Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:5472 - Bug Fix Advisory
Issued:
2024-08-15
Updated:
2024-08-15

RHBA-2024:5472 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2024:5312 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2294676 - CVE-2024-37371 krb5: GSS message token handling
  • BZ - 2294677 - CVE-2024-37370 krb5: GSS message token handling

CVEs

  • CVE-2024-37370
  • CVE-2024-37371

References

  • https://access.redhat.com/errata/RHSA-2024:5312
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-11@sha256:988fa6e0f9f93443e9693c235bbd3e01d5fbcade5956c2e6143ac2a92c4c36ef
ubi8/openjdk-11-runtime@sha256:8f564a0e34d998df3eb4dab010f7851bb448ea1ece53de2538519d0877d90781
ubi8/openjdk-17@sha256:d64f106eaf809c91f4be144924564ae45113197342d6ff6866ce34f37a73b74a
ubi8/openjdk-17-runtime@sha256:d4121b36e62d54b15f1578a352097df02e4658af52bdeb7b779498b8d101a327
ubi8/openjdk-21@sha256:40cfc4ee12151476df64820611f766e3e5a8ed4b20ba30e7962a69470c0cbc6f
ubi8/openjdk-21-runtime@sha256:15838feb845ec36added702fda42b82ef0cd7eba271da66c4373a59774c60943
ubi8/openjdk-8@sha256:d65af1a8f3836015d5b09c976665a270f78f41408f08aa35d29043ffcfe89113
ubi8/openjdk-8-runtime@sha256:2d42b4848522eee32d191730cc2edaf01f0c6cc4636247717a7140e38e399bb8

ppc64le

ubi8/openjdk-11@sha256:435846e0ef8a3ef2dfe8021bef79e77f927181e848c4ff03a8a2d1e8874f35f4
ubi8/openjdk-11-runtime@sha256:20dfe35dab3425585c1d1d28c98009673b34b59825c3b996d115be0e79a98b65
ubi8/openjdk-17@sha256:027f3e149abcd8c09fbf7186cdc61828301e4731cf0354c12de8d481acd6f9fe
ubi8/openjdk-17-runtime@sha256:c867fc28b99ab8ed5d73d33483c93f5dd15ee1fdd636e39088f8dfd82d4730bc
ubi8/openjdk-21@sha256:dceb3a4bb2ac38527de482a5b23fa2d4ea3c02f1f959d1209641a2d3131e1a25
ubi8/openjdk-21-runtime@sha256:117030e5eb5d37d4e2e84acd493ca6bb4aa6fccd82d49333993c38d14bca52d2
ubi8/openjdk-8@sha256:2b120ba7f8bbc0a5b57f9a1d411b6dc278fd30afcb697bf93eda8b4a6b39529b
ubi8/openjdk-8-runtime@sha256:92883a5b011f768496d42d1d0a0e2b94e9f4dba930bf8e470966cd5444ee7da9

s390x

ubi8/openjdk-11@sha256:9900ca6c47f22eda0e2e733a788486690bb119cc51460a0df2aff0dd3eb660ac
ubi8/openjdk-11-runtime@sha256:ad90d382b595f08c2aba87d03bec2979168c42d28ed475dbf243ee9158b63c44
ubi8/openjdk-17@sha256:81e09b730b7b66db4aeeeaec41c1679621e0d7cf337b56ae9d766c692e5e0e73
ubi8/openjdk-17-runtime@sha256:f3c7a7f25d9cbc0be123281d3392425aa65870e62e0559eb080cbbe6d6a22b8f
ubi8/openjdk-21@sha256:837c0bd94a153fbaa3cedb285e6653975ce458f5e3f4d8af9dbe033055f0074a
ubi8/openjdk-21-runtime@sha256:4be3bf5a1cd4953eb10d674494383414ed21bec00bae28933de6bd769027eabc
ubi8/openjdk-8@sha256:1d95d2458cd225cb516c610995eb749fade46c8b7f98510071338da325b5d2c5
ubi8/openjdk-8-runtime@sha256:6d8cfaa588853fc31aa231bf9b1720630d185060f6b215664d785af6211a13ef

x86_64

ubi8/openjdk-11@sha256:9ae75a97fe1f02d22040fc9f0b154aaf2172447c29a883a85fec27b206f48a0c
ubi8/openjdk-11-runtime@sha256:65d66079338d42133d658a708caa543684f970d660cdfaf7a250010dc78c7473
ubi8/openjdk-17@sha256:658ab5ea36b75bab59fa14e2ed2bc7461e9a2d296a9f781eb9dd9a18117a829d
ubi8/openjdk-17-runtime@sha256:0c7f7f74765c475e8a5746f40a7f8c3dd13e288c0649f99196f8b85d7272489b
ubi8/openjdk-21@sha256:98e4de1d10a114559321e8934899db531d4053b11bda8de249a2a1af6ab143e6
ubi8/openjdk-21-runtime@sha256:53376fb4bfb754275e7fcb7237c9cb603e699dd85e59c06900305a685f369525
ubi8/openjdk-8@sha256:76e6b89e7723a93d204fc4a9decb966df9183c1cb9efc740e05dfdba00b47016
ubi8/openjdk-8-runtime@sha256:be7c48c934c064a59f57b0ba58b625f0f35e258da044e39d6333d6908fe4196b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility