Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0842 - Security Advisory
Issued:
2025-02-06
Updated:
2025-02-06

RHSA-2025:0842 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: OpenShift Container Platform 4.14.46 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat OpenShift Container Platform release 4.14.46 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.14.

Red Hat Product Security has rated this update as having a security impact of IMPORTANT. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.46. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:0840

Security Fix(es):

  • jinja2: Jinja has a sandbox breakout through malicious filenames

(CVE-2024-56201)

  • jinja2: Jinja has a sandbox breakout through indirect reference to format

method (CVE-2024-56326)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.14 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.14 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.14 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.14 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 8 aarch64

Fixes

  • BZ - 2333854 - CVE-2024-56201 jinja2: Jinja has a sandbox breakout through malicious filenames
  • BZ - 2333856 - CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method

CVEs

  • CVE-2024-56201
  • CVE-2024-56326

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 4.14 for RHEL 9

SRPM
crun-1.17-2.rhaos4.14.el9.src.rpm SHA-256: 61777685334ee8e0a75078d47b310ff404185ee01f914abce38849321f2963f0
python-jinja2-3.0.1-6.el9.2.src.rpm SHA-256: 108b7d5c2da35219cf4e3b44d99ca0a4ea157d7b735b44bff3d2ff8e4d43ff43
x86_64
crun-1.17-2.rhaos4.14.el9.x86_64.rpm SHA-256: 93d1393368c041f2a9aa96ea286206ab7d9907afd5ec0fda284a7fa8ae591093
crun-debuginfo-1.17-2.rhaos4.14.el9.x86_64.rpm SHA-256: 230247e3445abb8c12d40ad6c10319e65db09f3755831e145fd5b684097ffe51
crun-debugsource-1.17-2.rhaos4.14.el9.x86_64.rpm SHA-256: 7238d0f089906ef560586339beba1b66c19d64c39e0e0fece1a5805a4837da7e
python3-jinja2-3.0.1-6.el9.2.noarch.rpm SHA-256: ace6417e1989ec79f51847ac37f1fddde4707d392ccdf1fabc084f8f2c6cb734

Red Hat OpenShift Container Platform 4.14 for RHEL 8

SRPM
crun-1.17-2.rhaos4.14.el8.src.rpm SHA-256: 31a94d2857f6b93c634ed4c9195ab15cb578d74b7746485e29b7a858f3435a53
x86_64
crun-1.17-2.rhaos4.14.el8.x86_64.rpm SHA-256: 251d667c569acc1938f56b608b8e8beb80a2fb81e791b9739a2cdbf7e58a27a0
crun-debuginfo-1.17-2.rhaos4.14.el8.x86_64.rpm SHA-256: cb73b42ace6ecfdb74066a897cb89fc02b61adc83d6044618ec565f39bc8167a
crun-debugsource-1.17-2.rhaos4.14.el8.x86_64.rpm SHA-256: 51eb5b45cec0c60d96a81e4c1a19ed7a8e8b8a13a8603134c31cb6e7a4744442

Red Hat OpenShift Container Platform for Power 4.14 for RHEL 9

SRPM
crun-1.17-2.rhaos4.14.el9.src.rpm SHA-256: 61777685334ee8e0a75078d47b310ff404185ee01f914abce38849321f2963f0
python-jinja2-3.0.1-6.el9.2.src.rpm SHA-256: 108b7d5c2da35219cf4e3b44d99ca0a4ea157d7b735b44bff3d2ff8e4d43ff43
ppc64le
crun-1.17-2.rhaos4.14.el9.ppc64le.rpm SHA-256: a25f1dd1cd9a2335a7f94b05b744cf6fd03dfb28b2a874db98d4010213bd73ca
crun-debuginfo-1.17-2.rhaos4.14.el9.ppc64le.rpm SHA-256: 84b0106e17d84dc4b6478369fc6e7e28eb1e4e17871f0108e5d766811fe2340b
crun-debugsource-1.17-2.rhaos4.14.el9.ppc64le.rpm SHA-256: 9e468049a0077eb35765b4a4af850fe52c2e794e17b5055c800bf4b299426a2b
python3-jinja2-3.0.1-6.el9.2.noarch.rpm SHA-256: ace6417e1989ec79f51847ac37f1fddde4707d392ccdf1fabc084f8f2c6cb734

Red Hat OpenShift Container Platform for Power 4.14 for RHEL 8

SRPM
crun-1.17-2.rhaos4.14.el8.src.rpm SHA-256: 31a94d2857f6b93c634ed4c9195ab15cb578d74b7746485e29b7a858f3435a53
ppc64le
crun-1.17-2.rhaos4.14.el8.ppc64le.rpm SHA-256: 6067beaa083e4a1c77edc13625abaacf073f9856dd45d28198ca96c82b21adde
crun-debuginfo-1.17-2.rhaos4.14.el8.ppc64le.rpm SHA-256: 8331fac3606f556cdaa9774017c6f8f74502f7b919e5bd09d1d69cb68457d460
crun-debugsource-1.17-2.rhaos4.14.el8.ppc64le.rpm SHA-256: 2b772a4b0e217098a16208e1814bc1fc158f851b96b95ab4604db8069362398d

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 9

SRPM
crun-1.17-2.rhaos4.14.el9.src.rpm SHA-256: 61777685334ee8e0a75078d47b310ff404185ee01f914abce38849321f2963f0
python-jinja2-3.0.1-6.el9.2.src.rpm SHA-256: 108b7d5c2da35219cf4e3b44d99ca0a4ea157d7b735b44bff3d2ff8e4d43ff43
s390x
crun-1.17-2.rhaos4.14.el9.s390x.rpm SHA-256: 4d8627eca29300e5e6c618f16e674475f46de21ba1096556e977bb2e777284b7
crun-debuginfo-1.17-2.rhaos4.14.el9.s390x.rpm SHA-256: 0d0e26dd0359fd45f346739a6c03d0de1b8f43b9a119d56a5f789c6a282f0ba6
crun-debugsource-1.17-2.rhaos4.14.el9.s390x.rpm SHA-256: a2e5aee8159cfe4f4a54c9f3199156a6db5992f001902456bc37129981d6c5e7
python3-jinja2-3.0.1-6.el9.2.noarch.rpm SHA-256: ace6417e1989ec79f51847ac37f1fddde4707d392ccdf1fabc084f8f2c6cb734

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 8

SRPM
crun-1.17-2.rhaos4.14.el8.src.rpm SHA-256: 31a94d2857f6b93c634ed4c9195ab15cb578d74b7746485e29b7a858f3435a53
s390x
crun-1.17-2.rhaos4.14.el8.s390x.rpm SHA-256: 161094da7a774a5fd95de52557d972713eae03ef276b169d87414f95fbffdd64
crun-debuginfo-1.17-2.rhaos4.14.el8.s390x.rpm SHA-256: f6106ef57eccdf24bd68ed1d816f44919c7c4e0f0930784761b34a7c92e5210e
crun-debugsource-1.17-2.rhaos4.14.el8.s390x.rpm SHA-256: eafef60300045357a90d6d32e4ceef40559203bd17e4ee5cf38a580751751c5d

Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 9

SRPM
crun-1.17-2.rhaos4.14.el9.src.rpm SHA-256: 61777685334ee8e0a75078d47b310ff404185ee01f914abce38849321f2963f0
python-jinja2-3.0.1-6.el9.2.src.rpm SHA-256: 108b7d5c2da35219cf4e3b44d99ca0a4ea157d7b735b44bff3d2ff8e4d43ff43
aarch64
crun-1.17-2.rhaos4.14.el9.aarch64.rpm SHA-256: e2f98f35fbc8c816f089fbdc306332e03b58a2a1c6e8210ca5707cbc08cab3fd
crun-debuginfo-1.17-2.rhaos4.14.el9.aarch64.rpm SHA-256: 965ca9a645f39ca78d8f2e854e4cbf68dd3f58b3fdc400f1f17c9c7dc430aac8
crun-debugsource-1.17-2.rhaos4.14.el9.aarch64.rpm SHA-256: 6c868a63c68a9de4c550f9ea4bfec232f78d4e90e811bf4092b40cb812a61eaf
python3-jinja2-3.0.1-6.el9.2.noarch.rpm SHA-256: ace6417e1989ec79f51847ac37f1fddde4707d392ccdf1fabc084f8f2c6cb734

Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 8

SRPM
crun-1.17-2.rhaos4.14.el8.src.rpm SHA-256: 31a94d2857f6b93c634ed4c9195ab15cb578d74b7746485e29b7a858f3435a53
aarch64
crun-1.17-2.rhaos4.14.el8.aarch64.rpm SHA-256: 8dbafa8f7a39bd721eb82e38d5642b2ac4e2431b19e6c8d90d4b9badfbadc4aa
crun-debuginfo-1.17-2.rhaos4.14.el8.aarch64.rpm SHA-256: 94cd3398c6e03c79c3b5c9892941e1ed5756fd2ca38d553c8f95129fb8bbfe5e
crun-debugsource-1.17-2.rhaos4.14.el8.aarch64.rpm SHA-256: 4e97cdbcbab39253efe84e86940ed93d413997d5f335411accf05d4bdbc6c5fd

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility