Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0645 - Security Advisory
Issued:
2025-01-29
Updated:
2025-01-29

RHSA-2025:0645 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.15.44 security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.15.44 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.15.

Red Hat Product Security has rated this update as having a security impact of IMPORTANT. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.15.44. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:0646

Security Fix(es):

  • golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may

cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in

golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.15 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.15 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 8 aarch64

Fixes

  • BZ - 2331720 - CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • OCPBUGS-47650 - [sriov] [release-4.15] FIPS scan failed

CVEs

  • CVE-2024-45337
  • CVE-2024-45338

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/ingress-node-firewall-rhel9-operator@sha256:7115e11135132d92dce5f03daaffa24c42b6bccc08a9f093f569045c2abdd59e
openshift4/kubernetes-nmstate-rhel9-operator@sha256:61e492db13f95d3c16669377ada5811da444f7371790a28db989de9223899f9a
openshift4/metallb-rhel9-operator@sha256:5208f557e2c39af8813c6c9da08fd4720351726e6273a56bef2c763af9136c21
openshift4/nmstate-console-plugin-rhel8@sha256:13f3a229909c074263dcb854f732a7c86102e302dd95f4b5da6f5c6f3d4d3eb7
openshift4/ose-ansible-operator@sha256:e1889810bfeaa6aa805654e0914d51c49c29f1f9f6ca3dd73c4ceffd49062022
openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:e7c6b0ac1ac41d0a100e27496a7398ea7681b809c182de392e560c945e4c6c0d
openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:df97159ba668b5db2b402682ece67f4d653f0c276cb42329035be06b7c24274f
openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:801e7ab4548ccdbe4986acceffc7030fbc2776ca3e17d53d5d71f4f62ac4b878
openshift4/ose-cloud-event-proxy-rhel9@sha256:0f3264a3e78af9b51b8d66694e793082fef728c2382a581a8007538318e0d210
openshift4/ose-cluster-capacity@sha256:a7d6d5d0a61f8bf8311bd019808b675dfe7d863b5424c9a6ce4bff33a88166b9
openshift4/ose-cluster-nfd-rhel9-operator@sha256:55d677f93fdeaff6372d622c5b58e7f83d68ef4a91744e922822b3b531c29236
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:0de77a0003ce0681909d171c7f6db670f851e93a76abdc9e2665ac7ce76c0f45
openshift4/ose-egress-dns-proxy@sha256:33ccf58bbee847f3014333f8f2e1aa0c7c774548681b9eba87ee52ad62f30c1a
openshift4/ose-egress-http-proxy@sha256:efb60f6c164313717acb4f3961df6762898fe5d7bc3e211e0262b2d19aacf137
openshift4/ose-egress-router@sha256:a086db5359268aa8073082894dfcd1eacfe93c6c913f98bf6f508168923e9618
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:76eae3016ebba08a452750fd0aac9e83b54bb50277f1f679ee3a8bd82aaf9af0
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:a9231ad2ec05ce406ebe03f50afac02f4b9a7501cf39fcf8065e011dc1bdac20
openshift4/ose-helm-operator@sha256:90d2a9a3868aef0db1838f4ce1585c7c1a5f04c0e266876ba39a052ff90a0a4b
openshift4/ose-local-storage-rhel9-operator@sha256:46ea8e006682fb826e897264769b354bd8f0c0acc4876766ddc106c97c56c9e9
openshift4/ose-operator-sdk-rhel8@sha256:d1971fc6246d6234171135c67d1c30b87c861d78acc9d8cdbd5d4b5382ec2d07
openshift4/ose-ptp-rhel9@sha256:b9db82e50b3d0caf88e3fb48152fb4569b6ebb2042293e0b975e17d988f2d95d
openshift4/ose-ptp-rhel9-operator@sha256:0349a965e3a6b5d8ca677f8d0e6756e2b24ec7369a67d4ffd19a69cd129f34ab
openshift4/ose-secrets-store-csi-driver-rhel8@sha256:4bd540a39c5d7773fbf2d928ab0f4173bae2782b5926f2dad05b082ca55c8f4c
openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:4a138d5c01db9ac16ac35e025bbfcb96703f5df574cf1f2296911e04bb5a7b0d
openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:f35a1ddc58a5f13949c1c39090be16521df66ce091382d6f71b84edba18de3f9
openshift4/ose-sriov-infiniband-cni-rhel9@sha256:b29bf69abcb2c649f7bb780f5f751c7e5ccc18723d23fc35baec5ca406433a14
openshift4/ose-sriov-network-rhel9-operator@sha256:bf068b672658f7dcbb7e481aa81281a009c9f0e88a200b45635a66b56634cce4
openshift4/ptp-must-gather-rhel8@sha256:547a4a30ba1e72e74159b638d311136abe906feb5783f19e3fec7e3dcd7f8521
openshift4/sriov-cni-rhel9@sha256:43c2e0172399d7f48ace37f3bbdfcafc414e830530cc36fd1c3b3fbd79df70d7

ppc64le

openshift4/ingress-node-firewall-rhel9-operator@sha256:c2406400a726936507eb208b98a5320064b9c17d989c7df553967be31aedac13
openshift4/kubernetes-nmstate-rhel9-operator@sha256:ab50c5442b48baf86fb593c69718d5072d785a8acebdff283a6fd9340c75992c
openshift4/metallb-rhel9-operator@sha256:9b9b58a22ec6e7e8ba10bf27ea8f3bbd38b0dae16db7e81b2ba736a9b106de71
openshift4/nmstate-console-plugin-rhel8@sha256:142cfdcba3d864812701022add7ca36a6a4c8ffa4fc9479c90b6e209d97210ba
openshift4/ose-ansible-operator@sha256:5a3529a59dbc0f91f9685a669ab1ad9cb2347775d4cda5821246a6f1df6f39ac
openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:77da1253d7d658ca1d3f0aab0873e0539dba7d39daf3a054cfc12f48d893c4db
openshift4/ose-cloud-event-proxy-rhel9@sha256:2c85fc5b05f0a0ea9b39d7f94b6f36bd81dbd4f13beba6d81a55ef06f2f038d8
openshift4/ose-cluster-capacity@sha256:4790cdb5f89d21d469e0b4dbe13f66c10d44ccb9ca76a7a9ece7dbb32f3703dd
openshift4/ose-cluster-nfd-rhel9-operator@sha256:43d93dd1e9d976fa70e75f2a75e283f79257b9201047c8a0847b1c46151834d5
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:01c977d35a8aff52b92f17a15bf9651627823d072901c0232b3abb97f0bd41f9
openshift4/ose-egress-dns-proxy@sha256:2444fbaec613561145aa57c9e526c1fa5a78fb8b87a74b979c2e1474a010d8dd
openshift4/ose-egress-http-proxy@sha256:e1a45845074f592638f46c63bfc87112a37363058dc4d3fa232e1bb58001b686
openshift4/ose-egress-router@sha256:203d0097a1ba10d6582af51bc22a8dba71f27f7c3244177057ed61d354cddaa0
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:dd6a46fc201fb4f32e48ab056c3c7ecc1e3da2946ab9190e096a722cdee9cb03
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:d7647b33d8020fc13fd62dfa8254efeb700958d556fabeffadc7e96b766a2434
openshift4/ose-helm-operator@sha256:3efbdee77e4028c1b0af3b0a8e265d21e07daf64381efd33b068d8f8cd4f4b60
openshift4/ose-local-storage-rhel9-operator@sha256:14025b7a147f19c2536721e6747d6ddbd4cbf8d53ef329832c7265adc5c911eb
openshift4/ose-operator-sdk-rhel8@sha256:959eabb135d7622c89a34eafdaa1333e3d54c79489cd7188653ffdb4a8e8720e
openshift4/ose-ptp-rhel9@sha256:711a94be9fb488d97baed8b6186eff2a5b0a6ce2a2a27f1fd22f6613302e8f47
openshift4/ose-ptp-rhel9-operator@sha256:e621cafc22e69c9998e4b87414a354fbb3f11a583d5d1de1ef153893bf629af3
openshift4/ose-secrets-store-csi-driver-rhel8@sha256:c57a882642f3f805329967d94e6ba6af2738b29820480576fbbc79c6e5fb6d33
openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:4b8224d9bd504801e175c326fff8f1ed7dfb5ada276f4158c9dde1acb1465d30
openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:9df552c581a3d77954124faacea61635262c8cfc2b768b56fa19b679162d6425
openshift4/ose-sriov-infiniband-cni-rhel9@sha256:5525dddd6cec6477b6048f773d0da67b6e8ba240a088fe8bf0b11baa5b760a1c
openshift4/ose-sriov-network-rhel9-operator@sha256:a8217e2a071654a98ebfc4cd1e0f871094f268c27fbbeae62a6ac5b6a7d24b36
openshift4/ptp-must-gather-rhel8@sha256:942c9d43e358b91921fc7fca4cbee1b9efbdd470771b6ff1addeb282bbb4a2e8
openshift4/sriov-cni-rhel9@sha256:d4970f706b2e1cd9417e56575e3f81910f66922bbcdf19b18c48309fbc7a090e

s390x

openshift4/ingress-node-firewall-rhel9-operator@sha256:b920aee9675dc92ac40060f243f6df28a989f267bcf7d165e834f084d3eed59a
openshift4/kubernetes-nmstate-rhel9-operator@sha256:47f71a832f11c6ef8e3874b0ac9152dfa22feab15889c15f300ea0a87f4666d2
openshift4/metallb-rhel9-operator@sha256:8cb733e986a96d7b69d445a1228c21a1ea20bab96e3eda95d57039ce55798f7c
openshift4/nmstate-console-plugin-rhel8@sha256:99c8449229919a9f54b818b0e849c1a0a6d2017e0c4f4e8ff749da930fca8ccb
openshift4/ose-ansible-operator@sha256:6d51952de47b4ecf2ed75e273eabd3049df8eb7cc8560b1ee3e9a3a61f35e231
openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:9bc61b16416da0de9c988c8f758ffed8d640634a3611d6152f3f801165d99500
openshift4/ose-cluster-capacity@sha256:1bbc187c7c39f79c6a787cb4c6ff3eb40ec75c31a0ae5184e17a721a23314295
openshift4/ose-cluster-nfd-rhel9-operator@sha256:91a131023fbef69be22c201122c3cf5c014b8cfdf921a08f82b381cdc07cf895
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:03c842cfe4c159273940c066386e5da449b8ccaa22cdc725fb755012d5192c40
openshift4/ose-egress-dns-proxy@sha256:4d46d799d7a39691f47b773e1e0c01f36e7883a6625baf48ef8de1f209f128a2
openshift4/ose-egress-http-proxy@sha256:39f2a020be80c50feaa37f7d35eee2f9736c373f7d23e1180dddf96c0b6ee0fe
openshift4/ose-egress-router@sha256:05a8cb5204beeb9150f34c905097364a221fd06ba4b758d690d687f54869cac4
openshift4/ose-helm-operator@sha256:e5055523af0038ddacbc89230216a69f7ad0c9b2591be50b4346d29bc85f41dc
openshift4/ose-local-storage-rhel9-operator@sha256:53da559d8fa393a777b554d8bb339a18bd8b9e0d7113323702af68b73c1f0442
openshift4/ose-operator-sdk-rhel8@sha256:728d374c937af6ecff1e6e6b369796cf07beeeb7acdcc4a93c49e782bbe4cf24
openshift4/ose-secrets-store-csi-driver-rhel8@sha256:fd6e27beb9c1911b85f7d0bcef0626286d914c184fe09916288e92688fcc9c1a
openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:bf517d981ddf57556c01ed296641907622dc17058b62636f9c15bb672a3fd698
openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:2f260d579992c50e0ee223c44f63162b96444a21281204cbe748bb5b8b677e79

x86_64

openshift4/ingress-node-firewall-rhel9-operator@sha256:c6580537a4e92ade960386f67583816b5ac75f64402b4abda44f185bb24b477d
openshift4/kubernetes-nmstate-rhel9-operator@sha256:4893ee823f93801e6933aa5e4a1029b847aa20fd8474ecb16d38ce51ac6aa026
openshift4/metallb-rhel9-operator@sha256:cf42d86f53203cb7b91f5b94d7332b6130098bba3fa1690ca9dc32fa5c15b74b
openshift4/nmstate-console-plugin-rhel8@sha256:51769a4ea8e980c99a20865cd238ce1f25c811ab6c38cd04acee50b09853913d
openshift4/ose-ansible-operator@sha256:eb87ad3443868f36d9da0bad1cffe1df617b5764ccf7ae5e38c5a4d81cda69a3
openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:10913b01b18b4d765a26e76c2631a4a8e7b5d36285a7bc29a6f85c9a89ac2280
openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:3bfebc15dee07e9b9b898e09087d74ddffd67456b59d25ba19ac4059490dedbd
openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:7ecb6e70f9b7419b2e23b9072f289cfd61cf18dd876386b20ce44c3cb21354b0
openshift4/ose-cloud-event-proxy-rhel9@sha256:4e1d1ecc5b5ed7367abd240b30c10a585b24dbce068136efc5bad178c12867e2
openshift4/ose-cluster-capacity@sha256:fc79ee59245e0aecf79f2d2cfac195621569763fcd896a4e6288b840a59f1a96
openshift4/ose-cluster-nfd-rhel9-operator@sha256:fa2e22a66a31d6d4ea2e5d97d4a7a6eec6177511e8108f4a02925cf8cf78b960
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:9e074b34be48b91660d9ac4321ba95f2e33343f3c16c75bcb26225ad37377429
openshift4/ose-egress-dns-proxy@sha256:505b2988e0273b38850c7193a5250caaf258ee01192bb7c9bb5237e7ad7c9f52
openshift4/ose-egress-http-proxy@sha256:be3e8b243bc196ece60a0c0889a738da7dd709ee72547e3b6fc6e7ea160be446
openshift4/ose-egress-router@sha256:e1dfdc2b45b7d1176e339891d897106f8f8a2babd8a58cdd907203a2de8bf40b
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:5b565e4a8b6f075c8b988bcae965de80fca90d342f2be237a94dd1a1c4c2294a
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:e54b85baa2adc484aaa38f57461b371f76a0832b04f5d98fcf970fc282a5e81d
openshift4/ose-helm-operator@sha256:62aa8073fd5e1a34759c99efd48deb7883084d01caf56cd44c320cb4c31aa3ff
openshift4/ose-local-storage-rhel9-operator@sha256:9725276d722a8454e31816aeda3694ac098f76eba24e9736e003985f17316243
openshift4/ose-operator-sdk-rhel8@sha256:130e9c6ed4fe399c12fda4ef2d4e78d9fbba2acb1c8e8eef85d241bb98904f7c
openshift4/ose-ptp-rhel9@sha256:3063b1016e6a2ad6c31b56781f21e73b1c1051aa26f4b079225b39c5cbec7bd1
openshift4/ose-ptp-rhel9-operator@sha256:1f387135bea0d72159590d79cef0ccfd3025edeb980a0954fab8979783b154bd
openshift4/ose-secrets-store-csi-driver-rhel8@sha256:8b18a530303b0abd2c67161a237bfd4080e280d7549ff761eb4dd3ee84489b2a
openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:1920adb1dfb322415f26d539765d3b962b3fb3fb57db49deb45d3237278ce71f
openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:50821133e5ebcc2e3a1b2c498196d0a9c78df9d3b1ba74e149abf59084bb81df
openshift4/ose-sriov-infiniband-cni-rhel9@sha256:3bea814c2576b21383cbce81a9b40654192b68252ea1a17a36e5ccf036fe88df
openshift4/ose-sriov-network-rhel9-operator@sha256:df4a699ae22ba5ac598e69ea82c3d27b779fe3758734df8a769dc4d495456f01
openshift4/ptp-must-gather-rhel8@sha256:27a0032351b60cc59ec62140680d5a185e9b4f921bd3f5a80aa2f70a3e967059
openshift4/sriov-cni-rhel9@sha256:c802ec48f3d7b256118a12ace0e0aa871b853bd9059d897cc515b9e9b6221de6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility