Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:3502 - Security Advisory
Issued:
2025-04-01
Updated:
2025-04-01

RHSA-2025:3502 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHODF-4.16-RHEL-9 security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for RHODF-4.16-RHEL-9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • DFBUGS-1671 - [Critical] Upgrade ceph version to RHCEPH-7.1z3 at ODF-4.16.9
  • DFBUGS-1011 - dataloss due to the concurrent RPC calls (occurrence is very low)
  • DFBUGS-978 - [Clone to 4.16][2315666] [Stretch cluster] Network Fence for non-graceful node shutdown taint blocked volume mount on surviving zone
  • DFBUGS-945 - [2311546] [release-4.16] Object bucket claim creation triggers an admission webhook warning

CVEs

  • CVE-2024-11187
  • CVE-2024-45338
  • CVE-2024-56171
  • CVE-2025-1244
  • CVE-2025-24928

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-core-rhel9@sha256:068a72256237bdd0a579b3aa76fc4bf37930b1f048ae6c3eb72f44c2f4599ee4
odf4/mcg-rhel9-operator@sha256:2960acdb44de44e4bc26f222f16c9fef9dca561ab90b3c088da822dcfbda0a7c
odf4/ocs-client-rhel9-operator@sha256:4f0fb6d02abae76a35f386dab1b2250bfe632a3c7a36a68688407d205b886ea2
odf4/ocs-rhel9-operator@sha256:c09589e1e0deb7e952806d235c1037f5c6e90d5eb037c9b7585f2dfbe2d53968
odf4/odf-cli-rhel9@sha256:85ea82a8bcbbb0e39e5b8b5535f2468d3d61ab1507548acf9ba2a89777382483
odf4/odf-csi-addons-rhel9-operator@sha256:27c832da54d32ada85fff3fb7d04d733143a1df7cb2e419b355191c1d91d1540
odf4/odf-csi-addons-sidecar-rhel9@sha256:71a8e62888c5d7522d44045b373595ec4188c7946d60f1e2c8eb0f0e93954a03
odf4/odf-multicluster-rhel9-operator@sha256:3527b74ae473b71b54fc4dcf53d247688ba11cc8656d7e96200b120bb2087f56
odf4/odf-must-gather-rhel9@sha256:c2b68542390a7e4336da0147eb19dfc1b5104a4be9fdfbce0f383d2e3c6012ab
odf4/odf-rhel9-operator@sha256:1973a2cc13ee9a32f8fa426511c69804821cd92a3f778ede9dc1dad3070132db
odf4/odr-rhel9-operator@sha256:f9dea8ea9ecae53cce167218abbe0b354279d8bb73115312ef413653d91d21f3

ppc64le

odf4/cephcsi-rhel9@sha256:f9a4390a3de6eb274c185a1cc3382b6c10a29b16d39de6f59df316b2d7a85ad4
odf4/mcg-core-rhel9@sha256:698896a47d4fd9f1bddf8fb1fb22b99f6eaec3c9591815e25e120e7df1844ae6
odf4/mcg-operator-bundle@sha256:a8c32134d2cb1a5db655586f65bd1fac568b010bc1f7697069b83e7c245f29af
odf4/mcg-rhel9-operator@sha256:f7c64b8539be7e027bac1547ece04653976d5bea6ead519b2ed6499de7180dbe
odf4/ocs-client-console-rhel9@sha256:409becedde385970154269f5dc84ac7961e219a1956930a14aa68183fb80fb49
odf4/ocs-client-operator-bundle@sha256:e677334c3782188f6aafb252308c9a1c8db6101b0bba4b79f3662b9c3804350a
odf4/ocs-client-rhel9-operator@sha256:ac83a0734f93025f3ab42ee520e0445240d043a4775664c6d44a87c7fac71d68
odf4/ocs-metrics-exporter-rhel9@sha256:bb2f890d57d4341eff0476325eadce481f38dd0bccb8f5f9974f61220bbce44f
odf4/ocs-operator-bundle@sha256:d648a6305dab917bc9094481a84bd0521bd48cac367670b6a723c6d59e9ec4d8
odf4/ocs-rhel9-operator@sha256:18ede0783538a2037a6b090c3e9c7ebeed3361f6594f865303e51677cf228e90
odf4/odf-cli-rhel9@sha256:78f071161808fcf3a228a8fe8bd2c8de1beb49a3963ef5efc589e45cff1a02a6
odf4/odf-console-rhel9@sha256:c766a6b85cd3bef81bc6f626589b569695d1742c1f961c4175a742de8dfc9712
odf4/odf-cosi-sidecar-rhel9@sha256:afe5fffaa37933af2ac55390ed46d37a277bdfafb63f504645b9d29bd23b6e30
odf4/odf-csi-addons-operator-bundle@sha256:d0a94174a1cdec08532959658b4dfe0e9adafb83314f69d4902c0b93e6ad4798
odf4/odf-csi-addons-rhel9-operator@sha256:088c5f7549320be94fcfe1d759a6c0b12b82b0eb2c7ad7ea8a65533db3c701d2
odf4/odf-csi-addons-sidecar-rhel9@sha256:13700b4ed1c50daa091652fd7b74779c06249ac21b9a741574bb5069b000f16b
odf4/odf-multicluster-console-rhel9@sha256:28075f58315b04c3aa4c9f4a23689c76f4645837ef6eae79cc3633f389610407
odf4/odf-multicluster-operator-bundle@sha256:42f94d2ec5d022c829bec6b88624b27ec21c444fe5c19396ce248dbb0582cd82
odf4/odf-multicluster-rhel9-operator@sha256:e83d5ec4974bedfb763845ea371c74f050cb38ba8bd8a9c7416dae502a7af87e
odf4/odf-must-gather-rhel9@sha256:2d0383fe62f6636118612bcb987ce484a4131656b27a31bcc1ee6299ff51a813
odf4/odf-operator-bundle@sha256:af735766b79a34a3bde546255f3a54b08b4ffc2c5a45e071cd887bf40a9f51b4
odf4/odf-prometheus-operator-bundle@sha256:a1d9cc4aff1553cdd490cdbbf49d927edf9320dfabc8327571805c04c87f1120
odf4/odf-rhel9-operator@sha256:d917d45adf63e8659d589eee79ccb9d1623252b7339b1e93524b7dea229c8f09
odf4/odr-cluster-operator-bundle@sha256:9dfbd7fb7a6ca22a2a7f18cf4ec5c9539d30879db0623798d1ec8e4f5eb84dcc
odf4/odr-hub-operator-bundle@sha256:08f5697d5460d1e509bfb4bf4b177e79a68c52b55cf693aa15b49a3951f972cf
odf4/odr-recipe-operator-bundle@sha256:36292e60b543154590ff245f4c4b233b8ad5857c7bac5fa0c45fa161500df1b2
odf4/odr-rhel9-operator@sha256:3466ff8766747872e8cb3c7d4e388e95bc93375509ee81076884e27b51875ef8
odf4/rook-ceph-operator-bundle@sha256:7e846eac9b45ddae80fd7bbd24f92809554c1b4c0fd915ff67ed5e1d08dd5c93
odf4/rook-ceph-rhel9-operator@sha256:80a4e57074bf6bd9cd8fd1e0beeddebe6d6e0986c9c0a9fe8839268341763e2e

s390x

odf4/cephcsi-rhel9@sha256:4a1de6a1af1b47680caa36a69c6a8b438d01a0810f4df1d9dbb8fc82f8e06284
odf4/mcg-core-rhel9@sha256:10fedd0456d7f81015f93e597932cb19b3576a5bffd95de325f160c44f78cfca
odf4/mcg-operator-bundle@sha256:b2b86eea9f1808e65ee3bfb0daad68e470bbe9d2525adcaff08d4fde8e52b4f0
odf4/mcg-rhel9-operator@sha256:0b7a3d603a5275d83492747cfa071cb626001938b174847619cf343b1fcd81b3
odf4/ocs-client-console-rhel9@sha256:52c70b591ad9bcaca488d0338b82c11fbccd63762f5fad40119d4e8419ded145
odf4/ocs-client-operator-bundle@sha256:3a07afbc05696f593190e75aabe6f32416d03574df873367458a62676409caf8
odf4/ocs-client-rhel9-operator@sha256:6d1dc63e8040cbd6e82514ded593540a16f4dde956b04d88649551a4333e7616
odf4/ocs-metrics-exporter-rhel9@sha256:a0f521d4f1ac22e066a109ae38ae11e248195f9520c3730e5053b27da5e7eafd
odf4/ocs-operator-bundle@sha256:fcc77519a4cc442b1bd61e5606efb35a4afc4fe6dc93e8093c2f306b3b5faacd
odf4/ocs-rhel9-operator@sha256:9df0962604f30ad2dd9861675ed4018ec4e1847d645a5f395a9755bfc3dcf74c
odf4/odf-cli-rhel9@sha256:10aa2a02209ef8f37238f873edde98369e15e738b2a7b80099be4b2b8647edbc
odf4/odf-console-rhel9@sha256:74b5fae3ab9b1cb951f533e9717e8dddf74cc20dbdbffa7753498fd851429392
odf4/odf-cosi-sidecar-rhel9@sha256:0f13b14109bbebcb40bdcd8f0fdfd7f61a25ea7f39af746644b0861c7ff49626
odf4/odf-csi-addons-operator-bundle@sha256:d2bff2e8f293034a8a7d80a063d35d5ba3fdc279b0d03440c1d2a47ff2606adf
odf4/odf-csi-addons-rhel9-operator@sha256:d2ae76ccd354cc34c46be21f3ba074fcfa1ebbdf7b32f4c61c4f45e55c23f270
odf4/odf-csi-addons-sidecar-rhel9@sha256:fb501c55629dc8f44267c6813a84d111cb3c98bf5185a04fddd41c4f47f05621
odf4/odf-multicluster-console-rhel9@sha256:f65ebe3bc2af885f04ac47d94d676a4bd95fb6534a24a9d436c215dbe40c41ad
odf4/odf-multicluster-operator-bundle@sha256:137909bdc89b6e2b6bc672333ab53ff56ebc0695311c5df09266f793bf4e81aa
odf4/odf-multicluster-rhel9-operator@sha256:20322293ce1012ddae0f395d5604e38a815e5da109bd11ac11e635c1773b1522
odf4/odf-must-gather-rhel9@sha256:53913fa206b297eb4e93d54efd6e0c3935a6b700f6c34cd9995d5483a855c854
odf4/odf-operator-bundle@sha256:d900dff1d730a61b9f1eb78f4902bd233113216973874cd0c77e2d27b249dadb
odf4/odf-prometheus-operator-bundle@sha256:c8c04af9ba9c10d8c32ac3c7004ba0c4ccf0c14ac683a1a685e97669ee387cca
odf4/odf-rhel9-operator@sha256:6850637e14d8acc7f88cd2b2c936b52ca66af159d7f97d37608da66cbfdcc825
odf4/odr-cluster-operator-bundle@sha256:c34e9f57958dc3bec472ee9b91ea31503fd939b07faae596677a36d7d73d3b59
odf4/odr-hub-operator-bundle@sha256:4d22347dbd2f7c1e243b440304e05f2749d88888924e913b661ce8fe4e219496
odf4/odr-recipe-operator-bundle@sha256:5045c0a773df2d4bff134934a4b61b3ed3653bce4bf1224495f71c14d0e34c7d
odf4/odr-rhel9-operator@sha256:6ea22220e927607742e39622db5fcaf52bd03bd363db7c41d9e6b869c305859b
odf4/rook-ceph-operator-bundle@sha256:a115350e444d74bd30b86b6f8d9a2c15f28ab5418cbf1fe599c2251b043708b8
odf4/rook-ceph-rhel9-operator@sha256:e388f3c0faa2505b6960c815043477034012d79660c3e5fdcc24b2272b93f218

x86_64

odf4/cephcsi-rhel9@sha256:1cf35f815de351a2c37340f850101d5b108fea0c4e5619a98080840ef3552e0e
odf4/mcg-core-rhel9@sha256:b0f34ed1b4c0f9a4176fd959d929c3755508ce881e431c2c2069428847ed76e7
odf4/mcg-operator-bundle@sha256:d7f607b353806840c3a2fb9fb02e5a96cd83e6747f67deb73ed0875df76828e0
odf4/mcg-rhel9-operator@sha256:a815540a133b0864ba427bf5f5a8153dd3e316bb39bbbbf464511fc0732782fd
odf4/ocs-client-console-rhel9@sha256:a06f898fe1be5935accc20fd1ee6a1e29f2350297e36ef7392392a359d4f7c47
odf4/ocs-client-operator-bundle@sha256:7b86fe3d3ac9ef7df8a851c7c1f24eb8212f4c8640bfbe1dbf25ca13e8754cb3
odf4/ocs-client-rhel9-operator@sha256:cea3919db348953e14f270af58a711c7073ad65ad4fbc375d80117fbabf936da
odf4/ocs-metrics-exporter-rhel9@sha256:1b602bb5459440906a466e9687301dc3c1233264de86498c94f26581060f9033
odf4/ocs-operator-bundle@sha256:8682c22f78b4e5b7d7a9ece542f02ec7d6172ccfcd85e82dfcbeb9c81fe7a6dd
odf4/ocs-rhel9-operator@sha256:087bffeeca3ed6f80ae7674c5a147b27a2f1feba965acbb27379c438c9686f91
odf4/odf-cli-rhel9@sha256:bb1aec4a92322116499401febc6982178deee5e989fd68a9635d9b31f7dd8db2
odf4/odf-console-rhel9@sha256:8eed4974c6b9dedd5cb4f7ff1027908ad4ab8274dafffa00f12eb9c63a15d288
odf4/odf-cosi-sidecar-rhel9@sha256:d5b01a44782ed114af0d96a357faa2ce00950194f8a6c63a37081bb3bfa8550e
odf4/odf-csi-addons-operator-bundle@sha256:fa43d6f2db3e6da5f5ae82a14b8631fdefee1ece7e8c714ca78d467b79f3b4a0
odf4/odf-csi-addons-rhel9-operator@sha256:9a83557ae92af7bf8ca4c687aee1ba82311acf55c98b17fc44dff6e8206f4c7e
odf4/odf-csi-addons-sidecar-rhel9@sha256:65d1d96f56293f276c8574363d872c8c89686e3a61ee577cb4393165e9bbac0f
odf4/odf-multicluster-console-rhel9@sha256:31dc2d31b429e63fe599141392370e529b597e41e3b6bd9da387eba8971cedeb
odf4/odf-multicluster-operator-bundle@sha256:951633082e542b42ec641cd9866518da79cfddafa069ef189281e2d580728c5d
odf4/odf-multicluster-rhel9-operator@sha256:8ec79d06669ee36eae6d6c2ed3ef835934ca6b5d6d27fc1ba524e17c5a2df2e3
odf4/odf-must-gather-rhel9@sha256:ea8f5dd86da91bd16a2b79a011dcbdc975383fdc736a19867d42e6318c691552
odf4/odf-operator-bundle@sha256:e58f88c021243d4616127c177bd9c0aeabca99e8e57e0648311d3fde0c192dcb
odf4/odf-prometheus-operator-bundle@sha256:f30254e9df41cf4049cc7b35610abd0a716a13f41a1c4523fc1e7bf2211085b0
odf4/odf-rhel9-operator@sha256:c75a9897a89243b793642d1d5918a666b08b465797212cfa29022a8fcbeb358e
odf4/odr-cluster-operator-bundle@sha256:601fbb866efcab2fec4a675094cfe1d5259b6e475f9e6dadda69fc21cc178aee
odf4/odr-hub-operator-bundle@sha256:1823f0fa1f0bf3097fa61cf9fa7dd6c591d43c7443942538ae126b6ab4d59653
odf4/odr-recipe-operator-bundle@sha256:424de07f469a52d905d50a126e0d0c48e5c2a8bfcc5fa6be37f4b0c806cf50b5
odf4/odr-rhel9-operator@sha256:c98e251621146b479822a517c9556bd9e49c8dc57b4afccede822aac5699b37a
odf4/rook-ceph-operator-bundle@sha256:04751a4c128f21d5f1ec2ddae1107ceb5902ed63fd705441dc7280ea66c8941b
odf4/rook-ceph-rhel9-operator@sha256:666b25c348e6275207b9bb2ef6ca1cf109fa935fd7d2dead4a764b5d7d243392

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility