Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2025:17376 - Security Advisory
发布:
2025-10-06
已更新:
2025-10-06

RHSA-2025:17376 - Security Advisory

  • 概述
  • 更新的镜像

概述

Important: Red Hat build of Cryostat 4.0.3: new RHEL 9 container image security update

类型/严重性

Security Advisory: Important

标题

New Red Hat build of Cryostat 4.0.3 on RHEL 9 container images are now available.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

The Cryostat 4 on RHEL 9 container images have been updated to fix several bugs.

Users of Cryostat 4 on RHEL 9 container images are advised to upgrade to these updated images, which contain backported patches to fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

Security Fix(es):

  • tar-fs: tar-fs symlink validation bypass (CVE-2025-59343)

You can find images updated by this advisory in the Red Hat Container Catalog (see the References section).

解决方案

You can download the Cryostat 4 on RHEL 9 container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).

Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally.

受影响的产品

  • Cryostat 4 x86_64

修复

  • BZ - 2397901 - CVE-2025-59343 tar-fs: tar-fs symlink validation bypass

CVE

  • CVE-2025-6395
  • CVE-2025-32988
  • CVE-2025-32989
  • CVE-2025-32990
  • CVE-2025-59343

参考

  • https://access.redhat.com/security/updates/classification/#important

aarch64

cryostat/cryostat-agent-init-rhel9@sha256:9463aed19da3b03a12bed39c6050bec99463e10065ee372b67816213a045c6f4
cryostat/cryostat-db-rhel9@sha256:f21352681262b8d7671383fad5ac0318ceffce84ad863072a4b9dd90a2f152e2
cryostat/cryostat-grafana-dashboard-rhel9@sha256:7a7bb95ea5e6a42221586653da0bf950f8aca246ac3615d09fd6679d4b13e07b
cryostat/cryostat-openshift-console-plugin-rhel9@sha256:50b56388f16ff8d9d54e0cf24e6169e21426725fa4bf7e7846191fb75b746aa1
cryostat/cryostat-operator-bundle@sha256:935d3968b95d7712f35efe8a60e45160ef8fdac687632f34edc447f22eb9e764
cryostat/cryostat-ose-oauth-proxy-rhel9@sha256:7f1ccbfe7c19ffbc43c864afa0f3265aaca55156b0dc37b35258941c5cefa467
cryostat/cryostat-reports-rhel9@sha256:b31a398c301bf937e3b32779990106e83514d78d880d468f52248c28a0804844
cryostat/cryostat-rhel9@sha256:cf45d23bb2e8064fb1f92335b9854bfc6d05a8ff82f93e19c6377b414c2cfba7
cryostat/cryostat-rhel9-operator@sha256:fe346c81d84d7919f0d15d0b3fc83a81274308b5e922347cb6d3c19e7137fa55
cryostat/cryostat-storage-rhel9@sha256:5735fe58a6bb76ca20fe83a7429bbe1ab0cc198d2f5248505c36bd13dfed54b9
cryostat/jfr-datasource-rhel9@sha256:78542cfcb567bc4c3766f7734a49b07485ec0283484878f16b3c3bb3ab0e4bd3

x86_64

cryostat/cryostat-agent-init-rhel9@sha256:f70b1ea3fc288d6054c8fd361e672849b35d8c4ae2ba844d7afe9fa4ae3e4d6f
cryostat/cryostat-db-rhel9@sha256:3f78daa87571d389f545698ccfafd7fb95e8acc88105bc26b89acd1f1d4604ec
cryostat/cryostat-grafana-dashboard-rhel9@sha256:d1336f0e9915a034b3156ab5bb1ee61fd479ceb5a16b9af95ea765998013222c
cryostat/cryostat-openshift-console-plugin-rhel9@sha256:35bde3754ad9ca1e81205f114c82d4a56f285057a61145909177a6cb65d29b9a
cryostat/cryostat-operator-bundle@sha256:dadf9b28a2d935a73c3daa6c26638ced5c433262a230d3a14ce1b4f2509244bc
cryostat/cryostat-ose-oauth-proxy-rhel9@sha256:287d87e4e5a80514270d9d3f3f0911bff5a965019445f2cbc3a354de87ee8fc8
cryostat/cryostat-reports-rhel9@sha256:3855e1063979608e04a443bb23061de41d40384de6a0cf97e773a9437e001e86
cryostat/cryostat-rhel9@sha256:a6c3b106d370130408da31aabe9719d7b9576275038b261fef2967b618faf03f
cryostat/cryostat-rhel9-operator@sha256:f93fb5a329f336d7221e457f33fea590d33b3f3a0d3817572ec6a3df4733492b
cryostat/cryostat-storage-rhel9@sha256:2b6db9665766c3d8320292ca3ff9840935e92f4d06acc4ec1abfd38d63b83b7d
cryostat/jfr-datasource-rhel9@sha256:ffcd3bb8792afadd97ac09e43c14cf5ee2da2688e0b9aa3e0839a411d87e688a

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility