Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:10365 - Bug Fix Advisory
Issued:
2025-07-07
Updated:
2025-07-07

RHBA-2025:10365 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2025:10136 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2370010 - CVE-2025-4435 cpython: Tarfile extracts filtered members when errorlevel=0
  • BZ - 2370013 - CVE-2024-12718 cpython: python: Bypass extraction filter to modify file metadata outside extraction directory
  • BZ - 2370014 - CVE-2025-4330 cpython: python: Extraction filter bypass for linking outside extraction directory
  • BZ - 2370016 - CVE-2025-4517 python: cpython: Arbitrary writes via tarfile realpath overflow
  • BZ - 2372426 - CVE-2025-4138 cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

CVEs

  • CVE-2024-12718
  • CVE-2025-3576
  • CVE-2025-4138
  • CVE-2025-4330
  • CVE-2025-4435
  • CVE-2025-4517
  • CVE-2025-5702
  • CVE-2025-25724

References

  • https://access.redhat.com/errata/RHSA-2025:10136
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:f1d9a4fdf60b0d83499c02bfff63755b9f3bcdac7a392ad693be744a61d19d66
ubi9/openjdk-17@sha256:6f42bb15d17e7c7bb2f8fc195586e433603a9d4a407f694a66103e625c59a8b5
ubi9/openjdk-17-runtime@sha256:564aedf15a570f211a2eb171071276619cfe0e2b6d4e74e929dae1a6d4037e25
ubi9/openjdk-21@sha256:6449406e817606ebc8c5c9b17265bfda10e428c517a45f34b1236043efc5f354
ubi9/openjdk-21-runtime@sha256:7bde889eb7fee4360eef3289b78eb85c44308909709fcb4fec3bb2b299203c1f

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:1dbc15d2bdb228bf2577fed047877cd164eadc1f02d119dbbe9bbce9db78fbd7
ubi9/openjdk-17@sha256:9fcbe97d45eb12bf2ae4f3217855b0b0516c3180dce9072aaa212569d28f97c1
ubi9/openjdk-17-runtime@sha256:c5ef7fc30980a6537d519c38fba289a6a5bceaf0f6f0fcf9c7a9da0be61c9b51
ubi9/openjdk-21@sha256:d2c54a1f86c9642af6ec4e237aad355e185490d8ce66047213c4927bfcb07fdf
ubi9/openjdk-21-runtime@sha256:38f717f3276db5ebcc5b70fc61dc9eff7f3a0f5004eab14df6a48a1b296ffee1

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:70b5319c2f270293cb23b57641c7d527eac94f2d7315d72e48ae61e60c21b67d
ubi9/openjdk-17@sha256:a15b34dfda43e003726867ecf0e4fa6372376f6ce5079c9271157417fddb1557
ubi9/openjdk-17-runtime@sha256:bd0ab9ce012df9475bd776e0db874ca1532adef84aff1969c05eadb206e8ac86
ubi9/openjdk-21@sha256:ef0f689a3d8347080cccad55cd79ca348fde7d77ed7f408de85eacec7f70404d
ubi9/openjdk-21-runtime@sha256:1f799dcaf4d46ee7815d8f345a261ec7580d83d2a9be5412b595230bc6889a01

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:dd12e4fc09d794cc10d3dc2ea3d7739b0ca07a0007bb0b00f72b7c59bff6bc3d
ubi9/openjdk-17@sha256:c540e4d0e649ca5286d6007d13877f5bfb8477623c3301db178456dbe27c8d13
ubi9/openjdk-17-runtime@sha256:d4315c83651bb5a935fb7ec0a3d68ab9e0b6984d30ed67715753c534f1f5fcb7
ubi9/openjdk-21@sha256:64a78860004ffda1abe243396e4ea4901ffd6dbdd4286d87f2d86a822fbb9d71
ubi9/openjdk-21-runtime@sha256:0ac86aa6da0ae4435aa9efeb64de51b0f561a2609c39531c3cac72176f3684c5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility