Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1119 - Security Advisory
Issued:
2025-02-11
Updated:
2025-02-11

RHSA-2025:1119 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.17.16 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.17.16 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.17.

Red Hat Product Security has rated this update as having a security impact of IMPORTANT. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.17.16. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:1120

Security Fix(es):

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in

golang.org/x/net/html (CVE-2024-45338)

  • go-git: argument injection via the URL field (CVE-2025-21613)
  • go-git: go-git clients vulnerable to DoS via maliciously crafted Git

server replies (CVE-2025-21614)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.17 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.17 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 8 aarch64

Fixes

  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • BZ - 2335888 - CVE-2025-21613 go-git: argument injection via the URL field
  • BZ - 2335901 - CVE-2025-21614 go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies

CVEs

  • CVE-2024-45338
  • CVE-2025-21613
  • CVE-2025-21614

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/kube-compare-artifacts-rhel9@sha256:a7b9531a56599925170d1c7be52958fb834ecad88468547639c0060d948ce912
openshift4/metallb-rhel9-operator@sha256:5ee9294a12e5d60b15ee0838b3cd6b87410834d2b3b597cef6da1d41a447a2de
openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:251dae2f76d2ac3b1a13212b2203528d9cbb10f7b6bc783ecc33a0c34015a085
openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:28bf4960766b3cfab26714a276d101ca93eca2d943f84bb1b71fd8a9992cebdd
openshift4/ose-helm-rhel9-operator@sha256:038f137f7c4e6ba3220328bae057c41bd9f6385fbf6afb6da2cf1946cc03e6b7
openshift4/ose-local-storage-mustgather-rhel9@sha256:8ab84769bcf9d725e71dc48d2943cab3565716423443dc29d922b2ef043f07cc
openshift4/ose-local-storage-rhel9-operator@sha256:8bfe6ace2f4be3848ea204a705d791d0f2bfb966909a538f22c828728238d319
openshift4/ose-operator-sdk-rhel9@sha256:24c0960f3e30a43373e26c8929c17b9cbe2d721e97ee17603f13045a494261ba
openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:162a63f77d89e235e2f53a979e25f7e4a1ee5f4de1bb686b09d881cd2d8436e0
openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:400a9ac28ef61e7b6c25ce939183eb60f634a44990f0d0654f47d8ff781b229e
openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a901c4f12ab7640b85283c54dc059001cf4dbcfb93d89fc0c110d21361b72bfb
openshift4/ose-sriov-network-rhel9-operator@sha256:61f68218f0fd1915221cf2418d6d20be07bb2a6f21ae021af2949c2a103b3464
openshift4/ose-sriov-network-webhook-rhel9@sha256:4167166e84ee00b0bb93313175b6adde4a792a0a5f2d9d7dca395f6a98042f98
openshift4/ptp-must-gather-rhel9@sha256:7632d692fae57120e2a6149a3a95fc70e45b17c993bf7e258a120aef54ec4573

ppc64le

openshift4/kube-compare-artifacts-rhel9@sha256:8f4d8e5228319e911902337fd482515ddc7de156cb491d30edb36894dc690a3d
openshift4/metallb-rhel9-operator@sha256:bed43aaabe0c0c4c1d0cac6f8c2fdf4ed48d3428bf9edf738c2450a65a54855c
openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:2c9493a94535682db564c76d3f9d21cc707075a0c6aed619a01ca0fcbc297031
openshift4/ose-helm-rhel9-operator@sha256:ec75c80a4825b3646ec061e3a125706f7a6edf986d66680e2fafdbfeaeebfbd6
openshift4/ose-local-storage-mustgather-rhel9@sha256:18a4daaaf65f9b34eadae4fdd3bc82c3145d7a286b7169f3851762f14a55d878
openshift4/ose-local-storage-rhel9-operator@sha256:52aed7ccf1d821c1b1779cbdbc72d092117f48aa8b8f3967d757c2e8966279b3
openshift4/ose-operator-sdk-rhel9@sha256:6c9b5daf583445bfd83ae87d3dd655e8eecb795a819ec4a07b90c02a413ffc88
openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:d957a9db284d307030e2455e6216ae49f920970800ced74056f25dbc0b52892b
openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:4f8c2267177f03d350feaaa243b505a26c14ba7cd182ef12cd5484689c6097dc
openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a1e5aed89962552881d38c933a53a816b8655ca4c856507996561dade257227d
openshift4/ose-sriov-network-rhel9-operator@sha256:bb6d4fbe8a74475cc96641403448ec11e12b05ed1dc888c847a1b091cf19ba75
openshift4/ose-sriov-network-webhook-rhel9@sha256:e2c3c17b739d8139b100f64a059aabae9d99a4469886104847604c9fd34e963c
openshift4/ptp-must-gather-rhel9@sha256:f4eea6f36a70212372061a6b1271cb35a4ce31ffc879348388ffee6514cb1c10

s390x

openshift4/kube-compare-artifacts-rhel9@sha256:8af8dfa63a2a891244144b4c0dbd47970f15b3795393b8aa19bcd21f0b9f8eb0
openshift4/metallb-rhel9-operator@sha256:ad79ec41f761e8f44955f623b760fb01955bcee48afa20c17d0f362349372cf4
openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:dac7a47f140321bdc554325a34c77cf5369d399834240a7959482fbb25b52ef7
openshift4/ose-helm-rhel9-operator@sha256:036293189bfd0cfbb075fa212edf98077ade272388a5812ef7f3feee2ffab9d7
openshift4/ose-local-storage-mustgather-rhel9@sha256:a1f0b7e5b8b1f7d9790ffd56173da47f1c5cbf1dc188216f722ca7d6f4286998
openshift4/ose-local-storage-rhel9-operator@sha256:7cde8ea58b6bca97a66b4f55ce8a9fccd567f869288c0574e2cbd28c343cf45f
openshift4/ose-operator-sdk-rhel9@sha256:8b40e9a56b60055f670a4fcc4da4a093c85d006e48053e7cd83a068aa653b724
openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:de94c0c57c6ff2a340d0882f2593c1130d8f8b1f64d98adba87c257466ad122d
openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:b9b7055ef70367f723208cdc886f29388a9deb2cf3ec231ea27fbbfedc3f1f7f

x86_64

openshift4/kube-compare-artifacts-rhel9@sha256:1a4b823bb17287ae51b3d7770e0f14975b962276383573db6c2d79d1a9fd9636
openshift4/metallb-rhel9-operator@sha256:589538372b29dafb22e90bfd2ddbf245b6d6b57eb5f00be241e6770793ba7022
openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:4e41138d77ce09c459970d0de4fa53b72eaf62da154e389bf18ab6d70b1f63fc
openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:5ce6d1d8275af12f5beebd50a26923ee2a3eaaf34f94b3c4115c0648253fbcb5
openshift4/ose-helm-rhel9-operator@sha256:dc9a97a71651e3c04cd461ce230555b5a4cb28e101cfd59bc01ed6da19c4e6a6
openshift4/ose-local-storage-mustgather-rhel9@sha256:f0651fe33f20e08fae754e0c28e08dab068b5c6afd310dd977d7b2e2fa2df7a6
openshift4/ose-local-storage-rhel9-operator@sha256:0d82e58b547202652165d35e053e299f121ae6cfcc3c850faffeec2181d74db7
openshift4/ose-operator-sdk-rhel9@sha256:e3205b40d1b837d61d3fef16c2d304a7302bc05fa30d0d53fcf2d64dd597cbf7
openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:ba31ff7bd93b1aca21517cd2f603e9beb39a502c2c217eec5832d7a76c9e2db6
openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:0674da22998057a50fefcf32f4e479f3df939d17fece1ea5de7b0db5e0088b47
openshift4/ose-sriov-network-config-daemon-rhel9@sha256:ac31d5883efa317fa0b5181382acc6790118c052e4db58a2e89b4b65b0fa6be0
openshift4/ose-sriov-network-rhel9-operator@sha256:12312e2e88530b7fbef5815ff8cfc264f8cd2cb3134b2562746e206c810b22d9
openshift4/ose-sriov-network-webhook-rhel9@sha256:f2e16bd06fe8a98901d1f13439a417d2b95bea2e7a5ad811db2628de4a024dd3
openshift4/ptp-must-gather-rhel9@sha256:f455859949594480bcb9b8e394343f85824197857b25e759905b22e6215e493f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility