Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:2922 - Bug Fix Advisory
Issued:
2024-05-20
Updated:
2024-05-20

RHBA-2024:2922 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated Red Hat Enterprise Linux 9 container images

Type/Severity

Bug Fix Advisory

Topic

Updated Red Hat Enterprise Linux 9 container images are now available

Description

The Red Hat Enterprise Linux 9 container images have been updated to address the following security advisory: RHSA-2024:2853 (see References)

Users of Red Hat Enterprise Linux 9 container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The Red Hat Enterprise Linux 9 container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x

Fixes

  • BZ - 2265713 - CVE-2024-25629 c-ares: Out of bounds read in ares__read_line()
  • BZ - 2268639 - CVE-2024-28182 nghttp2: CONTINUATION frames DoS
  • BZ - 2270559 - CVE-2024-22025 nodejs: using the fetch() function to retrieve content from an untrusted URL leads to denial of service
  • BZ - 2272764 - CVE-2024-27983 nodejs: CONTINUATION frames DoS
  • BZ - 2275392 - CVE-2024-27982 nodejs: HTTP Request Smuggling via Content Length Obfuscation

CVEs

  • CVE-2023-6240
  • CVE-2024-25062
  • CVE-2024-25742
  • CVE-2024-25743

References

  • https://access.redhat.com/errata/RHSA-2024:2853
  • https://access.redhat.com/containers

aarch64

rhel9/nodejs-20@sha256:bd336a89ec0920d9c35de9c7161ec168bbc5b92c76267645c4073f59f3262627
ubi9/nodejs-20@sha256:bd336a89ec0920d9c35de9c7161ec168bbc5b92c76267645c4073f59f3262627
ubi9/nodejs-20-minimal@sha256:53dcdf129540ba97971b3d146a4ee4e6e04400c0ea25c591bc936b83c9c0fddd
rhel9/nodejs-20-minimal@sha256:53dcdf129540ba97971b3d146a4ee4e6e04400c0ea25c591bc936b83c9c0fddd
ubi9/perl-532@sha256:36445b9860c1e8319872fce294f606ad14c550a3a2d64150c15cecdccae302da
rhel9/perl-532@sha256:36445b9860c1e8319872fce294f606ad14c550a3a2d64150c15cecdccae302da
rhel9/php-80@sha256:2d0c43737ca5692f3d5ae9639248d15a573c20cb5b0eadbe01118c2235375eff
ubi9/php-80@sha256:2d0c43737ca5692f3d5ae9639248d15a573c20cb5b0eadbe01118c2235375eff
rhel9/php-81@sha256:428c53fb6c9252574d7b77d3cd99d4759913f009a00d55c76d9ea76d0baeabdd
ubi9/php-81@sha256:428c53fb6c9252574d7b77d3cd99d4759913f009a00d55c76d9ea76d0baeabdd
ubi9/php-82@sha256:dd6c5f9967a8c148978abb408056b9fb179141cd4981e41ee2bd34f7ee84117e
rhel9/php-82@sha256:dd6c5f9967a8c148978abb408056b9fb179141cd4981e41ee2bd34f7ee84117e
rhel9/python-311@sha256:3dfd609c674fcabfe0bbe0d049366b2604026bc54de5bba9551200417a962630
ubi9/python-311@sha256:3dfd609c674fcabfe0bbe0d049366b2604026bc54de5bba9551200417a962630
rhel9/python-312@sha256:acd4472c2c8de6b461af7ec0dd7cdfa6ee074d682d80ae4bea0d0f44b590b140
ubi9/python-312@sha256:acd4472c2c8de6b461af7ec0dd7cdfa6ee074d682d80ae4bea0d0f44b590b140
ubi9/python-39@sha256:aed71e4ebbf6c2c533a5bf9cd9be35aff8bc40814fe7b590c630f8b46b052a30
rhel9/python-39@sha256:aed71e4ebbf6c2c533a5bf9cd9be35aff8bc40814fe7b590c630f8b46b052a30
ubi9/ruby-30@sha256:f183c41d6c2f1d0d3fe0ea922492ab2f7bca91dc1e5c7c017607f2acc69b0cd2
rhel9/ruby-30@sha256:f183c41d6c2f1d0d3fe0ea922492ab2f7bca91dc1e5c7c017607f2acc69b0cd2
ubi9/ruby-31@sha256:6ae3188f8cac87c69f849c47164d02bac7f3753bbd76b25c1168336f1ca32d5f
rhel9/ruby-31@sha256:6ae3188f8cac87c69f849c47164d02bac7f3753bbd76b25c1168336f1ca32d5f
ubi9/ruby-33@sha256:9ac273109cbe58a728a4628492bab0c685df66123ad3bcdf9ed048240dc990a5
rhel9/ruby-33@sha256:9ac273109cbe58a728a4628492bab0c685df66123ad3bcdf9ed048240dc990a5

ppc64le

rhel9/nodejs-20@sha256:875154d8fe6017ae21834dd32b36e628adc64290c303bb6c8263f1bd9fd875fc
ubi9/nodejs-20@sha256:875154d8fe6017ae21834dd32b36e628adc64290c303bb6c8263f1bd9fd875fc
ubi9/nodejs-20-minimal@sha256:80adeebdb76fa86415da4cbd185c7c62df5805b333d2352a784db557f6f431e0
rhel9/nodejs-20-minimal@sha256:80adeebdb76fa86415da4cbd185c7c62df5805b333d2352a784db557f6f431e0
ubi9/perl-532@sha256:3292df911dadb6b533358155e09bd69334e0c7c834216477fd5526d098c0af8c
rhel9/perl-532@sha256:3292df911dadb6b533358155e09bd69334e0c7c834216477fd5526d098c0af8c
rhel9/php-80@sha256:09117bfe55ae59184f4d02783f7d08491d417531892d3da30f624959a6c3fef2
ubi9/php-80@sha256:09117bfe55ae59184f4d02783f7d08491d417531892d3da30f624959a6c3fef2
rhel9/php-81@sha256:237eaa0ea0c638ae37b9f0758c71f289ae61d308f3eb14874cf7c0c4fb7672dc
ubi9/php-81@sha256:237eaa0ea0c638ae37b9f0758c71f289ae61d308f3eb14874cf7c0c4fb7672dc
ubi9/php-82@sha256:a88cb2f29db6019a1fc88ba0030bc7bedf3b0d17107f08035f92272f2070b142
rhel9/php-82@sha256:a88cb2f29db6019a1fc88ba0030bc7bedf3b0d17107f08035f92272f2070b142
rhel9/python-311@sha256:bab7ab02b216b50cf11835fb26b11a35297471a29bc7bbcd439f308db89e9230
ubi9/python-311@sha256:bab7ab02b216b50cf11835fb26b11a35297471a29bc7bbcd439f308db89e9230
rhel9/python-312@sha256:e5469b9bb1225db11b0332b64d0a621ee8948a8069154a7170ad30d78d42241a
ubi9/python-312@sha256:e5469b9bb1225db11b0332b64d0a621ee8948a8069154a7170ad30d78d42241a
ubi9/python-39@sha256:290eddf26ea5b7043b684fa2584ca847b4e87fed5da546f414a1db0d81655ebd
rhel9/python-39@sha256:290eddf26ea5b7043b684fa2584ca847b4e87fed5da546f414a1db0d81655ebd
ubi9/ruby-30@sha256:49740ca1582af25013d361a1a5a0ff2c25e33aa7068089e7cbe36a779bc52ffa
rhel9/ruby-30@sha256:49740ca1582af25013d361a1a5a0ff2c25e33aa7068089e7cbe36a779bc52ffa
ubi9/ruby-31@sha256:b72f4239057767fb6e3938a93569bc3212bbcc4a080e2075434fd6d1322d1c91
rhel9/ruby-31@sha256:b72f4239057767fb6e3938a93569bc3212bbcc4a080e2075434fd6d1322d1c91
ubi9/ruby-33@sha256:148bf08b7f164b79437885cc59af22275a1070e559c8a9313adbe6213a3ddba7
rhel9/ruby-33@sha256:148bf08b7f164b79437885cc59af22275a1070e559c8a9313adbe6213a3ddba7

s390x

rhel9/nodejs-20@sha256:d26ff1a9600c5fd2a3418c7af8b8c4a961d3109b6e16789cfbeb17b9aa70fd04
ubi9/nodejs-20@sha256:d26ff1a9600c5fd2a3418c7af8b8c4a961d3109b6e16789cfbeb17b9aa70fd04
ubi9/nodejs-20-minimal@sha256:04ba75ba261953bc1a07b54a1a62d3b4e5f91f22f23e08ff80fbea0f1d0b442e
rhel9/nodejs-20-minimal@sha256:04ba75ba261953bc1a07b54a1a62d3b4e5f91f22f23e08ff80fbea0f1d0b442e
ubi9/perl-532@sha256:9533609bed4a383f1619f031dcada20c5eb81fe8dfc0ef6929da00b17c44465b
rhel9/perl-532@sha256:9533609bed4a383f1619f031dcada20c5eb81fe8dfc0ef6929da00b17c44465b
rhel9/php-80@sha256:c2543cef8ce8087ba428be7f489787dc2b7fb9e3ab1a46879e144459a235af27
ubi9/php-80@sha256:c2543cef8ce8087ba428be7f489787dc2b7fb9e3ab1a46879e144459a235af27
rhel9/php-81@sha256:ede2c7f45e3095afca07a7cf47724778da613eb0cb50bd8a83dea976c86634ed
ubi9/php-81@sha256:ede2c7f45e3095afca07a7cf47724778da613eb0cb50bd8a83dea976c86634ed
ubi9/php-82@sha256:0fffff5135e53340b0984b4f077c57e8ffc23d6362e9eace16d9f0af271bc628
rhel9/php-82@sha256:0fffff5135e53340b0984b4f077c57e8ffc23d6362e9eace16d9f0af271bc628
rhel9/python-311@sha256:644d64d90f7e10a2528641bae6100941d28970763ebc47fdcc5cf918c0b88d65
ubi9/python-311@sha256:644d64d90f7e10a2528641bae6100941d28970763ebc47fdcc5cf918c0b88d65
rhel9/python-312@sha256:e9a8331876e4711cc51e7f1f4ee8433b6a9f0752140830d84307feaa18a811d2
ubi9/python-312@sha256:e9a8331876e4711cc51e7f1f4ee8433b6a9f0752140830d84307feaa18a811d2
ubi9/python-39@sha256:7a6f375459f5847827ac046e01d597654698f4c8a4982710ef7635c6c28652f2
rhel9/python-39@sha256:7a6f375459f5847827ac046e01d597654698f4c8a4982710ef7635c6c28652f2
ubi9/ruby-30@sha256:f53a7053f5a46fea001aae5a9cca8243ef2059166927f756cdfc4ee446391674
rhel9/ruby-30@sha256:f53a7053f5a46fea001aae5a9cca8243ef2059166927f756cdfc4ee446391674
ubi9/ruby-31@sha256:114498b844f9b92b02b28483706e502ce306eed91f5b260a7174b5486c34a66f
rhel9/ruby-31@sha256:114498b844f9b92b02b28483706e502ce306eed91f5b260a7174b5486c34a66f
ubi9/ruby-33@sha256:151385cd0b319f5c4eb761afc7774c71f89472113c051b4275c8ee7a03369778
rhel9/ruby-33@sha256:151385cd0b319f5c4eb761afc7774c71f89472113c051b4275c8ee7a03369778

x86_64

rhel9/nodejs-20@sha256:0a9da50447511bb74fadcf9e9113fff93abca0b7719c03312dcad71d006465f0
ubi9/nodejs-20@sha256:0a9da50447511bb74fadcf9e9113fff93abca0b7719c03312dcad71d006465f0
ubi9/nodejs-20-minimal@sha256:2bfa0326250532ba9808fd8ebae43e2ce779450ff24fe18cae470a0ebdfc11ba
rhel9/nodejs-20-minimal@sha256:2bfa0326250532ba9808fd8ebae43e2ce779450ff24fe18cae470a0ebdfc11ba
ubi9/perl-532@sha256:9d9a05236b4428fa94e1ee55cf80ffaacb3443f13cafa175dac79fd1585cd411
rhel9/perl-532@sha256:9d9a05236b4428fa94e1ee55cf80ffaacb3443f13cafa175dac79fd1585cd411
rhel9/php-80@sha256:997c0dc70ffa4b1bf218e90a1b632309dc21b10961551885b0533cf7e3cc5882
ubi9/php-80@sha256:997c0dc70ffa4b1bf218e90a1b632309dc21b10961551885b0533cf7e3cc5882
rhel9/php-81@sha256:cfaafbdc4c797493a9e0f07eb33c4398eaf44c877356cd4811cf3e7373834e83
ubi9/php-81@sha256:cfaafbdc4c797493a9e0f07eb33c4398eaf44c877356cd4811cf3e7373834e83
ubi9/php-82@sha256:9a79c692d63c20d88a6a0beaa279a438f29091f488618be7df3d594f9508696c
rhel9/php-82@sha256:9a79c692d63c20d88a6a0beaa279a438f29091f488618be7df3d594f9508696c
rhel9/python-311@sha256:c2ff882193a5f4dd518f8174ce9791b08a8217f8664c7d5ccc81d012810a328e
ubi9/python-311@sha256:c2ff882193a5f4dd518f8174ce9791b08a8217f8664c7d5ccc81d012810a328e
rhel9/python-312@sha256:ef3ce743200063c1dcec45e0e58faa166cdfbd36601f84158f5c4c466b85e784
ubi9/python-312@sha256:ef3ce743200063c1dcec45e0e58faa166cdfbd36601f84158f5c4c466b85e784
ubi9/python-39@sha256:e61bb4dfe280e50418d8a6150be222b929588fa61b1f4f17fa2e99b27b40bb34
rhel9/python-39@sha256:e61bb4dfe280e50418d8a6150be222b929588fa61b1f4f17fa2e99b27b40bb34
ubi9/ruby-30@sha256:6bb4e144db5e2d12ad4204f2261b2c9cab99aea0f610cab57285546600dcbcc2
rhel9/ruby-30@sha256:6bb4e144db5e2d12ad4204f2261b2c9cab99aea0f610cab57285546600dcbcc2
ubi9/ruby-31@sha256:ba30ad1d3fdb4b0904610fbc9c48038a2767dc1eb2edd26ceb907ad6397d86c9
rhel9/ruby-31@sha256:ba30ad1d3fdb4b0904610fbc9c48038a2767dc1eb2edd26ceb907ad6397d86c9
ubi9/ruby-33@sha256:85b05ef94871b6f1825ef19433a4a6cf4cc4c60bcfe6155059de4e2e1cb3c545
rhel9/ruby-33@sha256:85b05ef94871b6f1825ef19433a4a6cf4cc4c60bcfe6155059de4e2e1cb3c545

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility