Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0775 - Security Advisory
Issued:
2025-01-28
Updated:
2025-01-28

RHSA-2025:0775 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Data Foundation 4.17.3 Bug Fix Update

Type/Severity

Security Advisory: Important

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.17.3 on Red Hat Enterprise Linux 9 from Red Hat Container Registry.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es) from Bugzilla:

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
  • path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x (CVE-2024-52798)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2330689 - CVE-2024-52798 path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • DFBUGS-1342 - [Critical] Upgrade ceph version to RHCEPH-7.1z2 Async at ODF-4.17.3

CVEs

  • CVE-2024-12085
  • CVE-2024-45338
  • CVE-2024-52798

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/cephcsi-rhel9-operator@sha256:631b4807c9ddac3e24206cc81a0202dc2909805e0981c103363b8bc948befa2d
odf4/mcg-core-rhel9@sha256:3a071faaaa1f4e6d4ba0f13f7a24182a4516d57a775a1d515401e137ced6c996
odf4/mcg-rhel9-operator@sha256:dc025c0b6bbc414f91d25531e74f91672f5a283e4c545bf6bab535364ea05ae3
odf4/ocs-client-rhel9-operator@sha256:beea7afb0a8d770dbf7cf3611721b04f0aa0435ac578d04ddfe3bd25ea8f251c
odf4/ocs-rhel9-operator@sha256:2d50b99155123817766e1b22cb7e57e9ad8bb3ef11f5c27d5a32c1f48bc99ffb
odf4/odf-cli-rhel9@sha256:492673b05cf9578a7106eed3eb538f82041baf7ca411593c917cd19deca51ced
odf4/odf-csi-addons-rhel9-operator@sha256:1a51a10042151580cec1018d22c127ad2fee73d790a10375887a49355790c320
odf4/odf-csi-addons-sidecar-rhel9@sha256:94da06fc0a392a1fa372ddfb72a039d68570b8203ace986016df4b2acd6b0473
odf4/odf-multicluster-rhel9-operator@sha256:caf0d35429951f0d6f02c4d24b568e33890b915fd5409fc3bf9801418ab64aa8
odf4/odf-must-gather-rhel9@sha256:e5c3167f3a92c5863fcdf2b8a2bf8d7f1572321b70f3cb6a7e73a892e69170b4
odf4/odf-rhel9-operator@sha256:b2104f61d9ca62675b1ef0ad7510016c1e192fb84c275bf20b0b15687709d188
odf4/odr-rhel9-operator@sha256:d20f06bae29110c2ac50b074a1ff931fca29b5342ca67ec6fd3401ec902b4510

ppc64le

odf4/cephcsi-operator-bundle@sha256:db66b4ec8ff8296e68e4fa1b092256e41cb02e4fa14760fc86e17c1dc0d8df33
odf4/cephcsi-rhel9@sha256:1218397f98f75e8e48259739c5c73c9a1c092fbd63955f611463db5477262d93
odf4/cephcsi-rhel9-operator@sha256:4b0e2f9ed7f32b6a1b90d29d81f7c4a7f93fa99e2ccd4857a97e7f52b13432d1
odf4/mcg-core-rhel9@sha256:e0359bd7f35b45b3f9a1a1fbb34ef4e301a31b96c75421cb87299f4b320e6597
odf4/mcg-operator-bundle@sha256:b7de06ddcf2e1a2395bee9784de046decff49acfcd2d6082e0551237ecb27775
odf4/mcg-rhel9-operator@sha256:4276f1f062305363ea1355aec4bfc5b2c079f08281da48e74c3e22c1cc5bd026
odf4/ocs-client-console-rhel9@sha256:d7351eae984568def66130f1a0adef4f1120580ec27483caba19b51b06be2e78
odf4/ocs-client-operator-bundle@sha256:aa88056fbf96612aa65f21bdff941f109a7ae06b2023dc730d8a2b7f28e2c019
odf4/ocs-client-rhel9-operator@sha256:c6827a0f98dc71331a08a5aeb3c39a23699915ceb273fb08956ed7b8a9cbaccf
odf4/ocs-metrics-exporter-rhel9@sha256:de910610da6a2d0f2e0afec1cdf2aec4219a2d1fa988aabe75e0ca9d3dda8008
odf4/ocs-operator-bundle@sha256:da9813396e7cea5066d08446b18da0acac08524b9a018ca6fcd5135e65b6bb9c
odf4/ocs-rhel9-operator@sha256:2088f2444f10b19a1a3a1bd8e9f049560a234b8d5f287574d7c56e1106693950
odf4/odf-cli-rhel9@sha256:8edde7c3c879bb70bed60151e953b26f826eba35f8be2bea0e7f8fbbf19ddbe2
odf4/odf-console-rhel9@sha256:89db4dd9079dea23888beb926544585024f0d4f5bee9e582350fc951ff2acf7d
odf4/odf-cosi-sidecar-rhel9@sha256:6ce5185f87075ab348e03d8b6f0a3cb88ad6988bf73b82f9107e3207640cfab5
odf4/odf-csi-addons-operator-bundle@sha256:aed04293525c2469f7d7ef7b6adcf34d886abcaef29421c74c0879dd2e39199a
odf4/odf-csi-addons-rhel9-operator@sha256:71be35f451f98f6a78c4e7caf7efdba03ad0656eff33a463fa06d2685b1b4917
odf4/odf-csi-addons-sidecar-rhel9@sha256:b96c6d7062d7e68b3b14f0aa1b0f54e1adc7909a988bf1e008bb906485c00a60
odf4/odf-multicluster-console-rhel9@sha256:4048862925a5ccb7b6d458f1aaf5961fd7847bf0da684e405f9741cbacc73335
odf4/odf-multicluster-operator-bundle@sha256:bcb16d9b30c9f917ebe227f0b843639571d9f78fc2f46b5aa81c33b38e351e0f
odf4/odf-multicluster-rhel9-operator@sha256:2746caa28bc5cbb0498e1b637c83afe4b12def4aea85939de2275240cd59c9be
odf4/odf-must-gather-rhel9@sha256:bd372b797383f14e5c1a656109192e7902055d2090e5c1e52f3b2bfb584037ff
odf4/odf-operator-bundle@sha256:b1787c6d5ffc1bb61eedd483e4f30621f2086ed6f5200d990e3e65df032ecca2
odf4/odf-prometheus-operator-bundle@sha256:885c00eb563f0636bd3226e71ab2d54db5128f4a7edeff0663ea8923c28dda18
odf4/odf-rhel9-operator@sha256:1567b45f6892383e2c52f7c89b43608107e8fb2e9d6e502b0f19f529262509a3
odf4/odr-cluster-operator-bundle@sha256:0a9c13b80acc6457eb5ba4d39e5ebf7db4797964408edffed24695fd763a59f8
odf4/odr-hub-operator-bundle@sha256:17aab60e5f979fc0db5662314b610ca3e94411bf4623170b844a92ac3410dd54
odf4/odr-recipe-operator-bundle@sha256:887584d5fb1c08adcf9586fd012adb347f76c4a2a5368f3508f224598ef94549
odf4/odr-rhel9-operator@sha256:6b8a00202c66dfac1f5c61968341fbfc98c0bdde8a2597dedbe795186cbab224
odf4/rook-ceph-operator-bundle@sha256:944cbb913d5810b812419bc35c49702529151646f47d41e90cb2de3ea8430eb1
odf4/rook-ceph-rhel9-operator@sha256:6d03559c84c87318b78b7eb040108042a1f1dcbf3b98358f7f18e20004b28f4a

s390x

odf4/cephcsi-operator-bundle@sha256:f662e9fc3db6baec5854d8f3e3d64b99021777e9218bd391e0273c114e88ab6b
odf4/cephcsi-rhel9@sha256:e466fd8f8db4ab24e1212bcc1d8a177a7f197bf522257fff2876691c441a12e4
odf4/cephcsi-rhel9-operator@sha256:e8643999a91ecc8f647b000c4dd95ec2fc06e8e1f409c292c43d74c9d27410fc
odf4/mcg-core-rhel9@sha256:b939dcd622f4c0cd3fcd520a31b5ee8c0e1182e1bd6e9da0470d9069579162ef
odf4/mcg-operator-bundle@sha256:31c28061e59fda1bb0833f41bce95839bd9853d14e5bf1c8e02e903b01ee3651
odf4/mcg-rhel9-operator@sha256:a0e69ef5e79fef4ef3a989777c1016c6f265d45e6a93213cd1a18cf0772fa821
odf4/ocs-client-console-rhel9@sha256:852a42894fd99e2cf05dbbf28d4cacf7ca5b1a8929c77d80f426b360ce174086
odf4/ocs-client-operator-bundle@sha256:8f68bf9ccd711fc7d8995e045301b56a8992692258d69fa0fd2cbba2c8cb23e1
odf4/ocs-client-rhel9-operator@sha256:07eb6bcf76087da9d6af2fe8c13f6941c522ae2cf484f34f123b12d288bfdbc4
odf4/ocs-metrics-exporter-rhel9@sha256:77777d0b1760126cc9f304e728101727f0c2101acd773be3b372700d9bbf7ad6
odf4/ocs-operator-bundle@sha256:2658de5cfb3df56360254a0c7d38c6344910ecde613deb51a005f922d66ae8a8
odf4/ocs-rhel9-operator@sha256:2c70d4f70f7d21c402aa20fb5cf968589aa9a12c15551e199901a601084d4d8e
odf4/odf-cli-rhel9@sha256:5566ede2e45c6e5523ef656988868ea7b02f5baf239cf92e89dfe6db33c29a4d
odf4/odf-console-rhel9@sha256:759ccad38c6b3ece20d0a661792c36a5229b4a19fd627e34fa5bb407f34765c6
odf4/odf-cosi-sidecar-rhel9@sha256:896652abdaabdb81a2a20dad5fb18317c320be732f055005b5a382c57da61f40
odf4/odf-csi-addons-operator-bundle@sha256:5ba812d72ac76cfed90238a2296f213a9e3dea87c22eff84456621ffad134c91
odf4/odf-csi-addons-rhel9-operator@sha256:aafcd624387c80fe60aac74999bc4f98b11cc3193dc7fb3a5d1f5afba432ddd4
odf4/odf-csi-addons-sidecar-rhel9@sha256:5255f6cd1328bfa55aff1cb195bf32de7d9e6958e9f6aafd01d5bafbd695f87f
odf4/odf-multicluster-console-rhel9@sha256:741ff10d382bc5f463a2bd17d947ae09286505613f96aa128b93437c8e4ac5d2
odf4/odf-multicluster-operator-bundle@sha256:3cc3014d4ca49252b7ad428c5ad8e8cafc26fcc4b1934f1080a650c2d05df5db
odf4/odf-multicluster-rhel9-operator@sha256:c2ab2a1aa3601481cd020d793a32db6db0ecfe4a8528e1a08c47f3e2d71e755c
odf4/odf-must-gather-rhel9@sha256:591e5953a695f221e2fc56bd0f7e8b5d941551dda5e130eb8871f67c23e807e2
odf4/odf-operator-bundle@sha256:52f89973825cc34b3080fcfe6f384f683a0a0cbae1f411231a278aa3ece24b08
odf4/odf-prometheus-operator-bundle@sha256:04805fc27256939958af1ffb59b47252ed61101ae664d8d71d62bcd17d22e1f4
odf4/odf-rhel9-operator@sha256:77f56d984f1be209f3294adb59231e822051ce93f84872e5114b30151e0d33d0
odf4/odr-cluster-operator-bundle@sha256:b0356798393d9fd89896cfe4011d1f67ff237ac4024cca0a3ac7537d29aa3e2b
odf4/odr-hub-operator-bundle@sha256:4af7d40d1015fbdf3ee40c5d94b967eee19ca9b5b58aa9ff556c5b1195c5f870
odf4/odr-recipe-operator-bundle@sha256:51216f383041cbfb638d3ed638b23b2d6dfcb8613446482f23dd3eafd2328185
odf4/odr-rhel9-operator@sha256:4ba36bfc5977113b43ebd6d42322ac5de6735bd004b61c0339b000f95d4def9c
odf4/rook-ceph-operator-bundle@sha256:ca07d884ec386e595e4992df95f20df988712cd039d39cf39a482c00d3c4c0e6
odf4/rook-ceph-rhel9-operator@sha256:2e4dbde9ed937b1fff1fc9bb0625133f9c7075e0e11dbc903f0045262d72e190

x86_64

odf4/cephcsi-operator-bundle@sha256:d7690d04be35c5f14bd4c4d77e463e6fd462683aa5bfe1dccef844600441e021
odf4/cephcsi-rhel9@sha256:cd10c218e8398523fffd8710a2245b1ccb7df6c8c30e0864dd6afcc72a4defdc
odf4/cephcsi-rhel9-operator@sha256:aa3535655f828b6138b5b1f4f3c435afb4d47c1293deea7d34fb3d2a0e0c97ef
odf4/mcg-core-rhel9@sha256:5102738ac58fb4af057da51a651e320f44e10b506a170b9ad78df2f31b6eda25
odf4/mcg-operator-bundle@sha256:dd5a29213b5b9df50000e9b8476234c6dda06f4ba383ac39ca18dce9558d4c8d
odf4/mcg-rhel9-operator@sha256:e7bec2888fe97a7b880125f9b1947ec6d973cb0cf2721e8195af9b5465d999fb
odf4/ocs-client-console-rhel9@sha256:a6482714c4a1e0b9c5222a3316cc196e364a76aaaa1951c2b003115312b7ddc8
odf4/ocs-client-operator-bundle@sha256:57dd45d8082fc07d4153dc18ec3470e6ff6435fb4241b28e98dd1016bb8868d3
odf4/ocs-client-rhel9-operator@sha256:2879ac6ec566472c7e11314d82fc3af35fb2ad80e327f87bfc2935dfa7a7ebee
odf4/ocs-metrics-exporter-rhel9@sha256:e8b5b92e87ef30629cfdad5b578781722cc49895077d11b23ad8563e46cab6ca
odf4/ocs-operator-bundle@sha256:669d75517733c5d316b6ee869537fd119cbfdbdda388c03265a6ac87a8146f63
odf4/ocs-rhel9-operator@sha256:12270f1aae2f96473b554089c0587e5c3d7c200b4f58dbce395e63fba2d00a1e
odf4/odf-cli-rhel9@sha256:6ae43e76662b18eb98e1a4b4b6335908e0c0af68a7a06ec02048e213cc9161fe
odf4/odf-console-rhel9@sha256:b85663d38f955903b4e13e1fae79141952b0285b3b8f14ec3e059b4d4008575f
odf4/odf-cosi-sidecar-rhel9@sha256:17ac0bf348cd9267bc70cfd4eed1a5c83f46ea950ee19e8b639a542e20df8991
odf4/odf-csi-addons-operator-bundle@sha256:46836a4246848679f42817538a74e31bf7ba2e8e9c9f2e49552dd89a91747e1d
odf4/odf-csi-addons-rhel9-operator@sha256:70dd217b9700887b6de6d10015f4d665c2dc7217e461899e086441b2e6f80ad3
odf4/odf-csi-addons-sidecar-rhel9@sha256:f69e44e5cca62ddf8d6fa6894efa3294c16e5741b52c7e1eea6c7cb5c99ef3a2
odf4/odf-multicluster-console-rhel9@sha256:8bba409b33b95f1f2ecbf35def39b9337a829b75fd9feef1c98ae02de98eafc5
odf4/odf-multicluster-operator-bundle@sha256:24317a0acf6b60efd072ebff3e03df47eaaac0c2414da0f6f18507d436326f05
odf4/odf-multicluster-rhel9-operator@sha256:2c8c93b46936a09e45584cc930da93aa8de298013f3d3bf99eb33f493bc96bcc
odf4/odf-must-gather-rhel9@sha256:4a6459b196b8fab24d9f9d0cec41995129c0dd91d46d5522141e9475d99a55d5
odf4/odf-operator-bundle@sha256:8a9d791ad460bdc87a80687feb179608dc24f89dd87f75a8c5ec7d4cdbca6df9
odf4/odf-prometheus-operator-bundle@sha256:dbaa8b2d3ebc3d9dbe9d124e29856b383b678781782247630007de09ac555042
odf4/odf-rhel9-operator@sha256:43ffcff554c1a1ad7e524c1e882c257261860c1255b1482be79aa0af33d7becf
odf4/odr-cluster-operator-bundle@sha256:1a6c8d076d92afc1a0d57ae1a3d2a8f605cb26da489d9ddacecbe74552daa7b0
odf4/odr-hub-operator-bundle@sha256:adf0c8cbc58310b672cca18022fc6fea7ef076eace1919b897b8419624891ce7
odf4/odr-recipe-operator-bundle@sha256:604bf2079a4babdda6749fdfacf14564523bbfbaf07ca4a7fbe1f6faa92f64fa
odf4/odr-rhel9-operator@sha256:bacbd90b604be8ca94a04084be0a603b0fd01e984488eb6db1cc2f0f322d6db9
odf4/rook-ceph-operator-bundle@sha256:e6b54b07f0d590b883649f3123640858237b116e4c0164bd0934076f2cfdcfd1
odf4/rook-ceph-rhel9-operator@sha256:1095f6178493f0c30faaad4f6fbb3f11ebb2ef4968d15a99e90a0a32f363c5b0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility