Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:23753 - Bug Fix Advisory
Issued:
2025-12-22
Updated:
2025-12-22

RHBA-2025:23753 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2025:23383 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2394750 - CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path

CVEs

  • CVE-2025-9086

References

  • https://access.redhat.com/errata/RHSA-2025:23383
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-17@sha256:1bb007ce84a95f4df9c9b402b1f976c73de92dde819ba47cd629952c051ebb1e
ubi8/openjdk-17-runtime@sha256:6987a582cb3d7ae8424ee8197f3c700e0179f4b8d8012972460d362fe83ad8ec
ubi8/openjdk-21@sha256:181a8eb63016886b573be6c6f4ddaed67bbd357e9afe59c679768c72de4c9e32
ubi8/openjdk-21-runtime@sha256:7d60a642c334526e3fbfece8979eeb5eaf7e8bbc22eefe7b389b2af2d04613d2
ubi8/openjdk-8@sha256:7be19f503d6154f6d743dd30ddd29b29d64f192c202d8cb2fd8ae6f5710a31df
ubi8/openjdk-8-runtime@sha256:e286d8422d4a670f6a9037f34553cf03563e687dde874c5aff495c7e337d1dd5

ppc64le

ubi8/openjdk-17@sha256:49ca7a50501ba0ff5349b431222cdac7d8b987c2ed849e5635ee74303cc5f727
ubi8/openjdk-17-runtime@sha256:cb55ec1424cdb8f0e0e0f550bc9055a9963e08a048d0f9ae67bf6353191066b4
ubi8/openjdk-21@sha256:6d1885996fcb874c6335d9f01201a8af73147c1cfedb0423d6fb5e3fb5eb2d95
ubi8/openjdk-21-runtime@sha256:bd014c1dc07e092388aeef1ff72b6b87259f06e240ee611e4fe410b910a2f974
ubi8/openjdk-8@sha256:ca2d1621e3aeba739463b8e43ad8d65c0414d116bad6e5cbf7b0e8b1d82e82c5
ubi8/openjdk-8-runtime@sha256:f295997d0ec948fbb8ee7973eb959e80c12493c3491fdd585a146134e02695d3

s390x

ubi8/openjdk-17@sha256:7f6e68257b08444787a2f83323af5ac0de1004c50fb8811f67da0ccdf2c9caa6
ubi8/openjdk-17-runtime@sha256:8db4c6559f5cc047843d9880eb97ce9f0b8d8a017a97772d4d8976c58567534d
ubi8/openjdk-21@sha256:c61744a555103dc6e637d00e1e77a55dd5564f427cf6919ddeb2bd18e3c53154
ubi8/openjdk-21-runtime@sha256:0d667f287166d886e04880d91befe9c3b41232a119ba1e29540bb35a3e6db955
ubi8/openjdk-8@sha256:bf0b2a2abb049ed86652aa00fbe58a072eeba416840bf99d07ef3c1c7ca2d583
ubi8/openjdk-8-runtime@sha256:76fc09f9cd5ec8165ab573c7b9104f47958b3206ac22234e83207c7219a51985

x86_64

ubi8/openjdk-17@sha256:11f73b4a15a9bfb3a6cc9df9ce877595abfbef0f044782fb70b9c554923d8560
ubi8/openjdk-17-runtime@sha256:7d7e45ef5499d7acf57ff1bcb184e6456b066482b5f8a871ac414d98c3911c93
ubi8/openjdk-21@sha256:edeea2ab859623c0cff6e6969d473278ad550e06a3ab17a7660c7df6ab59b0fe
ubi8/openjdk-21-runtime@sha256:62b681997945efa7ca951f8925ce1ee8b1b2646dd13dabb4847405cb0a8cd6b7
ubi8/openjdk-8@sha256:e025f73839be9605138fb29a2e0649bfe3c9423461d7278e0f1b57cff7600b4d
ubi8/openjdk-8-runtime@sha256:bedc4247d4c0bee97b89ddaea980a0eb1216d2bb56103ee17f1765a61ce642e3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility