Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0653 - Security Advisory
Issued:
2025-01-28
Updated:
2025-01-28

RHSA-2025:0653 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.17.14 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.17.14 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.17.

Red Hat Product Security has rated this update as having a security impact of important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.17.14. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:0654

Security Fix(es):

  • golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may

cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in

golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.17 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.17 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 8 aarch64

Fixes

  • BZ - 2331720 - CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • OCPBUGS-48322 - [4.17] LSO stuck while deletion

CVEs

  • CVE-2024-45337
  • CVE-2024-45338

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:3fe4397f5fe7f586e84f147611c594cb689bfebffbed1d449e872274feb71258
openshift4/ose-cloud-event-proxy-rhel9@sha256:83a10ecb35b4a177481d7fa6a311b601b6ea96f2b4d85becad4cebc123ead0fc
openshift4/ose-local-storage-diskmaker-rhel9@sha256:7fe7fd7453ef4ed35696203d2aa52e20166d24c783426a04ead9d88ec91d677a
openshift4/ose-local-storage-mustgather-rhel9@sha256:03139664bf88cce6c7a1f28b36b38d05cdd1012cf69f670a66f696b1cd6191d7
openshift4/ose-local-storage-rhel9-operator@sha256:8d4b5a830af32fbe73996d0ba41d2ebc1c24df28d55521356dbf0cd9588a0681
openshift4/ose-ptp-rhel9@sha256:5d993633cbc2f5c858493ce91e147b4d6fba93c83bc88d64e499a54a25fbf6de
openshift4/ose-ptp-rhel9-operator@sha256:5c92b4acb8df7a117c3a92c4e93fc0304db985a4426ceb90c362bcca517f077c
openshift4/ose-smb-csi-driver-rhel9-operator@sha256:3bd3233ffeed2c5720983fdbb03413a0c83c4adf72caa697fe1079f2f553bd37
openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:bfc5730568927a5bcd9ac65f8907c7498bbafa1cffbef65d6299dddb748b2a7d
openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:57c394377ef8db5c9c07901a8ad67a0173d2de8e982a0ce37a51e3dd668198f5
openshift4/ptp-must-gather-rhel9@sha256:233c86975a0857088b2eff6320c2094674d3dc2393905ced19bfcf0daa48b04f

ppc64le

openshift4/ose-cloud-event-proxy-rhel9@sha256:9c8b3eed0a3385f54c6af67cb2bb48717c7fc34ad729545587271de329888aa5
openshift4/ose-local-storage-diskmaker-rhel9@sha256:1c1418b4ab558ac00178c4aca51d7388c518c77e565b4fbb497706857237c184
openshift4/ose-local-storage-mustgather-rhel9@sha256:238c255a96e26f71d5b40628824a23048f4a3fd32f9fbfe5b94063b0c647ac11
openshift4/ose-local-storage-rhel9-operator@sha256:41ee609ac63866e22b18c311161c5b211da5dbaf504afec79662962eac283ad4
openshift4/ose-ptp-rhel9@sha256:7f548c365d7be6285eb755187d6f79aa7f121a13e6f1d3f2c27c9b6988f5ab13
openshift4/ose-ptp-rhel9-operator@sha256:b9ba63d0a7a6930403bf4a19a70d449456219e0331134eafa97dfdfadeae0acd
openshift4/ose-smb-csi-driver-rhel9-operator@sha256:66b130b978ec62641094c839b75fec23dddd6fb95a6f697a72afa8b75b4efee0
openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:78087c1181787f56a2f14f5f6eff7b5e4aa374f1b60c8a92cc500980403a414a
openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:337f2d985957eccad95eab488ee5a9e6541015191400cee645f68b52edc1fa8e
openshift4/ptp-must-gather-rhel9@sha256:76d75aa93ed829cbde208e1778cb6e33802d7070c863807d0361a69ef01014fa

s390x

openshift4/ose-local-storage-diskmaker-rhel9@sha256:74d7d8b2546502c87fc4e67420e80895c3d02a5f817ef7ba54b7c5e4f719a18e
openshift4/ose-local-storage-mustgather-rhel9@sha256:6df974dd34bba7a40545655ae6eddf408d3247cd4e6c0f9af3293ebb21bfa303
openshift4/ose-local-storage-rhel9-operator@sha256:46db9c0f973a3a0c7a99fcb25fd93ac35b417213dab957888db25f502a581305
openshift4/ose-smb-csi-driver-rhel9-operator@sha256:9cee73a132fced89a5144050a24ba7e85da91c85244575e9628f369fe64664ec
openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:1b0fb51af1841fdf3596b4c87a5ddc070fba44c4ce3354f0b22dfc78fec91813
openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:e98cbe8a93b4fe89512a0e8eaf888cdab29efe96c3387ee8df6d40c6202ba95c

x86_64

openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:b2b01cbf6a1d26da968a3ad303a2183515a874b4b8c2dab53e1146d25ad8b2e4
openshift4/ose-cloud-event-proxy-rhel9@sha256:7dea24af45414335f1bd8f058721c2ba2a9bdda9342d453ef7e5d4c3f992d4aa
openshift4/ose-local-storage-diskmaker-rhel9@sha256:b61e9281efb6c68d32c9becc5fe7d7fd601b04f7b2a5815e1c6bd38e69b5a1ae
openshift4/ose-local-storage-mustgather-rhel9@sha256:1ab884f98586d2c1b14bcd03d3b120b7470b5903101ed9a4096d457e6ab36569
openshift4/ose-local-storage-rhel9-operator@sha256:1cb3e47d28a262792f8ab6f3f9f5e26aa867fd4dcd3350792519f54de305e997
openshift4/ose-ptp-rhel9@sha256:eccc98fe2b1697d9961e5184ae1571bed2ffb0a0b52b1e7c6e8e7c6359bfb136
openshift4/ose-ptp-rhel9-operator@sha256:f28540edc42678149c6e9e292a48f20b58f04b1adcb08ba6c8f3c2a5870f5917
openshift4/ose-smb-csi-driver-rhel9-operator@sha256:82dc51f470dba32cb720a369d17d7359688db2bf872200250221f19e0f546dc7
openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:5d114f8d48cd00ff9e9b3eb8f2a140149deaa35e9566f7b0e2f3e1d263028f6e
openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:0aeb88a0d0e7c2bf55dd4c1e3190a57ac9e565f85c904fa1cc30ba6f71a3fc98
openshift4/ptp-must-gather-rhel9@sha256:f7c2e60e634c64d88e762e3ebe430305f9548a097fbfd1d04a935ebbb9197b6e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility