Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:4536 - Bug Fix Advisory
Issued:
2024-07-15
Updated:
2024-07-15

RHBA-2024:4536 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

Updated RHEL-8-based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8-based Middleware Containers container images are now available.

Description

The RHEL-8-based Middleware Containers container images have been updated to address security advisory RHSA-2024:4252 (see the References section).

Users of RHEL-8-based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in the Red Hat Container Catalog (see the References section).

Solution

You can download the RHEL-8-based Middleware Containers container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).

Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2268639 - CVE-2024-28182 nghttp2: CONTINUATION frames DoS
  • BZ - 2290318 - CVE-2024-35235 cups: Cupsd Listen arbitrary chmod 0140777

CVEs

  • CVE-2023-2953
  • CVE-2024-28182
  • CVE-2024-35235

References

  • https://access.redhat.com/errata/RHSA-2024:4252
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-11@sha256:f03cb7b80a355543f90dc47d96fa3a9c470fdc2093ab8971343233252a2ee156
ubi8/openjdk-11-runtime@sha256:a7d2e13775f6099cbccaec2f6182feca6268b2ecb8fd96de7c10567cd5e31bbe
ubi8/openjdk-17@sha256:27a28cf9b80daec0ad388ec6401a1876741833a485264d0e46cd020789c642a5
ubi8/openjdk-17-runtime@sha256:9da2bbf90656e3c25cba4ebdc01a65ba84f17664b7d8087d469a87df0d7e8bec
ubi8/openjdk-21@sha256:bda1f864a6e53186d0fc509ce18ea0223df0fe8e125478bacee13f5f8a72e0be
ubi8/openjdk-21-runtime@sha256:4dbf57b5e0e064c522358862090489927f216cebb794e50805ab2adaf8e75731
ubi8/openjdk-8@sha256:a36621dc8c4bbfed2b5bcc3b5b9cee61b65c44769837976c1472ebb146b23201
ubi8/openjdk-8-runtime@sha256:54385d8034355c76db5bd4704d25e00ff6b2d9f96d1bf4e529dda0ac9250eb85

ppc64le

ubi8/openjdk-11@sha256:f841bb1f22fcebdd444055a3891b47c3d062bd79d6440df9071558ce1d0be7d1
ubi8/openjdk-11-runtime@sha256:1b0ee0cd381970753460706603e2dedccd0df4cd11a205e87af03f3078762530
ubi8/openjdk-17@sha256:61d885399fd86b0bc839aaaa24f8eb00a5db7ddecee39c8c0ce9dec60bfac3c6
ubi8/openjdk-17-runtime@sha256:4670e31e924dab4549e6f000a706c033c1655c35ff4ef8557b5ee0b4e7bb5fcb
ubi8/openjdk-21@sha256:b2109020ec8b5a86d967c6ab2325017267936e64b5b08c108b7b47ca411c1d96
ubi8/openjdk-21-runtime@sha256:dd5ea10abedc6ada851c3f17a009e28a74c09ec7a1800b37c39ee05cef3e5ee2
ubi8/openjdk-8@sha256:778a2299c7cc71dd33d5efaceeeb5b38318005c7a4107bbdd9d6f1a8033b9326
ubi8/openjdk-8-runtime@sha256:30e467060011417da4d7b3bee055bcc647e500f2f5ee5232ca2876a4284c22bf

s390x

ubi8/openjdk-11@sha256:51fd632d2b8e6df9194e412c1fbf8991429707258cfd11efb480dbad75e0ac9a
ubi8/openjdk-11-runtime@sha256:5a3968ee4afd1a0b4945a3246837d6eed30e3d468f75c587256c9e7f5220e4c1
ubi8/openjdk-17@sha256:969a8377d7943f9692e47649e36d77e5d62608af380ead34e0bb198da4555d97
ubi8/openjdk-17-runtime@sha256:6c72e6f9a686ca40595dbea5abf98539ea19be4c4c0354258b8b8cafa2455864
ubi8/openjdk-21@sha256:53bfa12fd958829d6719859ad73605e14833fecc7d57c2c92c11ce39dfc37313
ubi8/openjdk-21-runtime@sha256:cfc9a7e703e5422fd158228e4451852395b3d73fe7f7ec2aa31d9f8bc2b40ffc
ubi8/openjdk-8@sha256:0d4bf89bf8000a1896a96f61d523d8c40c735ddbe80c144903f9049a4d52d6c6
ubi8/openjdk-8-runtime@sha256:69931a074ae6c044d059a825a219c8f7aafabe098e9904cd37d91e247c55bfb4

x86_64

ubi8/openjdk-11@sha256:062f4801bc425c05b7e95cac22270a14cf36e05b3aa939debf7e1ca70d11fa16
ubi8/openjdk-11-runtime@sha256:191fe40c499c0e8e8b7ca855e9aa0a830fbf82c7d45503d26d988d246d13b248
ubi8/openjdk-17@sha256:635c67299c602390e24cd4e5e42e695a14b464fd4f38990f0fc0c5398b60497c
ubi8/openjdk-17-runtime@sha256:5d69e5593d909c6f173d54017a51c61a244e47b0b23047a7e594e0dc5f223d6a
ubi8/openjdk-21@sha256:77b57554c4eb6e6827a55ee733ba70f5b52d2086791be556c933cc73270a7385
ubi8/openjdk-21-runtime@sha256:d7dbec8dc1f9651bffac1a62a4ec308fa1d6322cb22b8361b43afacc2beac07d
ubi8/openjdk-8@sha256:71b7519c5d0e9a01d9290cd89fd315df5982eca9dac4ff5c55d5d216905dc71c
ubi8/openjdk-8-runtime@sha256:e1434bfaeff4bd61ca8a869ac1bb5347e94be61a44bb352e6840e9157c64624e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility