Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:3598 - Bug Fix Advisory
Issued:
2025-04-03
Updated:
2025-04-03

RHBA-2025:3598 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2025:3531 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2310137 - CVE-2024-8176 libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat

CVEs

  • CVE-2024-8176

References

  • https://access.redhat.com/errata/RHSA-2025:3531
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:9c4216fc3b420122a4a56d13377c9f975a16e2ac09a7c3932597292378e02edb
ubi9/openjdk-17@sha256:33f22cae1a37a9d536eac73229ef203faf9dbd7be4f2cb99c6c27c031e56171d
ubi9/openjdk-17-runtime@sha256:ff56b6b795b9c76c1d0097da6a315cff138b1b3c50248bc61efbe6ac7dbd2915
ubi9/openjdk-21@sha256:f425b78f8f9e000796ac11cc6b250762f2fa92062ce46c87b7d9da165ca27633
ubi9/openjdk-21-runtime@sha256:77348501dc7d9447313ed4dec83d791c61f2a4cce52ed50f3f17759fa98d8ae4

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:65e0596e316d3e363630f056edebd455f457e999d253761992a00b9ab940d400
ubi9/openjdk-17@sha256:51c1e018f4d162e252a4b824b9690df28c98a90679d47ba7cae42e89b8e11e0f
ubi9/openjdk-17-runtime@sha256:5934f89c5157630d60e4b22f25f739691d71e6386823b32d813020858ba45d8f
ubi9/openjdk-21@sha256:017840fb6db595ddd49b928229aca6579948f69343439308975f521ae8ae4fc3
ubi9/openjdk-21-runtime@sha256:3eb81da4f5ca9be0e0d484ec599941bebea08558e0b18b4f9ef1ea1968f868e8

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:2ace7a310673aaaa61712e1f3005f0752ec7a534911b07ded90983e8b9d4471c
ubi9/openjdk-17@sha256:1400e56ccc87dd293185920790814c3c580763bcf3404328ff55464535ff481c
ubi9/openjdk-17-runtime@sha256:f25fd95b9247e56e782add8c68758947b51639e86811b5d858c29317b2a4be3d
ubi9/openjdk-21@sha256:272bbb45804fc2cfc7fefa458177ddf3b278f91ecf402e023e714e380d6cd883
ubi9/openjdk-21-runtime@sha256:a659f5b86d49a15ed83f6dbc65fe160a7303b9975709dd4a2ccd8a80ce77dedd

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:4258a1e1f427dd3784396809d9bbc572fccd729b57c71b3bb29c0add7ec4b855
ubi9/openjdk-17@sha256:d72c1b762f021b436fee50afd13c56fe5e4e11c42aa067144980c9acf40b7287
ubi9/openjdk-17-runtime@sha256:8d26265ccb9afe8c4d985e3698f255125056f65951089e694243211fa1f39d02
ubi9/openjdk-21@sha256:c81f671e740d88f67162a881afe3e7b7b7667cc1f93ee8eea743af7df1b41b9f
ubi9/openjdk-21-runtime@sha256:eadd0ae343f22c3cd84dc936bd1039a964381a4edd42336e16ff21470ac797c0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility