Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:21911 - Bug Fix Advisory
Issued:
2025-11-20
Updated:
2025-11-20

RHBA-2025:21911 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2025:21776 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2395108 - CVE-2025-59375 expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing

CVEs

  • CVE-2025-59375

References

  • https://access.redhat.com/errata/RHSA-2025:21776
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-17@sha256:e2b96f89d5bd39785c417f6e5c25f8cb8119f7c971f64ed4a65f55c5932f2a3b
ubi8/openjdk-17-runtime@sha256:efccffa2ead827dda28b81300f29f6141347edc0b587aa946a972deb7c9ea4a5
ubi8/openjdk-21@sha256:7152d143f659ebae0594361b9f23b527487a1b789585422932e86c949bfcec99
ubi8/openjdk-21-runtime@sha256:8616653cb227a87b26fbba4116cd5bd5045d5578ad820ee9cd9ebaf4ad570156
ubi8/openjdk-8@sha256:420b8c427426b66a223d8a88bc64cd40b4d64a615a2fbfa6dd5d46478bf870ca
ubi8/openjdk-8-runtime@sha256:a36a473cfef9ba0c85458241ae68ee6bea7441f6a0423d70bd099d86e75fba9d

ppc64le

ubi8/openjdk-17@sha256:80538e60fb392cda1a999221bc7c01868b4730c640c8b5184f03c9d9874dab5b
ubi8/openjdk-17-runtime@sha256:f2a51238e730b4733a848f40f33f782371220d49c35d0cf6b841c5c4f02d6801
ubi8/openjdk-21@sha256:a5419b297d6a778ef38a71d84e71818d47a9f9272809a0327f0fbe8febbcceab
ubi8/openjdk-21-runtime@sha256:2e51e01ee7851f031b1994ad9b5cbb7ca7620901a1406db98d39687106ac78ca
ubi8/openjdk-8@sha256:115b81fa8b5e9ca4e84d1a5da9264adadee3db1f0e01b4e9ac8e559ca6a13082
ubi8/openjdk-8-runtime@sha256:09b75614a40f3a86718a9a927faf629f46b5a6e8f4b23432adcb719dab9e5fc4

s390x

ubi8/openjdk-17@sha256:8f97aa14c2b4233fc564e7222a520f4b7c30ef7e29d4ae40a89bea9f15eeb189
ubi8/openjdk-17-runtime@sha256:6e4bea209a149adb71f85f3d4b85c8010e444ebc73d9dee9f07b2f736afcf8b9
ubi8/openjdk-21@sha256:b9022e7e7f323d0cdbd44505253b3a58b6f775f39916b8361fcc155d98d4b9e6
ubi8/openjdk-21-runtime@sha256:6669d03e70574f00a0a247177eb6f2dee5b202033f09aa8e734f6812e31dabe2
ubi8/openjdk-8@sha256:12945d9d371d15f79212e1f8a552db5f3ae9d9263edcdd48600e640ac41d4886
ubi8/openjdk-8-runtime@sha256:d98a641304c3f790dbdf83aa3f763aef8ac68fd80309a4d437502ca369a15538

x86_64

ubi8/openjdk-17@sha256:33ec44a9082e78ac901d33abc0330fa8ce5c01c0502156f4d2410506bf0fde70
ubi8/openjdk-17-runtime@sha256:95138ca048aff8e2654a5607fea26f17234bac80ae01c3dc6d0008c807b5d0bc
ubi8/openjdk-21@sha256:18254d1b7c232fce33939dfa5158691b705428599bab0d94d0f08b2242440a8a
ubi8/openjdk-21-runtime@sha256:07bc0ed4d4b8ef3b01f990e17879c7cedc33241c92137286bbad25e584748e71
ubi8/openjdk-8@sha256:4407493c95f24643cff5039a6ba713b688d0b6737bc0fd9e91730a855f51c55a
ubi8/openjdk-8-runtime@sha256:1dbf36bb328fa48735e1226a1c52f99e3e91e6bbfd85356c1501bbf20456246f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility