Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2021:1562 - Security Advisory
Issued:
2021-05-24
Updated:
2021-05-24

RHSA-2021:1562 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: OpenShift Container Platform 4.7.12 packages and security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat OpenShift Container Platform release 4.7.12 is now available with
updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container
Platform 4.7.12. See the following advisory for the container images for
this release:

https://access.redhat.com/errata/RHSA-2021:1561

Security Fix(es):

  • runc: vulnerable to symlink exchange attack (CVE-2021-30465)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.7 users are advised to upgrade to these
updated packages and images when they are available in the appropriate release
channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster-between-minor.html#understanding-upgrade-channels_updating-cluster-between-minor

Solution

For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-release-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.7 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.7 for RHEL 7 x86_64
  • Red Hat OpenShift Container Platform for Power 4.7 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.7 for RHEL 8 s390x

Fixes

  • BZ - 1954736 - CVE-2021-30465 runc: vulnerable to symlink exchange attack
  • BZ - 1961052 - Placeholder bug for OCP 4.7.0 rpm release

CVEs

  • CVE-2021-30465

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2021-004
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 4.7 for RHEL 8

SRPM
jenkins-2.277.3.1620985335-1.el8.src.rpm SHA-256: 671ebc450d25bf829b994196d8b1138d076efa13db0d085b34dcbaf393dce9da
openshift-4.7.0-202105160013.p0.git.df9c838.el8.src.rpm SHA-256: 20f84164adc377e41d69bcbefb288ada4a8247d8f61d5128540ef25cb6f2157a
openshift-kuryr-4.7.0-202105140104.p0.git.8b61936.el8.src.rpm SHA-256: cf4d4ee4ff2f7f814c33ece3032e2c739a204c91bf45d49f1d16f28f6101d8f5
runc-1.0.0-96.rhaos4.8.gitcd80260.el8.src.rpm SHA-256: 4a3d05822e509c239638cc1f53fdee7afb41e9922ab957a5729249a7eeb35295
x86_64
jenkins-2.277.3.1620985335-1.el8.noarch.rpm SHA-256: dca58dbc44880045362019a4d631f734dbc3e1f148ef41f974978518d3c10f8c
openshift-hyperkube-4.7.0-202105160013.p0.git.df9c838.el8.x86_64.rpm SHA-256: 69f35b3c7a838045e2a5c83d2708b1ce930d32aa86757f2826681852465095f8
openshift-kuryr-cni-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: d8f406387af61908af2e851b171ec13faa785152523c1eda72b0f38614325b82
openshift-kuryr-common-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: f75a90d809f64407ccf597365f9bddaf87275417a3b96cd255e1863374e61523
openshift-kuryr-controller-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: 5f88e372b2a82b2eb9056aa3b06be1a666530ae9ca0c5657f6abe87a756e3d0e
python3-kuryr-kubernetes-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: 124d38ce4b8a6f28a0ddac9b426fa8426272f85a344b3e5308ffa905d646cc1a
runc-1.0.0-96.rhaos4.8.gitcd80260.el8.x86_64.rpm SHA-256: 1ca4c4c87fc056d3fa924b3f7a10d3a4ab9725de46d8d0bfd2a6058e04ca1177
runc-debuginfo-1.0.0-96.rhaos4.8.gitcd80260.el8.x86_64.rpm SHA-256: 35830f0883b9f8dc94661c0e8959db192c3882019ab648c31761a8b20ca5b56d
runc-debugsource-1.0.0-96.rhaos4.8.gitcd80260.el8.x86_64.rpm SHA-256: 273b3b490bbea3bff5b62f3ec528067dc6ca8684117c04141032ab05ce7baae7

Red Hat OpenShift Container Platform 4.7 for RHEL 7

SRPM
openshift-4.7.0-202105160013.p0.git.df9c838.el7.src.rpm SHA-256: 40a20eec4683246c9b7467ddb6b4317c637730936ef12cc641d7f6dd5cc81c56
runc-1.0.0-96.rhaos4.8.gitcd80260.el7.src.rpm SHA-256: a90ef5f41f4da332010fb9f15f08492644870a9e5cd9cf914a113f110c81b664
x86_64
openshift-hyperkube-4.7.0-202105160013.p0.git.df9c838.el7.x86_64.rpm SHA-256: 6b573109fe28be4114d670df0f4e973306ddfa0ce645e18f9a9cf366f29dd317
runc-1.0.0-96.rhaos4.8.gitcd80260.el7.x86_64.rpm SHA-256: 6112dfeb065f9668949676ee7c548830539fb5e6ba5fe29ccd7b24d754603de5
runc-debuginfo-1.0.0-96.rhaos4.8.gitcd80260.el7.x86_64.rpm SHA-256: e8523f93a31d44829ef8fa6b2b8ca63112d71358d1d947538dc0d13ecca1d8fb

Red Hat OpenShift Container Platform for Power 4.7 for RHEL 8

SRPM
jenkins-2.277.3.1620985335-1.el8.src.rpm SHA-256: 671ebc450d25bf829b994196d8b1138d076efa13db0d085b34dcbaf393dce9da
openshift-4.7.0-202105160013.p0.git.df9c838.el8.src.rpm SHA-256: 20f84164adc377e41d69bcbefb288ada4a8247d8f61d5128540ef25cb6f2157a
openshift-kuryr-4.7.0-202105140104.p0.git.8b61936.el8.src.rpm SHA-256: cf4d4ee4ff2f7f814c33ece3032e2c739a204c91bf45d49f1d16f28f6101d8f5
runc-1.0.0-96.rhaos4.8.gitcd80260.el8.src.rpm SHA-256: 4a3d05822e509c239638cc1f53fdee7afb41e9922ab957a5729249a7eeb35295
ppc64le
jenkins-2.277.3.1620985335-1.el8.noarch.rpm SHA-256: dca58dbc44880045362019a4d631f734dbc3e1f148ef41f974978518d3c10f8c
openshift-hyperkube-4.7.0-202105160013.p0.git.df9c838.el8.ppc64le.rpm SHA-256: f9d4401c54b4a157b2b4f63815b2452c957dea218029c8f015f5f8589ca7a427
openshift-kuryr-cni-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: d8f406387af61908af2e851b171ec13faa785152523c1eda72b0f38614325b82
openshift-kuryr-common-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: f75a90d809f64407ccf597365f9bddaf87275417a3b96cd255e1863374e61523
openshift-kuryr-controller-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: 5f88e372b2a82b2eb9056aa3b06be1a666530ae9ca0c5657f6abe87a756e3d0e
python3-kuryr-kubernetes-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: 124d38ce4b8a6f28a0ddac9b426fa8426272f85a344b3e5308ffa905d646cc1a
runc-1.0.0-96.rhaos4.8.gitcd80260.el8.ppc64le.rpm SHA-256: 833a162b152b59bd70c19605e3bb4e637c24a7423df9ec75d57fd8f97830593f
runc-debuginfo-1.0.0-96.rhaos4.8.gitcd80260.el8.ppc64le.rpm SHA-256: bb8a260e6224b177114a668f630f1305295c642039639decf1970e2f75227f88
runc-debugsource-1.0.0-96.rhaos4.8.gitcd80260.el8.ppc64le.rpm SHA-256: f516c490259d64721f14a05f6c569693f93654245d146345fcf0081ecd4de8b1

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.7 for RHEL 8

SRPM
jenkins-2.277.3.1620985335-1.el8.src.rpm SHA-256: 671ebc450d25bf829b994196d8b1138d076efa13db0d085b34dcbaf393dce9da
openshift-4.7.0-202105160013.p0.git.df9c838.el8.src.rpm SHA-256: 20f84164adc377e41d69bcbefb288ada4a8247d8f61d5128540ef25cb6f2157a
openshift-kuryr-4.7.0-202105140104.p0.git.8b61936.el8.src.rpm SHA-256: cf4d4ee4ff2f7f814c33ece3032e2c739a204c91bf45d49f1d16f28f6101d8f5
runc-1.0.0-96.rhaos4.8.gitcd80260.el8.src.rpm SHA-256: 4a3d05822e509c239638cc1f53fdee7afb41e9922ab957a5729249a7eeb35295
s390x
jenkins-2.277.3.1620985335-1.el8.noarch.rpm SHA-256: dca58dbc44880045362019a4d631f734dbc3e1f148ef41f974978518d3c10f8c
openshift-hyperkube-4.7.0-202105160013.p0.git.df9c838.el8.s390x.rpm SHA-256: 55affda4b61b3d7e552db9a8015ba3f684d11b25ab7f7452a0b9f6cfb4847224
openshift-kuryr-cni-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: d8f406387af61908af2e851b171ec13faa785152523c1eda72b0f38614325b82
openshift-kuryr-common-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: f75a90d809f64407ccf597365f9bddaf87275417a3b96cd255e1863374e61523
openshift-kuryr-controller-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: 5f88e372b2a82b2eb9056aa3b06be1a666530ae9ca0c5657f6abe87a756e3d0e
python3-kuryr-kubernetes-4.7.0-202105140104.p0.git.8b61936.el8.noarch.rpm SHA-256: 124d38ce4b8a6f28a0ddac9b426fa8426272f85a344b3e5308ffa905d646cc1a
runc-1.0.0-96.rhaos4.8.gitcd80260.el8.s390x.rpm SHA-256: b8a77bade0de8944dd6a62c7e816463faeb24fe5cb20755c3376556a8be0056a
runc-debuginfo-1.0.0-96.rhaos4.8.gitcd80260.el8.s390x.rpm SHA-256: d827b2cf934b353a7ecb6f9a7246ef961d98e44623cfe52f039e9d2df8a63884
runc-debugsource-1.0.0-96.rhaos4.8.gitcd80260.el8.s390x.rpm SHA-256: 1065968fb88da3ec3d89d76c63dc6bc0066b558e28c95d2748780824329e8fd8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility