Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:2696 - Security Advisory
Issued:
2025-03-19
Updated:
2025-03-19

RHSA-2025:2696 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.17.21 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.17.21 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.17.

Red Hat Product Security has rated this update as having a security impact of important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.21. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2025:2698

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

Security Fix(es):

  • kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy

and Mbox devices (CVE-2024-53197)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Solution

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as follows:

(For x86_64 architecture)
The image digest is sha256:875094103228a685ab9c2159f5bb97455a823d137e9da09bfd0e00af9296b042

(For s390x architecture)
The image digest is sha256:e58f5fcf5e47bd00bf0bc0eb73b4d16e0da066062e7034e387f5dbc4c574ed7c

(For ppc64le architecture)
The image digest is sha256:f016b55cf94d5b24de70ca8e708ee30caa176a668e747bfae4578c8b9ac2238c

(For aarch64 architecture)
The image digest is sha256:1dbe1293475e6ac71e35301542a9e017a624e27ea17309194ed70439722092ac

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Affected Products

  • Red Hat OpenShift Container Platform 4.17 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.17 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 8 aarch64

Fixes

  • BZ - 2334412 - CVE-2024-53197 kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
  • OCPBUGS-42387 - DataImage owned by deleted BareMetalHost is still present after BareMetalHost deletion
  • OCPBUGS-46440 - HyperShift CEL validation blocks ARM64 NodePool creation for non-AWS/Azure platforms
  • OCPBUGS-49795 - 'create a Project' button on Getting started page doesn't work
  • OCPBUGS-50589 - Upgrade failing because custom scc in version pod
  • OCPBUGS-51353 - Unexpected Permissions in `cluster-reader` ClusterRole in OpenShift 4.16
  • OCPBUGS-52205 - Show Observe section without PROMETHEUS and MONITORING flags
  • OCPBUGS-52292 - [4.17] runlogwatch in ironic-image is broken
  • OCPBUGS-52497 - [release-4.17] Add runbook_url for CoreDNSErrorsHigh
  • OCPBUGS-52657 - The trusted-ca-bundle-managed ConfigMap requirement breaks those with their own PKI

CVEs

  • CVE-2021-47497
  • CVE-2023-52520
  • CVE-2023-52615
  • CVE-2023-52922
  • CVE-2024-26603
  • CVE-2024-26744
  • CVE-2024-35801
  • CVE-2024-43830
  • CVE-2024-50302
  • CVE-2024-53197

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/driver-toolkit-rhel9@sha256:721a5d0f95e7a75f04af0d5661829a98a5105ce0018cde470b8f4025d79cb348
openshift4/network-tools-rhel9@sha256:100768530d6cad43836826a0fc63c32cdf9e60a1205a1a646542fc4781d5871a
openshift4/ose-baremetal-rhel9-operator@sha256:d25fc1db14915fb0f782033f8264e562d57686549da2fe324c431858ed98e60f
openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:47e87dd6956db481b60f7bff93c3012cb9922c6747a4037bef32d527b3c9c197
openshift4/ose-cluster-dns-rhel9-operator@sha256:42600082a39a044940f0604a98b836b8cbc85e9f6e0a735ef0b229064f3c25cd
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:118711d19ebbcb3921a03d663cb39182cce4b6edd0f3958938ad4ef7aeb5e83e
openshift4/ose-cluster-version-rhel9-operator@sha256:9042105599d9071ff207be3b2424a0f746e4131f6c589e847bde37dd7df389cc
openshift4/ose-console-rhel9@sha256:7b94107c57440c1718d030ca99ba9e080f375660709ce9c5a4a90a62808d3986
openshift4/ose-hypershift-rhel9@sha256:0cb7448a14da0ebc32167c38c2918d96fa7dfa456600f1eaec2c5a1baea5ab6d
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:2cae4581c005c88234aed41f805c584c185c4f6958d2ab4be795fb9ff09afa51
openshift4/ose-ironic-rhel9@sha256:35dadac47566594f20209d769a26250173f592a49bdf58bf72d1b5d2f1ba3c28
openshift4/ose-machine-api-provider-aws-rhel9@sha256:03496dcd33b829ae076477ae857742d314e3404e622ea78e2f03ae9e72bd8dcc
openshift4/ose-machine-api-provider-azure-rhel9@sha256:589dc304d1bf82d52b8ddae630161c067651d9bcb8ad4705906bc5053d552bd3
openshift4/ose-machine-api-provider-gcp-rhel9@sha256:59ab2a8be62d7f1c299d112649b03bd0db038c3126809a309242dd6e7034f376
openshift4/ose-machine-api-provider-openstack-rhel9@sha256:9d08b6b702963a98263e373a4e23cf538a03a0bb7a47c508df39a953e2d8030c
openshift4/ose-machine-api-rhel9-operator@sha256:4ce7fd5e808fa955e044c629513c46cd4fed05cb18dace243cdded28d057cb89
openshift4/ose-machine-config-rhel9-operator@sha256:bc1b704990e4f8f89d79693267119053d4142a3a09d673293027c0b404deaa7e
openshift4/ose-monitoring-plugin-rhel9@sha256:4f03d9470b08bc26a539ee9eebb15059b022dda587d2c7c8a064d1afc0f656ca
openshift4/ose-networking-console-plugin-rhel9@sha256:fff4391b9a3e86c18e99f04a1c85170dd46d4b95bcba2b348da3e4bdee1c47ac
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:def8fc6db3808a805f089bfcbd7c7c528dee7af6d9c6d21098caa13809563c8a
openshift4/ose-ovn-kubernetes-rhel9@sha256:505af81c9555014dd3b3c4c4129f9122a37c208fc0b1857066841468533a3ac3
openshift4/ose-tests-rhel9@sha256:f2e3026872049a6f47fc67d95dfb94208a1f812f4571d20a4620966f744106f9
openshift4/ose-tools-rhel9@sha256:ed8385517c6c64755299cbe6633b46dbe71c46e97f07561383a38de2167c3896

ppc64le

openshift4/driver-toolkit-rhel9@sha256:539afbf44d727657eb54b8ba7d1e7a0ca2dc992eea15d530414c08bcbf99cd73
openshift4/network-tools-rhel9@sha256:e13231fa9485833c5702b861d609007cfbc291c93477c4e963f1c036546caa14
openshift4/ose-baremetal-rhel9-operator@sha256:ebe22bd66aa177b365ecb51ca498859c147233eb86f6f1085247491983642513
openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:d4a51253f0ed5d130792a9af04ccf82e21f63ecb217ad1ed2d1b428b7e1fe801
openshift4/ose-cluster-dns-rhel9-operator@sha256:7e69a7f575bd9261db3bfbc99402e97161d6afd235ef6c2e9427278a92687da2
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d328efc0a49a71d1c9015f1f411bbd5376fcf53d367df040e01b6d993ce1aab0
openshift4/ose-cluster-version-rhel9-operator@sha256:10b0fe5c484a7bd1e1ea8e4f574187b8791555a7560fe2122802fb117b813687
openshift4/ose-console-rhel9@sha256:7b96f01459bff0c89ad2b95fb240d67110cee89981423dbb415167ea6093dab4
openshift4/ose-hypershift-rhel9@sha256:072cec37935dc0df0548c927eb71681831c23f5f656d7c5d76afa777ef426ba3
openshift4/ose-machine-api-provider-gcp-rhel9@sha256:b71667c7cd5ac5e4a0d2b83ffa00d7e747c420337149b1b9acc58c5b11713f5c
openshift4/ose-machine-api-provider-openstack-rhel9@sha256:9fba70d0c7e036f72ab912d357ad1f0d8ab698162bf440b99c5d11e4776d5ce3
openshift4/ose-machine-api-rhel9-operator@sha256:dff229fd564924c3841e0a6775e994c3b52ef189c539574fd59b53c3a9c7b41a
openshift4/ose-machine-config-rhel9-operator@sha256:8a79ea87b1bd4af8da2424e89bac7cc0fb44ded85ad44bb4813aba99cb2e1650
openshift4/ose-monitoring-plugin-rhel9@sha256:489f1adda7ee0d49c99a1334fc8dc67f7e3ae6c7b564fdd43d1c7298463a3a82
openshift4/ose-networking-console-plugin-rhel9@sha256:3a678b5bddf8cf08c64ecbdde2f266ba643d78b9cdb161f9e2c2d8a9f900d0db
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:6fc7ac96d788d4ea9a1b89c1c8b98b2f68eee1e6f6cf0e84fbb9d56a4af3116f
openshift4/ose-ovn-kubernetes-rhel9@sha256:6bda5b5c5fbc0dc824121e7efab2c9abdaa50801a7094a7e23ae44a3f8dfd466
openshift4/ose-tests-rhel9@sha256:f7cb54b9d1681a4247c51a60800797bf1153d1ad219325e53ab4afcc94a8e5b0
openshift4/ose-tools-rhel9@sha256:86aea55ec869c7fdc89d4a84e465bca05d5b3c66dd72548ce67c4e5323853d0d

s390x

openshift4/driver-toolkit-rhel9@sha256:bfd381eb29635ac73ed5d8df1dd2a5f834ec09a7a3eeca98b52a5fa7ef0a696b
openshift4/network-tools-rhel9@sha256:d0597f671a242a77c5f5c071c5688ac5d6c9eaca6d61a523166fbfed8d842b58
openshift4/ose-baremetal-rhel9-operator@sha256:6dd22b43db9a2dcacca35795d023bd1d6d6331a1c9d1be353abfe6fab8755742
openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:9f57e3f3233575051c73b379518e6d4dedbb8439a256ba366e3925e694c87e3b
openshift4/ose-cluster-dns-rhel9-operator@sha256:61dd0c1337a508b074fbe8333d9382191b16e19a61dd3fdc67de0c72cfe1b0c5
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4e9a613f0d36a1ad64673247f8cf86a85f7e2fd0faf800223c3be2ffe5676d28
openshift4/ose-cluster-version-rhel9-operator@sha256:77a11ed62cfe3433e32d7a4869cbebce26a91168cbcd5756cfbb57aecda45232
openshift4/ose-console-rhel9@sha256:f44a84278fa25804ce12091829b7e2c91caa4dfd0104ee4719a17a97f075c889
openshift4/ose-hypershift-rhel9@sha256:277d223f9a8ef0be71bb744f0c7350457b19db4d6748037b1b3f7665d0661ede
openshift4/ose-machine-api-provider-openstack-rhel9@sha256:edc36b322a4b81987198cf221931c101f815c49fca6a6e6793f6de40fb2b7e0b
openshift4/ose-machine-api-rhel9-operator@sha256:44a6d8e15ea59a92fd896eb69be8d2375e627d2213ddf884fe6e655e2cb3fb3a
openshift4/ose-machine-config-rhel9-operator@sha256:2a886350173f9a0e87227c64aa7cc249b8fc0809b902b949ac1dcfb1e93fb425
openshift4/ose-monitoring-plugin-rhel9@sha256:37589059c091689a41ee8e48dbdd433e629156b258c5064b07a5fc90c383b98b
openshift4/ose-networking-console-plugin-rhel9@sha256:5de0c8f534a7499b1772a1bc60da0f0ea8febe0862d3c5ff33bb699c58336500
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:05124a245823825ca7b3d8819a428606d48a50f5d99962b7d58e83f4ce164210
openshift4/ose-ovn-kubernetes-rhel9@sha256:c29d9fb805b4137b460fdf29e1a05186f7cbc475b1d1e7d0e68a2abbc58682ff
openshift4/ose-tests-rhel9@sha256:aaac50ea156d926436c4facf4c6441cc7ee855ebabc4119b26cb7170d378da91
openshift4/ose-tools-rhel9@sha256:6554a4935882f7d5c064b6a87cb5872e53d6733a55408139fc1c96eade15eff6

x86_64

openshift4/driver-toolkit-rhel9@sha256:bce72b5d72965531809e7424d271390575a0696896af4841290b30cdd54e1984
openshift4/network-tools-rhel9@sha256:8648c92dbbbf1ebbee711a4800f1224f63e9478d5c3bccaab48637c080701274
openshift4/ose-baremetal-rhel9-operator@sha256:c7801fe20f1ee79b01050b7ae052af34aa92bfee3ef277e11a1e4c6dcaefc059
openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:6ca2097cdea9e3a2cab0b917de06ff3d1722f73f7cf81b9df25acdf779030b34
openshift4/ose-cluster-dns-rhel9-operator@sha256:8cddad35e161c977d4be85debf3296db4afb7c303ed30db170a05dd040baacd9
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:f316395585ddf5564691724235ecdb64087f6ee7b466e64b5495ca2e89dcf555
openshift4/ose-cluster-version-rhel9-operator@sha256:68d7fadefdf43ea96cd6b58dc6b886b3f3052115d2fbb6af3e19ff7c30343e4c
openshift4/ose-console-rhel9@sha256:a9afe0d712cab33cceb0a4818e9ef4d95a09daf9d753f51b9117c3050e5ae9da
openshift4/ose-hypershift-rhel9@sha256:0124e058f5266ca800074f0c241af2b7be4a50870e66a10a226e331b9f5719c8
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:55fbe3a93e167cd774f1c114f99b3e21a8ff56035af238b01963eef31e7742e6
openshift4/ose-ironic-rhel9@sha256:797681bb1edf041587cc9404baeb0c8e333f8a58787d45e0d3e2a63eed6dc333
openshift4/ose-machine-api-provider-aws-rhel9@sha256:1695a01b9680566efb61b43a80395eb90e3edc57decf59ec6f4e44e938eee195
openshift4/ose-machine-api-provider-azure-rhel9@sha256:3666e08a55fff7ac13b3083ccdb4608116897108f82468c2c86d2bd975649191
openshift4/ose-machine-api-provider-gcp-rhel9@sha256:d76526a9ae2770b2bb84d451b7d22739f06d82ea9120d8cebd1bcaa2a5044fe4
openshift4/ose-machine-api-provider-openstack-rhel9@sha256:e87f458f1b18ff2aed479e4a7c800c2788fb9270ca65e7b3db0ed00464f7f762
openshift4/ose-machine-api-rhel9-operator@sha256:4b0b9f7da485412606b685c22f892cf4c15f7dba47d1999f33b03c6748f20d8c
openshift4/ose-machine-config-rhel9-operator@sha256:93d98bbaa7ee6052bc26973d6dd4ab342397b03a12ca1f6252b8b752d5285b9f
openshift4/ose-monitoring-plugin-rhel9@sha256:fdacf3a87bf26df7c21ec1200b046f985ff609f492b88e8c777ba3a796480203
openshift4/ose-networking-console-plugin-rhel9@sha256:3ceb5465874ed75b4a6314aeb5945ed265eb3ace5de26c83ecdfdf2675ab459e
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:bcdd6ab0c327b94bdf05af7c4ce60dd1bd3347fdf25f967d95a7666c39b0d49c
openshift4/ose-ovn-kubernetes-rhel9@sha256:7aec3879e052732a639515597e5c7d50e01a92f850c5afd03242f8ae8559cb40
openshift4/ose-tests-rhel9@sha256:dd91590deac108a085aeefeb83dcd63f29aa44763c85d98abbea8dd20e0a03da
openshift4/ose-tools-rhel9@sha256:038d2dc9a10a7d9a166e8b2603107cb4b5e507667ab6b94652beeb46841856a4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility