d89afa96914_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:95a5dd3ee93857d9e65d57257e2864774e0f1aa15d14c62765dd110807a7e983_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:bf017210bb8bfbefa027c830656e83b3db86e940e5ef1f62e67fdc84545cd118_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:04441c2a5c244d0a76052a2e071d994d81415da2cbf49cdd74d3b64fae89fea4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:50caa5c63088b2cd98d85bf793eed760beae31c73d8cccc60f3c82f7e4a436f2_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5d302fd1e0d562fd3074aea7fda53b46878dd5c27f53b4086f43e0b60c69cd92_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c1ec441285a07891350ef5b92dfe8cdef23f963d39ee86b7c2eaa0f29deced63_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:29924ddf95c884e61e24bc38d457d4bb997c5a03789459ef7565f2350c778e44_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7ca8870aa5e505f969aa26161594a3f99b65baf7d29bab8adaca0cade51b0bb6 (For s390x architecture) The image digest is sha256:b33dc753fbb59cc939496922a7f65b3eaf145214f5635c9824790a5bc7a0b5a2 (For ppc64le architecture) The image digest is sha256:46bd467d5cee3e80019ef25c8af7460dfee7e5ae376dd640b76251666eafc98a (For aarch64 architecture) The image digest is sha256:6d018f320d0ba0496fe3410470c2ea3c58e9d77a95fe0f64f3120bc1115f9bf1 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this flaw, ensure YAML files are formatted as Helm expects prior to processing them with Helm. Workaround: To mitigate this flaw, ensure all Helm charts do not have any reference of $ref pointing to /dev/zero. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:2129
- externalhttps://access.redhat.com/security/cve/CVE-2025-15284
- externalhttps://access.redhat.com/security/cve/CVE-2025-55198
- externalhttps://access.redhat.com/security/cve/CVE-2025-55199
- externalhttps://access.redhat.com/security/cve/CVE-2025-58068
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2129.json