Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0115 - Security Advisory
Issued:
2025-01-14
Updated:
2025-01-14

RHSA-2025:0115 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.17.12 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.17.12 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.17.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.12. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2025:0118

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html

Security Fix(es):

  • runc: file descriptor leak (CVE-2024-21626)
  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in

golang.org/x/net/html (CVE-2024-45338)

  • GraphQL: Information Disclosure via GraphQL Introspection in OpenShift

(CVE-2024-50312)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as follows:

(For x86_64 architecture)
The image digest is sha256:7b39e1a5a98fa5bda517f3a1800c4bc96838fdc8318036d1b0cc519fa3534690

(For s390x architecture)
The image digest is sha256:c8f6db9b700aed437a869d28c3e657159fd882d51e50d4412b0ab33ffcb42309

(For ppc64le architecture)
The image digest is sha256:f8fb1c6cd43b8f88ee7fff5870d0be047a2e3d6d7c3d5de1b4f5c56e414fd339

(For aarch64 architecture)
The image digest is sha256:cd432819f6123ea6430afeb3bb6291deb691935c5e563bcd65f11a9237ce1328

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.17 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.17 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 8 aarch64

Fixes

  • BZ - 2258725 - CVE-2024-21626 runc: file descriptor leak
  • BZ - 2319378 - CVE-2024-50312 GraphQL: Information Disclosure via GraphQL Introspection in OpenShift
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • OCPBUGS-41672 - Patternfly 5 components are missing their CSS
  • OCPBUGS-47497 - Getting `Oh no, something went wrong` error when trying to install operator.?
  • OCPBUGS-47712 - builder Unit Test Permanently Failing
  • OCPBUGS-47791 - Unable to subscribe two or more consumers to the same PTP event
  • OCPBUGS-47792 - Bad HTTP response (409) sent when the subscription request is not correct
  • OCPBUGS-47802 - Multiple reboots during EUS upgrade on Control Plane nodes
  • OCPBUGS-48068 - [4.17] Update must-gather owners (artificial PR for backports)
  • OCPBUGS-48143 - nto:e2e: handle regex properly

CVEs

  • CVE-2024-21626
  • CVE-2024-38598
  • CVE-2024-45338
  • CVE-2024-50312
  • CVE-2024-53088
  • CVE-2024-53122

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2024-001

aarch64

openshift4/frr-rhel9@sha256:5212e02d762ebafe58ca2c73337d63eaf3e12698d3f7adb82dc081162c0a811c
openshift4/network-tools-rhel9@sha256:89882be3b40bd56f4758745d5ab5e91c489539dd60adc7ef906fd20a206b1075
openshift4/ose-agent-installer-api-server-rhel9@sha256:15236fc08fa6bdf401175d9a898831684a0c5cb4058911425d8425a01a13c617
openshift4/ose-agent-installer-node-agent-rhel9@sha256:802e1ca56ee809f76f2ce5d926389ab72469d63d91515dc5b04383f3a47c5a15
openshift4/ose-cloud-credential-rhel9-operator@sha256:139310acbf21f93759ccc8eefc384f8f487a75ecad99e3fb1160c3713f1d607c
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:9aa04ebf5c9f8f772c50659b30b643cb5e100b26d713e048507e5e17319df46a
openshift4/ose-console-rhel9@sha256:9fcf611f0837f46958da0d6fe5574e535cb2435e83420e20f861720e383d872f
openshift4/ose-console-rhel9-operator@sha256:2a8ded36de613a93c2980bf9859c7bd575d4f7105ae3e9d62db3e5b75d8c8e93
openshift4/ose-docker-builder-rhel9@sha256:3a5b97c7237c4e88c88392e4db0724c94780d0fdce8e35338f4830c704ca748d
openshift4/ose-hypershift-rhel9@sha256:9c42ddbbf437dcbee967212cea174042221046374e77066185b3eda8f61e6117
openshift4/ose-machine-config-rhel9-operator@sha256:bbc849ef56950175e9ab143e17e7016bec7c939faa88ea3b3991a8c8a233aee2
openshift4/ose-monitoring-plugin-rhel9@sha256:c1af80d27347a7a0fcde72434887887f104575bfffa7673a86865e357901e58f
openshift4/ose-must-gather-rhel9@sha256:57c34f04070b87637ca38937e22c76d73758a6f93a30eee23a1e355cd35c5062
openshift4/ose-networking-console-plugin-rhel9@sha256:d2c8ba0654398cbfaf986afde00a52149cf7378812e163e3b6b9b30e974a4c5b
openshift4/ose-prometheus-config-reloader-rhel9@sha256:2bff78ee02862a502cde1a8ad67186bad62b9ba7e71dcec79280d31fc509c5f0
openshift4/ose-prometheus-operator-admission-webhook-rhel9@sha256:1db52fc1a6c9ad226a7538551c65aacef47f6a198ed5574f81c03d1ebb37d688
openshift4/ose-prometheus-rhel9-operator@sha256:362ff85ac486daecfa5128bd1b037b3577772940eded51860dca30830e088d0a
openshift4/ose-tests-rhel9@sha256:cc761464c5d7f38849086031c5d8415585c7823722a372cb7cdbf411e27f297d
openshift4/ose-tools-rhel9@sha256:5e24aef7e318991a13bbf21e7702edd7f2650f3b69bb5afe76437ae60893023e

ppc64le

openshift4/frr-rhel9@sha256:7511eb430c24855fe97ed963aed687b825e82c75d56c8856fda6923b35dcb23d
openshift4/network-tools-rhel9@sha256:e92db6450b2ac2cf37b6003eb690b74acd37c469b2fa97780ef86a9696913ff9
openshift4/ose-agent-installer-api-server-rhel9@sha256:097c4e17ef4525e913b1b90161bea683895452fa338424e8add3aa3b71b674e9
openshift4/ose-agent-installer-node-agent-rhel9@sha256:da26422197147727aa35a92897237db53b7c8b1189c9804f0ea2417fa6ce77bd
openshift4/ose-cloud-credential-rhel9-operator@sha256:3f69f30a2aea7bd89d21ef586d9a9033148dd79eb594241e29f339fd28810a31
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:92faf8240c18dd8997a573204b5bf78a4e323c91775e6da37dfd8db5eadfa276
openshift4/ose-console-rhel9@sha256:73d36458f00881f46c76e625f44b0a016c2b1e6cfe77faf52ef3cf9d2f4516b4
openshift4/ose-console-rhel9-operator@sha256:52255a9fee1486e0908c1f64187d421ffe07dd9a2c7b63d5be529ded2833e5ad
openshift4/ose-docker-builder-rhel9@sha256:aabb1e0efb2922c93013a855532d9f3f5e31d0638c80848e493c1263ceb63813
openshift4/ose-hypershift-rhel9@sha256:3eccfd9b636cd27bf8a7cf7934724b82ec4ae6876d0a344cb467ee05741902e1
openshift4/ose-machine-config-rhel9-operator@sha256:8b5418625375ab70a299f0a727e9ad3c0ee81d93f6246229529e36235169991d
openshift4/ose-monitoring-plugin-rhel9@sha256:fcece09c607077b86a99426ae44cd5fb9874ec4d483cc000d15d831c9ae6e57f
openshift4/ose-must-gather-rhel9@sha256:078e3b69ddd170de1fa749eb98ac9de97cdc77702b3512be2a45be6eddb32221
openshift4/ose-networking-console-plugin-rhel9@sha256:69a78d30bdcad04810b86fe08b958d9577f4f4902b0a6c841b220813bfe801bf
openshift4/ose-prometheus-config-reloader-rhel9@sha256:fed1d6a29066f0e4fc4dd531c92c41e6822e532afcf3ff3eaf0749ed63eec76f
openshift4/ose-prometheus-operator-admission-webhook-rhel9@sha256:2563651da86152cdf72d420fac3050f240cbff113f1dbc1b46b2037f47757017
openshift4/ose-prometheus-rhel9-operator@sha256:5e67ed7d6f92a32546bfc6712708fea22a79791520eae47a8909f30ac81c0815
openshift4/ose-tests-rhel9@sha256:700035f846920417f8e8bcc584208b41481bc3fe72ba6617073057e4743449eb
openshift4/ose-tools-rhel9@sha256:fb69e76fa2da0da58fef93e1e0ae19b47bd5f63fb1aebe08c2502669c2a7d032

s390x

openshift4/frr-rhel9@sha256:46f73534bbb01dce1664e9fdf6855d41d3c3ed34029ac41026bb96f847b22de9
openshift4/network-tools-rhel9@sha256:726b429fe3490ab1a958cbba71f7b3a46d02b1fe54ffb5a70e5604a9a42e8f3b
openshift4/ose-agent-installer-api-server-rhel9@sha256:88338dd223edf215c26fa8acc77686e36709450d5d0372dfadd514d8fbab894f
openshift4/ose-agent-installer-node-agent-rhel9@sha256:6893734a11a3bdd5a46b285843e9b5a9c09b0b2d234654f946d5dc1291decc58
openshift4/ose-cloud-credential-rhel9-operator@sha256:3ead532eec6f93f3b1e34d3144d669f1136132f7eb129ad25a0f6519012ac13a
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:81207f1e27b22128634f0d63b62c36fe8e844067ac2d7894639a3e763cc1fe74
openshift4/ose-console-rhel9@sha256:4224497544a6beac95ff098178b0f8611c353254a495324f59112d74d865d9b8
openshift4/ose-console-rhel9-operator@sha256:12c6cb48f15d58d2564a1a4140861ca7c1dcda1ded9924c4779486556731fbaa
openshift4/ose-docker-builder-rhel9@sha256:9c6832836754276dce44e306a4891123c77d23d59a74348ec70a4bd86ef229c1
openshift4/ose-hypershift-rhel9@sha256:cf8cb7b37d78eda29bd220968399869980d5eefe144672678aa91830f88fed10
openshift4/ose-machine-config-rhel9-operator@sha256:5ab91e7c78f201043f42a98ecec365b52184929cabb14467f3fbfc6df175dea5
openshift4/ose-monitoring-plugin-rhel9@sha256:e18faa3901de5702bef90f2f733168bdc57d9080625f8c5d8cbc111d75fc1ae5
openshift4/ose-must-gather-rhel9@sha256:e281b313b7a714622d086bdb1919c40ad6f2ff6bf8a225c7e1776bb5c7429181
openshift4/ose-networking-console-plugin-rhel9@sha256:2305e0b6ad109c5fa31ceed753d2661995d4724ccea1ce81abe4395706efd1b6
openshift4/ose-prometheus-config-reloader-rhel9@sha256:a7ed1d5194c0a32ff46662a718b691c159c7deec6fc828df3949bb7dd1a09002
openshift4/ose-prometheus-operator-admission-webhook-rhel9@sha256:95e0c216b7a50499c3e5690894e08e65b013e7a5e15ed58b0b53034dc0714554
openshift4/ose-prometheus-rhel9-operator@sha256:ea54077a2fbc4f3b6f47ef1044d32cfdfe9e3d0b56f03fda78d15a90ed81069d
openshift4/ose-tests-rhel9@sha256:e0a505f5e686cb2f388c36251f6aaf892e0d16d5f3e7d667cd9850579b197092
openshift4/ose-tools-rhel9@sha256:fed69a332e96542a14881e66d75592c4af04c5ee3ee61c0a32023b3e13d24b29

x86_64

openshift4/frr-rhel9@sha256:d02412b15aa52c1cab70939212bc876cde131d8c0b221cd0bf9250f75fb2ddeb
openshift4/network-tools-rhel9@sha256:cdda6abfeb0a9095177f60ea7b75db62b43af28de0d869e34e25050b8592ce7e
openshift4/ose-agent-installer-api-server-rhel9@sha256:c27928620dc56e0810301fc82ad619e4b9976bf601d48ce17eadf0c6321b57fe
openshift4/ose-agent-installer-node-agent-rhel9@sha256:49b3b961e2d80346432439605fcc81e10d5314dd86338dfb6cf67f39b2f7b5fe
openshift4/ose-cloud-credential-rhel9-operator@sha256:ea5edc24bb8b9d2239bd7e33c89bbd7c76fc11e468ecb8a9feb4d122a5dd7ded
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:a069d06d21386f150dc32e9adaad28da4069f924e685725158b62958d30c1e01
openshift4/ose-console-rhel9@sha256:b4c70f754b64caf173c31ec24d0acd82c7f04fc6eaea90e4818efd4a26f60362
openshift4/ose-console-rhel9-operator@sha256:86ee4f1e2f565605880a38c01a594b9d50d485e7a1c3a986c7ead94028b699e0
openshift4/ose-docker-builder-rhel9@sha256:9e4158d6ef0117239f1826c79cabe851bd6cc82a045a8c86674a1295be4291e5
openshift4/ose-hypershift-rhel9@sha256:73961bd739c1dfd21c4f342b475b8a76fbf2d7c0449649307851029c48140e29
openshift4/ose-machine-config-rhel9-operator@sha256:2f9ceb65825de7ebebd194cb7deb2e7cbe388929c9b88dd991077444edfb900d
openshift4/ose-monitoring-plugin-rhel9@sha256:a8c55f21385c620012041d79eb371c1a0226ffc98ddfdad4905fc552c1dcde58
openshift4/ose-must-gather-rhel9@sha256:700fc9d30f097b644dce8eb067a9f30b2356e9c4b4f3ae9ef4019aadc08d7cdd
openshift4/ose-networking-console-plugin-rhel9@sha256:85c3e910555ea4e5d1223db4deb39c8e8e5005d71ee096970e8e980a1a67a408
openshift4/ose-prometheus-config-reloader-rhel9@sha256:9762c088b90d45a863987f72deac6d894bf239364a9ec2e6013ed7adae875b41
openshift4/ose-prometheus-operator-admission-webhook-rhel9@sha256:6c951d56cd71a928fd9775a98623b5b45541f755e6764f0d7116f1b377300673
openshift4/ose-prometheus-rhel9-operator@sha256:c704c2a7c856083cc523b5a43f075c0c5b5403236ce4db3f7c5cc0c61e310967
openshift4/ose-tests-rhel9@sha256:272148c4fa2a6a244629535e0e25ea1c1fc39bdc8d488ff8344694fa67df3d97
openshift4/ose-tools-rhel9@sha256:e8f9165d86647a18b02053243ab4607ba9910ffd91960dd23a964de889c08fb3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility