Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0140 - Security Advisory
Issued:
2025-01-15
Updated:
2025-01-15

RHSA-2025:0140 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.16.30 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.16.30 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.16.

Red Hat Product Security has rated this update as having a security impact of important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.30. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2025:0143

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html

Security Fix(es):

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in

golang.org/x/net/html (CVE-2024-45338)

  • unbound: Unbounded name compression could lead to Denial of Service

(CVE-2024-8508)

  • GraphQL: Information Disclosure via GraphQL Introspection in OpenShift

(CVE-2024-50312)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release tab=tags.

The sha values for the release are as follows:

(For x86_64 architecture)
The image digest is sha256:7aacace57ab6ec468dd98b0b3e0f3fc440b29afce21b90bd716fed0db487e9e9

(For s390x architecture)
The image digest is sha256:83d85abae03310d7875f484ea2ba5d0224fe9196d7be0556032feb9685282472

(For ppc64le architecture)
The image digest is sha256:e9a6f42c118d20b1e81dcd17c4a2166becdd558dd55d5badd33a36cdda5118fa

(For aarch64 architecture)
The image digest is sha256:184c6892722a60f87a0efea8eaca8fbbca3cebfc7c0eb6496005c241ce383a22

All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.16 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform for Power 4.16 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.16 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.16 for RHEL 9 aarch64

Fixes

  • BZ - 2316321 - CVE-2024-8508 unbound: Unbounded name compression could lead to Denial of Service
  • BZ - 2319378 - CVE-2024-50312 GraphQL: Information Disclosure via GraphQL Introspection in OpenShift
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • OCPBUGS-46524 - BareMetalHost CR fails to delete on cluster cleanup
  • OCPBUGS-47645 - Azure Cloud Controller Manager Panic
  • OCPBUGS-47698 - e2e: add irdma to module_blacklist kernel args
  • OCPBUGS-47701 - [release-4.16] PPC: false negative reporting while comparing the topologies of affected compute nodes
  • OCPBUGS-47704 - Too many pending CSRs lead to scaleup failures when scaling to 500 nodes
  • OCPBUGS-47738 - Evicted Pods owned by Catalogsource are not rescheduled
  • OCPBUGS-47793 - Bad HTTP response (409) sent when the subscription request is not correct
  • OCPBUGS-47795 - Unable to subscribe two or more consumers to the same PTP event

CVEs

  • CVE-2024-8508
  • CVE-2024-38598
  • CVE-2024-45338
  • CVE-2024-50312
  • CVE-2024-53088
  • CVE-2024-53122

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/driver-toolkit-rhel9@sha256:3692078bf6c849f201050f0d66239638cdde56ea574a3e66cad6815244edd9aa
openshift4/network-tools-rhel9@sha256:2e540e9ed4ccc9321249d2f40cc9c6a6477720031b1eb5c6f0ba9e3c4fdc3e84
openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:50cfe0a16ab572a75870daa9dcfada0a830ff6cb39a7e895d3eaa6c239e8df55
openshift4/ose-azure-cloud-node-manager-rhel9@sha256:2b96b1a91f370232db32e47446062435aee2dec7e4a776a955836dfb76e0429a
openshift4/ose-cloud-credential-rhel9-operator@sha256:7f570a2ea837869b57ff32a0e58ce28a4f1bd8f750fc056dd7a4a8139d738a10
openshift4/ose-cluster-machine-approver-rhel9@sha256:e8ad85471a599a15384118ad84e5fe04c1066966267ada590c9596fda1a26d57
openshift4/ose-cluster-network-rhel9-operator@sha256:30b717387c360535ec0c7196c22018fa18e1d9a6f7c6c13097b04b45ad168e04
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:7df61fe55463528ec68f2fa8e3230d9a4ee6b5e57860fff8b3a494981ecb11e6
openshift4/ose-console-rhel9@sha256:1d7cf74ed566cc2737f80167180828f426f17f6835c2d30fb7d47232befd2ade
openshift4/ose-hypershift-rhel9@sha256:634d5454b3d80af282794d33ea14bc5b706af1d7f4cec854ee529126c383b3ea
openshift4/ose-machine-api-rhel9-operator@sha256:4da710c6ba1112629acfc0a605cff5cb1a45ac56738159271ce6dbdb01f3dcba
openshift4/ose-monitoring-plugin-rhel9@sha256:281135c869d040b174650c9245ac0c0a7f2ebf40c118a1d28f07a199f189d135
openshift4/ose-networking-console-plugin-rhel9@sha256:bf1b44ef5576e8ed3e9435ba9d3ef7276297a7995887bd019fc72069755a4fdb
openshift4/ose-openshift-apiserver-rhel9@sha256:485b94663eee05699713efb3ea84bd10ff092a68391a278ef2bf50220490fdb9
openshift4/ose-operator-framework-tools-rhel9@sha256:090f2f55098edc2308d8a631f65fc1f931c3c87591d68ef735b5d9505e2df66e
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:684786e22528524f839867cbe0596c38492f5955173bd5ff498a1cc8a9139746
openshift4/ose-operator-registry-rhel9@sha256:615f591deaa19a25fbf0714ce9a8fc838e4a2650be72f04088671e02f44aa1d2
openshift4/ose-tests-rhel9@sha256:585097c2da401a0b37e74127274acf36fd5a1cdb6b9b6d4de5238aac68a82a20
openshift4/ose-tools-rhel9@sha256:fc39f41bd5716be0284a1149f918d766a3394188c6cb7cb3de08900ad19a204a

ppc64le

openshift4/driver-toolkit-rhel9@sha256:0788cc893f3c3fe13776a3b74e733eaef22fb376a50b41cb2a4064098f494f89
openshift4/network-tools-rhel9@sha256:3355d618a7608b72caf5a20a156070c9a780307d75ac8c13c50b4c53c0adadf6
openshift4/ose-cloud-credential-rhel9-operator@sha256:710767d4394156f89a8081e0f760d547f806e8c0d5593863a01c6e86baeffea2
openshift4/ose-cluster-machine-approver-rhel9@sha256:088633bb25394ac6595c6120213962ab5df5f919f6b2564a79dcc6d162c00f79
openshift4/ose-cluster-network-rhel9-operator@sha256:33bab056241314bc10b5acf9851c6232e1ba44ae50474f028d76e3c0b8907819
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:8890e1d96d5bb7be3e0c61d2df3e46df16f27c5ab83f5d5777bc1c520a13cd52
openshift4/ose-console-rhel9@sha256:6a8bde992c71507a29f99b8c8f74be4e2a9a1afda4ab0a79b42ec6bb448f9d1c
openshift4/ose-hypershift-rhel9@sha256:78dc922b3e132f34849a962074f2702be95ed6d1010204df3ba29fd6cfc619da
openshift4/ose-machine-api-rhel9-operator@sha256:c1b19bc6c7a675f1eb646dca8d9fac344916a1af797ba035a6a94c8276f081d3
openshift4/ose-monitoring-plugin-rhel9@sha256:c4a9d21a84c28d788afb2a432c3ff3aa5ea501aa9d82c7566f8c67a39da22c3e
openshift4/ose-networking-console-plugin-rhel9@sha256:882b1f6b8038c94b51a330533c238da2d72c5a7fb169cb642fcd678cb8574008
openshift4/ose-openshift-apiserver-rhel9@sha256:6804255cc525b9106509eb34c25abff776ab03e2ffd9133b672734c753996712
openshift4/ose-operator-framework-tools-rhel9@sha256:48a0b160f6a53e7f73a17246712b73432b4aa81375ea670d9bb2608166903040
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:ed4330297895128161771302521e608c00fcf2ba1b46617f9d1dc3c5250d74ed
openshift4/ose-operator-registry-rhel9@sha256:0d623ff1fa4bd1faa10bda177dfb5a963d201d56c4d6511b3271b6ea94ea0b92
openshift4/ose-tests-rhel9@sha256:f43938e36d3a63a1706a92825cf5b878673b4f3734593fdeec9051de707a8ef2
openshift4/ose-tools-rhel9@sha256:1f690694f958dc4df9a3f16cdc49233f2733fdf328b4e681306da9e85b482fa1

s390x

openshift4/driver-toolkit-rhel9@sha256:c5d791f47678270136183fce850a87e21e60410e1c88a1040b82348ee3480eaf
openshift4/network-tools-rhel9@sha256:e574f1077ed39453679c274e8f025a49b3ab630f9fc69c5843ecf16bf17d2f26
openshift4/ose-cloud-credential-rhel9-operator@sha256:fb38c15cdcb6443826a209377481bc0e64fbddea2d72f5854f0abfeee6bb7b0a
openshift4/ose-cluster-machine-approver-rhel9@sha256:b37207e27a4ff7449cc09a75868c8d8425fffb7989e6f2caca459dc6a3009521
openshift4/ose-cluster-network-rhel9-operator@sha256:9ff45306e5c5fc5a45f2d7dfac65b4504ccab952d80c1f69499d0eb5f2b68655
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:ebd626c92e011d7260e50bb3cd8c13b656e883ec9e483ba227c91c9c142fe39f
openshift4/ose-console-rhel9@sha256:f3f68c1aacd28732173e290ab598175498a949b9f2358f3f4ce78c027431ab0d
openshift4/ose-hypershift-rhel9@sha256:15641a80ccf126f3388a15d1dab6878b57f64a7ad28ac5fde534b90a07156f76
openshift4/ose-machine-api-rhel9-operator@sha256:72ff41efe162043811997d37b151615b0e9dadb160414947c0dfbb1544787c87
openshift4/ose-monitoring-plugin-rhel9@sha256:fc56056860cc684cfe3bd1c54e17f0f4d11cc6238ba92fedccb425814dce85b1
openshift4/ose-networking-console-plugin-rhel9@sha256:a04e738c58c86fd62a4868b0b5b245cf9b9977f4d0dbc1e3fa18cfd0b4ca9403
openshift4/ose-openshift-apiserver-rhel9@sha256:7777383223bd2f56bb708d501fa328df00791ba16112926a043524035e119fde
openshift4/ose-operator-framework-tools-rhel9@sha256:e7c37173a9d6f9fede9be792e720c4a18c4143f1c01139709bee5156fb179140
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:1f345c1fe715a1243f72df05fb8ece7c43f38e452f5be77d4a2044acacd0c013
openshift4/ose-operator-registry-rhel9@sha256:c4d9f263f747f4ac35a762a7550e3e633d547e09f7584813b974e981b6171764
openshift4/ose-tests-rhel9@sha256:a2c53e8847a3ec2c4824a84061e9792e27f2278d57b68971be8c9e77e48b1586
openshift4/ose-tools-rhel9@sha256:ba0a5286de0f597e01848b971658e4429b110884a996d810aa28c76000e64a97

x86_64

openshift4/driver-toolkit-rhel9@sha256:37bc4b1f8fdbb3702e6b6ef15e3ca7bee4bf9902fbe6922ec06cb640188b2b87
openshift4/network-tools-rhel9@sha256:406c5f0ef3287123d14d117db603ced651e80a790f3e79c443255b09f9201798
openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:0afad7b7c0b70f382c5af08ffbc7960e6cec4c7a4a77ef0412654b66b9409dd0
openshift4/ose-azure-cloud-node-manager-rhel9@sha256:0e9a6290982e2cb93066c839c8ff6390e58decef8959af4ed8e6da089aae7001
openshift4/ose-cloud-credential-rhel9-operator@sha256:bc197126cec1a9f6c3525be72be1dcc755b8cb891320c6076548d7ef6a3028f3
openshift4/ose-cluster-machine-approver-rhel9@sha256:55ddb7dae8e366fd10f8069bd19d6171c0e7b3622dbb53109bf40ea190cddc30
openshift4/ose-cluster-network-rhel9-operator@sha256:0978fbdf465d7b9ea5502d502156011c355ab83cb4511f578c938566896404c1
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:491d8b1d8e08708427c2625f4b10108fcd706a833bc02435d9ebcdd4e239f7d5
openshift4/ose-console-rhel9@sha256:596113e5aa895de590f83a12d4216b054f83c870b70444b928a52989f6df80a4
openshift4/ose-hypershift-rhel9@sha256:abeec9180996406e66a4409a1eb5394b7339ae13fe8936995ed7d1d5a865dde0
openshift4/ose-machine-api-rhel9-operator@sha256:0028b8cc67e020954e57e5cf81740e30fe7896e4569c3c39dac079b1838ba1a3
openshift4/ose-monitoring-plugin-rhel9@sha256:cc10a569ee6c2989fa2fd48b19bc162c312cb10e3035997f1249708d734e94a7
openshift4/ose-networking-console-plugin-rhel9@sha256:c74ace304a2f74a1bd258a43e8803db1421d66878d8e8e1947e1720c39449bfd
openshift4/ose-openshift-apiserver-rhel9@sha256:5dcadf3bacfd3a4dcc9cc9d2987177d3a718cb9011b7b6cdcb20221f90d10446
openshift4/ose-operator-framework-tools-rhel9@sha256:5f6768d6357ed0dbe46b013b669c6c30c4a4d0ba563922e8a7a2ea7a368f3bc6
openshift4/ose-operator-lifecycle-manager-rhel9@sha256:8d7b09ba0ff25852e4f3d802cd070b079dcffd00ac7e986d9b554b7927133635
openshift4/ose-operator-registry-rhel9@sha256:df8835185bc0051c3582a6b053cf337d09c2e57ee4dc324b819ddcc93aa6e602
openshift4/ose-tests-rhel9@sha256:948dcc42cf690ac3fc81db917fbc919f771f2447a0a14be2b6ace8c09c023161
openshift4/ose-tools-rhel9@sha256:24817882cf12c76e974b52ef861ee98e5337c9a52160ae77a9dad405cf4a5833

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility