Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:4850 - Security Advisory
Issued:
2024-07-31
Updated:
2024-07-31

RHSA-2024:4850 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Container Platform 4.15.24 bug fix and security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Container Platform release 4.15.24 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.15.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.24. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHSA-2024:4853

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html

Security Fix(es):

  • coredns: CD bit response is cached and served later (CVE-2024-0874)
  • containers/image: digest type does not guarantee valid type

(CVE-2024-3727)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are

(For x86_64 architecture)
The image digest is sha256:88d387f6fdae0c77613041aa6166ea35b301a3201becb8e1f354065ee3ee3a6c

(For s390x architecture)
The image digest is sha256:6766993fb25bdda0a00ce38c9be6d4629c0a1f2ed219322940a4506287657c4e

(For ppc64le architecture)
The image digest is sha256:6c0dce1a86f2336bb7493ead9d8c85b116208dbd9356af87ea34c9e2b0628324

(For aarch64 architecture)
The image digest is sha256:d29f09c0aca5ea05c86964f741e0d86575fc4dd39db709ad8e644cead54c3588

All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.15 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.15 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 8 aarch64

Fixes

  • BZ - 2219234 - CVE-2024-0874 coredns: CD bit response is cached and served later
  • BZ - 2274767 - CVE-2024-3727 containers/image: digest type does not guarantee valid type
  • OCPBUGS-36325 - [4.15.z] SCC pinning for all workloads in platform namespaces (cluster-image-registry-operator)
  • OCPBUGS-36812 - Catalog operator pod crashed during SNO cluster installation
  • OCPBUGS-36870 - NTO operand reloads TuneD unnecessarily twice

CVEs

  • CVE-2024-0874
  • CVE-2024-3727

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift4/driver-toolkit-rhel9@sha256:ecbe01f20e2169ae76dce32b7cb3a16545271488601a635756fe71959d026604
openshift4/ose-agent-installer-node-agent-rhel9@sha256:8515ce453bfac15087bc476616cd91e3cf473753f35d955dad197773dce9552c
openshift4/ose-cluster-image-registry-rhel9-operator@sha256:e8d13e181b0d61182c644ae1737c3ffd2d861b57f2b849235641ca235d2035f7
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:addbfe6a86ab7d98b983c9001a262028588b83e326bee490cee3c595148d623f
openshift4/ose-console@sha256:94ed097987afe3abcf3fbecc8552132985d65d54f665cc1a06de7c6465538347
openshift4/ose-coredns-rhel9@sha256:0c16d413ea08c1eccbdb6706ca43118de919a279ab86c66c95201883ac54e889
openshift4/ose-haproxy-router@sha256:186ec95c56f6c742173523873d4f1166564b06cdd4af9dae055af1b03f4a19de
openshift4/ose-ironic-agent-rhel9@sha256:0a17a990c559707de11893f5856e0e439ddc545626574ddf468e5f8d43bf35c8
openshift4/ose-ironic-rhel9@sha256:78d34fd9fb472618abefdf45fd0964ee6228644f8548797718e3bd6b0245534c
openshift4/ose-libvirt-machine-controllers-rhel9@sha256:cc0fa68e7ac3f97f49178199cf95d0f35fb8a7612fe66f1996365bf7008598c8
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:3952ada86beaa57743331b8014beadac751ce1e4b3499f65b6bff20f0d2215fe
openshift4/ose-operator-registry-rhel9@sha256:6ae849b54e1e3560e2a8ff5fa76cce15214c23f83aaca5f99e2332e375c97e26

ppc64le

openshift4/driver-toolkit-rhel9@sha256:10b09958285e35d1b5650f65c9529af55cf7dbc8df8dde959fd9e329109e0e22
openshift4/ose-agent-installer-node-agent-rhel9@sha256:34750d444686a546d089de411049de34a2da6d4b5eeb1371b90585de9aa10dfe
openshift4/ose-cluster-image-registry-rhel9-operator@sha256:0d78794f29f3009f8c0bd82bd310833b990c89f43fdaf6bf93197225269364da
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d0391a5087fdaba6da8adb3d938439297520042991ae956237b52b0529f87413
openshift4/ose-console@sha256:8f2cce34fde81a8f9b30901278ed26ae295ea71d337ad3ad9835ee00467d14b3
openshift4/ose-coredns-rhel9@sha256:ecb4cf9278334dd7ba523addafe33966d5dd0007480fa8e802f4e870cea042f4
openshift4/ose-haproxy-router@sha256:b65bf51f0d1cebe8e01698804021a3e5b20a3e26cb85a4eadfda26b96f872df9
openshift4/ose-libvirt-machine-controllers-rhel9@sha256:fe1c8bb199d490fafc60c6a99d69b4e441f77aeb13d168e44860f1530b592db9
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:a1586bae2a05498f4e4abcd06137ec12240a349e84dd53c0005dea7e4e9801a9
openshift4/ose-operator-registry-rhel9@sha256:99fd17429d97e52d20c8e40b4bcbdfdfe9c8da0580fcfdbe28e2837d32cbdee3

s390x

openshift4/driver-toolkit-rhel9@sha256:3c408fd22a03b012ca9e6d3d37f8b5af541231e9b728fd964ed15c30341883ec
openshift4/ose-agent-installer-node-agent-rhel9@sha256:05f9d802900b2e23465c593f5a3f7335b2f3f79fd65780bec9f6e910238c900f
openshift4/ose-cluster-image-registry-rhel9-operator@sha256:9a256f5ce5c6bf2ddc4a6018ba4ff6e7a12a4617b11b749fb80c1c41e8184b06
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:bb4059d222186c7384b2bd244d96017a0cf0310c13790736ce87db831547274c
openshift4/ose-console@sha256:1510b18921d4fef7e7a76249f13a0da3090115c29aba3f0448e147ae0ec77fa5
openshift4/ose-coredns-rhel9@sha256:f15ffcfb856a603834584d3818b93609f0e7ab6a4290bb332c5cc18482e865cd
openshift4/ose-haproxy-router@sha256:ba09f72cbf69253534480dc6d6241852e43630112bceb6ff511717c8e6b0637f
openshift4/ose-libvirt-machine-controllers-rhel9@sha256:f603914855a1102c3a78c58b7a5d87cd88a67fc50dafaa2cbb472ea3fe76579d
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:61eb791b852e84e2d6a5b68ba7f714be8577df93d492f01421979c214bba1e1a
openshift4/ose-operator-registry-rhel9@sha256:3369300d78bb20f03f9ee36795d040eabadce5446a42a27d3bf4fe487f2c44d2

x86_64

openshift4/driver-toolkit-rhel9@sha256:f5795679574a352b52cebd793c55d0c4ce03f4aaf2c787a1ccb7d305a20f8586
openshift4/ose-agent-installer-node-agent-rhel9@sha256:21688b76861b1d6a6d96d209ab7a40193fee15d511263de4fde6dca6879d1908
openshift4/ose-cluster-image-registry-rhel9-operator@sha256:3cafb94f71981d750073781f430b4f2b8a115f10845ee23f3b0c9612f6697832
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4a0e50bdde22987d5c40494584d4fded8f0120d6288b3be8e35b20e411ed7397
openshift4/ose-console@sha256:b3ca26bd4fe34ac0dde55c3966011b82e493e283c87323c9591d9c1eab2fcbb5
openshift4/ose-coredns-rhel9@sha256:1d96a087eac8c22a30b2b39478d248f6404855e794762329539aabfb46eaeb80
openshift4/ose-haproxy-router@sha256:acf3e277707191e82811a1d4b139db21d779a21bdf093ca8961b47e9227f5031
openshift4/ose-ironic-agent-rhel9@sha256:a2bc1d1ad15e746ebb14750131d87496c7682430491802d646e944cf3db0e862
openshift4/ose-ironic-rhel9@sha256:06de651d91229b19576e9c67bd3351128aa90d6d21b6b35e3f59701276284ceb
openshift4/ose-libvirt-machine-controllers-rhel9@sha256:9431071f4b4773d1bd523a67b1bd523f63ee5f7af7c7d01732c672f1442a326f
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:567991b15bc4615590916c428aa9d1d835f4f076c5fd268eacb6cebddb17d925
openshift4/ose-operator-registry-rhel9@sha256:d00b50929f7a486fd4c91bc3c03d60e2b7e8cf9072564af5674834254115b3da

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility