Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0164 - Security Advisory
Issued:
2025-01-09
Updated:
2025-01-09

RHSA-2025:0164 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Data Foundation 4.15.9 Bug Fix Update

Type/Severity

Security Advisory: Moderate

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.15.9 on Red Hat Enterprise Linux 9 from Red Hat Container Registry.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es) from Bugzilla:

  • tough-cookie: prototype pollution in cookie memstore (CVE-2023-26136)
  • css-tools: Improper Input Validation causes Denial of Service via Regular Expression (CVE-2023-26364)
  • path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296)
  • express: Improper Input Handling in Express Redirects (CVE-2024-43796)
  • send: Code Execution Vulnerability in Send Library (CVE-2024-43799)
  • serve-static: Improper Sanitization in serve-static (CVE-2024-43800)
  • cross-spawn: regular expression denial of service (CVE-2024-21538)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2219310 - CVE-2023-26136 tough-cookie: prototype pollution in cookie memstore
  • BZ - 2250364 - CVE-2023-26364 css-tools: Improper Input Validation causes Denial of Service via Regular Expression
  • BZ - 2310908 - CVE-2024-45296 path-to-regexp: Backtracking regular expressions cause ReDoS
  • BZ - 2311152 - CVE-2024-43796 express: Improper Input Handling in Express Redirects
  • BZ - 2311153 - CVE-2024-43799 send: Code Execution Vulnerability in Send Library
  • BZ - 2311154 - CVE-2024-43800 serve-static: Improper Sanitization in serve-static
  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service
  • DFBUGS-922 - CVE-2024-45296 odf-console-container: Backtracking regular expressions cause ReDoS [openshift-data-foundation-4.15.z]

CVEs

  • CVE-2021-3903
  • CVE-2023-26136
  • CVE-2023-26364
  • CVE-2024-2236
  • CVE-2024-2511
  • CVE-2024-3596
  • CVE-2024-4603
  • CVE-2024-4741
  • CVE-2024-5535
  • CVE-2024-9287
  • CVE-2024-9675
  • CVE-2024-9676
  • CVE-2024-10963
  • CVE-2024-11168
  • CVE-2024-21538
  • CVE-2024-34064
  • CVE-2024-34155
  • CVE-2024-34156
  • CVE-2024-34158
  • CVE-2024-43796
  • CVE-2024-43799
  • CVE-2024-43800
  • CVE-2024-45296
  • CVE-2024-50602

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

odf4/mcg-core-rhel9@sha256:7817a2d1b6de114ca1b5226d09be4094eaa835b9c7d0a41086805cb4163ac443
odf4/mcg-rhel9-operator@sha256:66b735da50b05a5a22cbf53b663509d308017a217fea035fa70b09fecefe86c4
odf4/ocs-client-rhel9-operator@sha256:44e3d98c19e610e9fa811f41891aaae979467cfa91c2857e213583e4bc59e1a7
odf4/ocs-rhel9-operator@sha256:50a235be9eeda52c5a29ddfd429f95432f1f69c87ddc1d2f9265ec5e1da70ec9
odf4/odf-cli-rhel9@sha256:fd1a1a23f2afea648bc7b3ea77fb058cd084ba38cf7192c025ed8fa70ed9f993
odf4/odf-csi-addons-rhel9-operator@sha256:84cbb62107754084a5609f4912207ab247b76e0897837d3adfc9a91b06bafa25
odf4/odf-csi-addons-sidecar-rhel9@sha256:54403144cd72d71d4f6e8d8cd2dcc9ac8207a71dd48ae9a1b900d6c4814b6b14
odf4/odf-multicluster-rhel9-operator@sha256:137cd5de95c8bcee67cf76555dc461d1e3fab2b6320fcab81cb251c91d8bb825
odf4/odf-must-gather-rhel9@sha256:54c0d01faab0360c7d7aa0ad488d7867c68d25b8323094d91622d5291762811f
odf4/odf-rhel9-operator@sha256:7a1e409ac23b1212834d5dba2da4736a5ef52de466f59b89fdda6c7cc29a0fcc
odf4/odr-rhel9-operator@sha256:4b16b53f3fd5ebb41d9e8c1e9bde02d1d8aa5cda35e88a6e8a3d35d1ccdfedf5

ppc64le

odf4/cephcsi-rhel9@sha256:3937c42c64a9081ddc0a4b5525becdd2447aae95ae5185b59763f5cd6d8d9ed5
odf4/mcg-core-rhel9@sha256:9094e2fd73c5f596670851b5e34682b944df891a02dac93286f3b773caf4af31
odf4/mcg-operator-bundle@sha256:e64903ef260263c7f0779b8c9797725c423ce752cdb89935c43d35b184c7e45d
odf4/mcg-rhel9-operator@sha256:4c83b9041674c6e1e4a84afbdc8c7a81f73de21e82f20dc1c6afb771847d5b49
odf4/ocs-client-console-rhel9@sha256:65fbf4dbc21b4aae396354468c0e8a745050e2336b5761b9bc653fa95379dd7f
odf4/ocs-client-operator-bundle@sha256:384b4b031d0851fcee92ab683166c76e1e4189cc01c84d10bc03e50b22d884a6
odf4/ocs-client-rhel9-operator@sha256:ec22e19a1a0c9dfb748f92836cdbe962d5d0a2357f6d886bf42e0e42c59dceb4
odf4/ocs-metrics-exporter-rhel9@sha256:3157bbe3ec0600100311d7ed133847c62cee5262ca882001857d9d6d5c26d6e4
odf4/ocs-operator-bundle@sha256:114edc4bebdc0cad21feec6f94f60d61f2497929f905474204f5c9aa8191e713
odf4/ocs-rhel9-operator@sha256:0ad68ddec888376f3f6c6b9f9062ea6f168478da7c486946f6f31ef823b0ef95
odf4/odf-cli-rhel9@sha256:d042cb185853e17483c9e1964b47473e3901f60e7e0891d57036c3b355b7ad30
odf4/odf-console-rhel9@sha256:920acbb24a05df495c4153e0bd51ec4cff19c2ba783b3f9f001d583bcdbb01f6
odf4/odf-cosi-sidecar-rhel9@sha256:bbc6b08747ba404faf7b8b9b512c325cf57b00285e86d5873c7573f360511109
odf4/odf-csi-addons-operator-bundle@sha256:6f8e56f1519fc3f9b4804a9c551058b92b00965103239061da1990bc7b602497
odf4/odf-csi-addons-rhel9-operator@sha256:89f0474edd31e53908de679169fa6c56a6914948033299b4b6bfb86b022f888e
odf4/odf-csi-addons-sidecar-rhel9@sha256:08bb11d356ec21507a460d7fb29705af84b81b99982503204c1728ec5d9641a7
odf4/odf-multicluster-console-rhel9@sha256:69949d60d1bfc13d193fd74f193899a3afa44b0e4dc38a93403af459d96fc2f3
odf4/odf-multicluster-operator-bundle@sha256:93a7249fc48703d89c98554dd361f8c1859955b77a443d3030de1897161116d2
odf4/odf-multicluster-rhel9-operator@sha256:f83c6898254bb3490ad10e058227fe72c809b6169966241a5c44892ab8d227f5
odf4/odf-must-gather-rhel9@sha256:c129891a9b1f5c02258b872a747168782bbc633e415f0248b9df37b3415fc36e
odf4/odf-operator-bundle@sha256:815b8b390f9b129bcd10ec73eddf21d7250674a5ca7ffb0d604c81894b7cbecc
odf4/odf-rhel9-operator@sha256:05cef37dc66427a15280cf4bb7c055a9db08932dc2a4bca30ba816624ce46d5d
odf4/odr-cluster-operator-bundle@sha256:37bf61df390ffff7ae6c8cde93c7b0a59e52f95106963e7933a7cc32d1fcc091
odf4/odr-hub-operator-bundle@sha256:b365387d8ae44150af9ed728f31b30c14050f2b3875dc2169506164bc2b15ee2
odf4/odr-rhel9-operator@sha256:3619a2b4ee71a023c781d62bde7a14c853fc564449e31d8f8a806c0d0b1f3ccf
odf4/rook-ceph-rhel9-operator@sha256:0bf915e956e440d1db22090bbb583593824b2e9d0fc929d891fcbcf744809558

s390x

odf4/cephcsi-rhel9@sha256:b7b3409ff5f52b3fa2c7f84f996f7468686e0a900b77e857ef9a4495e8556c68
odf4/mcg-core-rhel9@sha256:51e0b564b23b53da2ddf70a672c039afb38e19447c7ecdbe98984bdb081465db
odf4/mcg-operator-bundle@sha256:bcd9e01713211bfebd7447161aa5c74a76e05247dd545f32855ed962fb0d6823
odf4/mcg-rhel9-operator@sha256:6fd9acdf1a8521a400640236fdcaecab834ad065cdf64f1004094315ccf8f2e9
odf4/ocs-client-console-rhel9@sha256:b30986a29f5baf8c017fc7afa9d652711c23220094d556d43e01a817fe4daf1d
odf4/ocs-client-operator-bundle@sha256:f80cf655d891a16f218dbae983ecc0d7198912a27f2756cafa9b868a7b00da7c
odf4/ocs-client-rhel9-operator@sha256:1cb2a857941d2f629b1da758afcc4f6f05e16ae00eb6b3f35fdb58893f16420a
odf4/ocs-metrics-exporter-rhel9@sha256:578e0e4e00460806914d4d00226401465265eb1dd43a2401f2ff988e1c83806a
odf4/ocs-operator-bundle@sha256:64480d6fe5e017282fef728cf0f920772da7b0d2508e6101b7e513a3fa9f9fa1
odf4/ocs-rhel9-operator@sha256:fbb5a48b7384e9f63ffc743df30b5901b19c9e5bd4d9086f96c1f3843eb75d84
odf4/odf-cli-rhel9@sha256:caddccac7b9752f76e72a0d11ac367aef6c06b77e11eb9a7ffc22d032c321273
odf4/odf-console-rhel9@sha256:37fa930cbf34510e74628c08de8b6f99bf83eb675cd620a34af15a1f691b013d
odf4/odf-cosi-sidecar-rhel9@sha256:16dbb3d170133b7e29c4ba68666827a109ee7187838c4397ff9a21618f4fce1f
odf4/odf-csi-addons-operator-bundle@sha256:c647c8145247744e0f6b7f8e73dc9a9b575ecbc5d3d952528b59aa514111337e
odf4/odf-csi-addons-rhel9-operator@sha256:86ecc604fef6788d1cb5e8416862f4deb2f04d5eff221bd0eaab86e0dafe3dee
odf4/odf-csi-addons-sidecar-rhel9@sha256:b81f242ef73d7d068073fbaa8f5a7a543e85e35564eaded9cc0d1a8d8bbb2ed8
odf4/odf-multicluster-console-rhel9@sha256:5bf30cc10867e25a2224c92a75eb9c0ef12d3c0e88e9e805612f1d31440c6b02
odf4/odf-multicluster-operator-bundle@sha256:6b8ba892689a379ab98d817816bc0cf420364ff46bfca6227b89285843a86968
odf4/odf-multicluster-rhel9-operator@sha256:29c8412908ae3c47e26bf01c59076d88bc2121f52783d5a44af3de9a4e12e033
odf4/odf-must-gather-rhel9@sha256:7b286b5738129a947df94de9089a3ab6e5ace3c130b249108df4176a342e33e5
odf4/odf-operator-bundle@sha256:b9c5a8f11a8ddcee38ff049d000dca64ea9f8c8f2d86467a752bde84211060d1
odf4/odf-rhel9-operator@sha256:36a4fc7a16f407d8131c550a3d8ef938f42c9e900450db1d09cdc21c9c9f3137
odf4/odr-cluster-operator-bundle@sha256:84488a0de65621880e5f55279d8cd922cc82ed422e7d82513423995b7901326f
odf4/odr-hub-operator-bundle@sha256:b83df43790d7508ae08f85413ca0c32cddc2dafe271f093fd63a64390652585b
odf4/odr-rhel9-operator@sha256:208395b5a3580eb4645b38def5ac57ccc8f23040dc2aaace55331560a79c7389
odf4/rook-ceph-rhel9-operator@sha256:52b3e7b4ea2e00f7c5a5c49e5b1e9899e9dc758c13e65670eae5ba79de3fc3e0

x86_64

odf4/cephcsi-rhel9@sha256:09e31fd9fcf5384bf4b38a9ebf9a2d61743b9e127a4f054b9f623e69f27f86ac
odf4/mcg-core-rhel9@sha256:ca9bfe19cc69400e2bd4700f29017fe9ec87f057e61babf38fc239b50cff3de8
odf4/mcg-operator-bundle@sha256:d62e96c9eb95d55df1cee4aed2b5dc3e91bde16f4a70b2a796841040813a36b7
odf4/mcg-rhel9-operator@sha256:0ed292c91ef8252f3f77454c1a5bdc8c5537514ec0fe11e352cdb4f6b2649395
odf4/ocs-client-console-rhel9@sha256:e69658ef8a9410a42d877e8d32e300b83190e8ad3d4135bcfbca40ea048b9b13
odf4/ocs-client-operator-bundle@sha256:48b734787a14525410dc36bfb96a8b270fabef6e28cb36bc018c673cf10ebe6e
odf4/ocs-client-rhel9-operator@sha256:c455b1a39487855d949c4fa3902fa295fcaeda7c491c40d184b05ab574b94308
odf4/ocs-metrics-exporter-rhel9@sha256:5f1f93569937823dcdca79af386c09940568667800eee988c874ae9fbd6ec792
odf4/ocs-operator-bundle@sha256:600c7c62bc8b670abed7669204eb8ba0ea5381b50f55c3155328704f57e6fac9
odf4/ocs-rhel9-operator@sha256:d4d1e360d1139087afb23a720b2066fae621bf674430310c4cd90fd3d3e78567
odf4/odf-cli-rhel9@sha256:9991b0a080d5156cfbb4a9072f8054fdd1e442469e1b7f738bed75575ca44472
odf4/odf-console-rhel9@sha256:24d3b1f6d23154fb25a0560bbf13fa962e11001c22991d78d941b4a6fabf2abf
odf4/odf-cosi-sidecar-rhel9@sha256:83f58d172d606cd3c8a62ca2c1cb59271325350130457972f8344c6fe83b172a
odf4/odf-csi-addons-operator-bundle@sha256:fb37cb8285ec359f0b989b380c0383be50adbb6f4445d1215f2d1d62fcb64fd0
odf4/odf-csi-addons-rhel9-operator@sha256:3be9972c6eae43930e5b975e71ceab699cb82a4a27a006bf11f1137378f54074
odf4/odf-csi-addons-sidecar-rhel9@sha256:365d2cccbabf03b74226ad0e174e254894ff2f30d8326a6a9bdb43d21733ed56
odf4/odf-multicluster-console-rhel9@sha256:f205c884dec22de48caf49134b4a6e708e025459d5ca9b62dc517463cfc6ffac
odf4/odf-multicluster-operator-bundle@sha256:74ed33ccd3088ec8af8dea1ef6dfb493763c376059a948399284c7f71726ce13
odf4/odf-multicluster-rhel9-operator@sha256:fcb4756af29ba557d19c39e1302d0c7cff7e0b090e4c5be738abb7d449ef92c3
odf4/odf-must-gather-rhel9@sha256:5db3c8100d1ddc03a18b50d25ca3c5d44fdbefb8aef97d5b2c5f678e89d3c06d
odf4/odf-operator-bundle@sha256:da9d121532476f2c29d7e0d7e7a6484f454e12a27bc8a2c78924e3233f8811f6
odf4/odf-rhel9-operator@sha256:17de023fe113d9f55027acb8349ea053bfa34e3ec7b34053dab59613c2010a87
odf4/odr-cluster-operator-bundle@sha256:ba079e0f046efdbe472a4eab0ad3edc1eb299563e6aa4e4210184775c79a59fe
odf4/odr-hub-operator-bundle@sha256:ffdef4fa612e41c01644c7f1f1bde0a0d3664d52a822a67df55230e8f515833b
odf4/odr-rhel9-operator@sha256:5172c09a0c168b6e625a2f7d5705c657d257e8c2471081c6592925e73d66fc54
odf4/rook-ceph-rhel9-operator@sha256:56524d91acb5424966c097f78bffbc6412f8a092aadea1f8d9687e553bba9fbb

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility