Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10823 - Security Advisory
Issued:
2024-12-12
Updated:
2024-12-12

RHSA-2024:10823 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Container Platform 4.16.26 bug fix and security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Container Platform release 4.16.26 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.16.

Red Hat Product Security has rated this update as having a security impact of moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.26. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2024:10826

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html

Security Fix(es):

  • go-retryablehttp: url might write sensitive information to log file

(CVE-2024-6104)

  • cross-spawn: regular expression denial of service (CVE-2024-21538)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags

The sha values for the release are:

(For x86_64 architecture)
The image digest is sha256:7ecc9d14151c7d16a04aec8103ba6c32fd424898e45b7a09e9bc861ccf895eab

(For s390x architecture)
The image digest is sha256:1d3e9211862c50a10eca9b4e892b2acceef271c52407e57642378095f9732335

(For ppc64le architecture)
The image digest is sha256:af2ec5ac93e6b43b4a85a7c9061b5281da597efca15056cce267883300b66fba

(For aarch64 architecture)
The image digest is sha256:e2b8441b9931f8fe4964d1759497c3b3af5228120bb54ed3ff82b6a6c9b89143

All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.16 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform for Power 4.16 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.16 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.16 for RHEL 9 aarch64

Fixes

  • BZ - 2294000 - CVE-2024-6104 go-retryablehttp: url might write sensitive information to log file
  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service
  • OCPBUGS-39372 - NodePool Controller doesn't respect LatestSupportedVersion const
  • OCPBUGS-44456 - Sync stable branch for cluster-api-provider-openstack release-0.10 into release-4.16
  • OCPBUGS-44792 - Collapse/Expand Feature Added, Removal Option Removed in Version 4.16
  • OCPBUGS-44874 - Telemetry userPreference results in empty nodes output to the DOM
  • OCPBUGS-44875 - Start last run do not work in buildConfig details page
  • OCPBUGS-44895 - Delay in provisioning master node
  • OCPBUGS-45015 - [release-4.16] Remove ClusterTask dependency in console from Pipelines 1.17
  • OCPBUGS-45124 - [regression] Impossible to pass multiline parameters to templates
  • OCPBUGS-45181 - Ability to sync OS time from NTP and update HW clock at the time of installation of OpenShift in ABI

CVEs

  • CVE-2024-6104
  • CVE-2024-21538

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift4/driver-toolkit-rhel9@sha256:d3b202cc6d77207f938dd987bd74af50c1e85f8c731e657643060f94ff74f42c
openshift4/network-tools-rhel9@sha256:df92075e02f2a10650635a34d0264f1a4de1d3088cdde25b10e1f02c9c08e230
openshift4/ose-agent-installer-api-server-rhel9@sha256:deb5205b49937c56c1da1a4d99a7fe367863164bc28c40fe90d15b960698e377
openshift4/ose-baremetal-installer-rhel9@sha256:83ae1bab573192eca28401340ead868a8a060ea3a0a074fd5f6b0f3ad9d38888
openshift4/ose-cloud-credential-rhel9-operator@sha256:ca4ec6ff8c325f9ed28555bb56f43ffdc07b94617e9692fbebe6e2af0e4e243a
openshift4/ose-cluster-autoscaler-rhel9@sha256:0044511738de69ba8ff84fd9b8b6beba2bea08020dce60b761166fa484657121
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:a6c8678c1853bb48436f1b88b46acf6bfca863e8dcacdb53bffe822e9f2d592d
openshift4/ose-console-rhel9@sha256:406e9bc504584e79fb1cd2b7cbb7b482c5fe5d3fa68106273081414751d07b6d
openshift4/ose-hypershift-rhel9@sha256:7e2843aeb35e3c34477d460e39ca965090087fe1be344121d36fb093c8a0ca0b
openshift4/ose-installer-altinfra-rhel9@sha256:13daa8babcb0c4715ac0c23bb3c8b73cdc7d05e9e2e271b6355b1105b229e0e4
openshift4/ose-installer-artifacts-rhel9@sha256:1c285578b6180a8a6c3a862647c34e7060cbbfcd2eb4261974d810bea18ee413
openshift4/ose-installer-rhel9@sha256:a197c4052f93223696a6335c594327b4050c67e57ad1427df64da24ad8ec6ecc
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:7387f761a9a58fa9507f723d97692ec576ad51da75b2d7bb49392a8caf8e9d2b
openshift4/ose-ironic-rhel9@sha256:4222a4e2f63511dfbd07bc97841369c9c2f28a179b936aada42323e51a25f86f
openshift4/ose-machine-os-images-rhel9@sha256:45183b4740c5358195b2483fa8415cd4f375d9cb3eb03073c7f4a5b916ede008
openshift4/ose-monitoring-plugin-rhel9@sha256:86d8742e2a9739ac11bfb3327f9c0493411abd7984274f9d2cd44eeb624cc7db
openshift4/ose-networking-console-plugin-rhel9@sha256:cdf2da663ef2ba7490557232f2c1fcbf97cd698fe0da80e5d425e5a842263881
openshift4/ose-openstack-cluster-api-controllers-rhel9@sha256:8296f179804c152858976b754b32932c7928751006ff51936ed4bcaf909c617a
openshift4/ose-tests-rhel9@sha256:886d34f8981372b2a421d82b7e59cc3be78d1085fcdc11ab0af56c701f11de75
openshift4/ose-tools-rhel9@sha256:bf3379a8b4175594f5970c0cfe5d48eac2259de7f3aa78819e384f164154fdcf

ppc64le

openshift4/driver-toolkit-rhel9@sha256:073fae43179377b9a509e08ed63aeca250f7368439c12a8ab5589ff125201ed5
openshift4/network-tools-rhel9@sha256:5491bc8d306e5bc783824077e2832fb8e9c7b3712471853eecf19e7745b4a9c5
openshift4/ose-agent-installer-api-server-rhel9@sha256:a92ff5c8702bce81b99510ddd1644d4c2f833714eabb97f031ac0e82d6ead422
openshift4/ose-baremetal-installer-rhel9@sha256:d3c56a54e7cbc934e19430b7e948e7b8a6f5d51b0918b3738e455f396427d4e4
openshift4/ose-cloud-credential-rhel9-operator@sha256:856c7d165e06055c120810859d804d17d0635d3e186e37631dc8d207fd945aa9
openshift4/ose-cluster-autoscaler-rhel9@sha256:30547619975f84bbb85c0372a60e07ac548fdf68663943c6651caf458afffbbd
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:3317932512907d713e27059f74e9f468a5800eb23677bfae2dabb24da663d8c9
openshift4/ose-console-rhel9@sha256:b7ffa518c4903754f65661bbe359da9666a35bf6d09b124ce96aa45666ccb39a
openshift4/ose-hypershift-rhel9@sha256:153b6d4ce73be9613c702afaa8774f4cb2ee539e08b3f12d751e64d516fcfacb
openshift4/ose-installer-altinfra-rhel9@sha256:9312cb8fd1e55f6b5055d8e2bd339cf1998bbdc5ce537ffb4c5a61b501f2f2aa
openshift4/ose-installer-artifacts-rhel9@sha256:d2979711573f2b0d56bf94c3fe5140a583b5f5573a4a95d989a96612e9302210
openshift4/ose-installer-rhel9@sha256:c2f922fbee69157ad1b8e293ac14f268d93c3bb60348bb3f666e1cebabd8198b
openshift4/ose-machine-os-images-rhel9@sha256:80b0a7442efb95780db7750e2a5382f26d9def34f089d20db1551755ae646894
openshift4/ose-monitoring-plugin-rhel9@sha256:d24153565576aff8c5fe2b8c1e62227f5bf7e15c87e894ffed069b8a2091b2d3
openshift4/ose-networking-console-plugin-rhel9@sha256:cdfc779fcc0717185ca1d3eafc75ab1cfe0ba94b3e51d734a1333e8d9264a4fa
openshift4/ose-openstack-cluster-api-controllers-rhel9@sha256:a23dfa7cb46b0b046b71ab8b08f27687fefef674a37a412de1c5332a6ab4dfcc
openshift4/ose-tests-rhel9@sha256:1123f5cb73434ef6616e9c4a224f762054211c2faafd09dd4b5c4014f95256d8
openshift4/ose-tools-rhel9@sha256:5e241a21c616fa4227eb136ca8faecaab83b523537308626a994f1e82df0e3b8

s390x

openshift4/driver-toolkit-rhel9@sha256:f789ae59040dd9708a37ea446d80da517fa0eb630ec4b3ff277353cee5c10287
openshift4/network-tools-rhel9@sha256:08e35c180b212f67f7942744ed75281e1335e37176dbddf4aa8405860eff0b9d
openshift4/ose-agent-installer-api-server-rhel9@sha256:1aecb68890e83bd9b49a0945e6ccd929c70d78d9a3c027814162bae5da958377
openshift4/ose-baremetal-installer-rhel9@sha256:c94f78d1389140013aecda297c04184d6571e573749a09dd9e3648bb862ca824
openshift4/ose-cloud-credential-rhel9-operator@sha256:34982b14838e78095571fe6792c56ed1900b2975027dd0039cbd9333e4f65f4e
openshift4/ose-cluster-autoscaler-rhel9@sha256:386af7b7d5bd40a39f5a80d5404901f3575dd3f4b0c6694d296eb7b7e136bb8d
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:b00798daa9f32d37ddde28672f2451ff1445faf76606d12370895418a5da2ac6
openshift4/ose-console-rhel9@sha256:cf729dc9c7a618f37f7d8d7cfef6b7884ddc6767f2a017fbe7d840cffdebef97
openshift4/ose-hypershift-rhel9@sha256:327a90e55fd989757c4c2f481c46f8bb7ad492ce9721f28b385ef1fa25305ada
openshift4/ose-ibmcloud-machine-controllers-rhel9@sha256:6b99e7fab91b7b118fc3b7f03fe174095464829b84bfe4c582ab8a5b55d9a3dd
openshift4/ose-installer-altinfra-rhel9@sha256:e7ead2a4d8e858e83c12cc4d30df1101ad467c9e1aac19ceae344efd863280fb
openshift4/ose-installer-artifacts-rhel9@sha256:0d4601665306f56cbce4c717d0f8d4e88156794931395f7b71a0d12b376be9b4
openshift4/ose-installer-rhel9@sha256:3a10e9d1f6e4ce63473fbd5daafa15c851027639e25727970fa6cb3f35283032
openshift4/ose-machine-os-images-rhel9@sha256:37b212b802eddb1341d4940dc6a3a2ae519993557fce23d484084fce53478cb1
openshift4/ose-monitoring-plugin-rhel9@sha256:03257d5132e2a38020d2ff5e429d9197911045b1f5f416563f69675ed1df7639
openshift4/ose-networking-console-plugin-rhel9@sha256:f5bada0a8c78fd0585651f4d96a82bcdf05bd17b97d5a4570c3cc1c66bc1d45d
openshift4/ose-openstack-cluster-api-controllers-rhel9@sha256:b4c74a1f5c9f1ea890c0e9f71fa9c55d0f13fb0fb4281d74c8990197de07e094
openshift4/ose-tests-rhel9@sha256:965a17a70a8cae8db9131c35031ce15cadfb75a6ce54bd85c3ab48fc194f85f0
openshift4/ose-tools-rhel9@sha256:582da06f6fde711ba84ba352513bd57d4ebe478e25c537a789c48451693f3a22

x86_64

openshift4/driver-toolkit-rhel9@sha256:d0e1f1e1fa657e1bcb148ef714f9325d75ef3a21248a7cef56d404a15b143bea
openshift4/network-tools-rhel9@sha256:87bb74eb4211eba4abd2f079d26065bff96bebebe3dc5a6115e557c46b36d029
openshift4/ose-agent-installer-api-server-rhel9@sha256:c537893896ab4068ad183ebbae64d25c65645496aedda159ce9a4e41d6763eb0
openshift4/ose-baremetal-installer-rhel9@sha256:2360e90def430fa49417dffc67db6528416f2586f626e030f8eabcc53b387c9f
openshift4/ose-cloud-credential-rhel9-operator@sha256:ae4ad261282bcaf0f49aaf964988675683739747e80046f964b8e41860a1990b
openshift4/ose-cluster-autoscaler-rhel9@sha256:0d646b93c683b95943f7ee763097805579559e811f6c16cd71e9710e1bd8f78d
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c77d180573859c703bc3e578eb7387d572e13fc08e4b3592d17b15d0ca0a4393
openshift4/ose-console-rhel9@sha256:ce1747c7ccb467142b9366b98dd19b89e9b7d9a2f979c890350cb9eea330a63b
openshift4/ose-hypershift-rhel9@sha256:c65c3285b80109044e363e8d1099f1b4e794ec4b30c73d192b82e3035325c797
openshift4/ose-ibmcloud-machine-controllers-rhel9@sha256:5964336ecc0d208667f165b6f668f6177b2ccd0afc0fd4e7cc4e3d9361aea361
openshift4/ose-installer-altinfra-rhel9@sha256:b671cd681c73903f8285012b8faeefbb7309676a0c9324b9f710a3793ce18918
openshift4/ose-installer-artifacts-rhel9@sha256:ed7f711ab1883f1b36b8ab52fbec1d2a2efcb43234ba94cc8e3dfca2e1c15a49
openshift4/ose-installer-rhel9@sha256:2498d45ea43a836b89a7e5633f81ac83e04418e1ee2707bb15eed9ae12060053
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:926ef8d19df2a36eebc3d269aedecb71a2b9f1b29da35b16148aab6db1129c83
openshift4/ose-ironic-rhel9@sha256:02489ab8434e9d708a2bd84fe1fe95eca60b495077066d9e5a482504a4b1b964
openshift4/ose-machine-os-images-rhel9@sha256:5840ecf198df293a16885b1a87c4479da547348f4df1b3d2a9cbc816558f6ba3
openshift4/ose-monitoring-plugin-rhel9@sha256:b3183620acf30a6fb6046dd2311d90026e23e54bb3c9af15d1f5abcb78d99e7c
openshift4/ose-networking-console-plugin-rhel9@sha256:06af72fd381bf31dd8c71e0b9ee6e0a048787f2dfba879f33af92e06ab3aef04
openshift4/ose-openstack-cluster-api-controllers-rhel9@sha256:1da798492bea040bad85d7b9da6fc7e30b5c6fce6408909d4c016f1ccedb8973
openshift4/ose-tests-rhel9@sha256:3719b22906b84275724a5d36770dc34772462423b23756220f58b940d4fce288
openshift4/ose-tools-rhel9@sha256:cd0442e4997f92ffb60031b05b9afa0f5acfe9a06758792f34ff13ffa7b2b306

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility