Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:3542 - Security Advisory
Issued:
2025-04-02
Updated:
2025-04-02

RHSA-2025:3542 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHODF-4.15-RHEL-9 security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for RHODF-4.15-RHEL-9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)
  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2331720 - CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • DFBUGS-1345 - [Critical] Upgrade ceph version to RHCEPH-7.1z3 at ODF-4.15.13
  • DFBUGS-979 - [Clone to 4.15][2315666] [Stretch cluster] Network Fence for non-graceful node shutdown taint blocked volume mount on surviving zone
  • DFBUGS-944 - [2311546] [release-4.15] Object bucket claim creation triggers an admission webhook warning
  • DFBUGS-913 - dataloss due to the concurrent RPC calls (occurrence is very low)

CVEs

  • CVE-2024-11187
  • CVE-2024-45337
  • CVE-2024-45338
  • CVE-2024-56171
  • CVE-2025-1244
  • CVE-2025-24855
  • CVE-2025-24928

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-core-rhel9@sha256:cd37fe49d2702c78a87c7299f5192ed1cc11c1178b8b633f7dced80f3b946fc3
odf4/mcg-rhel9-operator@sha256:86347d437ac659fbba7ca5d630f67d6dfaf9b96b24bbe0d74353bcf5dea0c593
odf4/ocs-client-rhel9-operator@sha256:0a0d42d05ca14802c5fe8c2d9482cdcdf21e77ef27bd03a8237fe36d268d4b8d
odf4/ocs-rhel9-operator@sha256:e53a5a6beacd5f4b0a261086c3cd8320bca975293d19bd44e722ac027541f323
odf4/odf-cli-rhel9@sha256:c5acbd09ea84230e79e08d0091fbe0da17ce8e0905f1d9c46c2d6efab26f9d78
odf4/odf-csi-addons-rhel9-operator@sha256:7134af93863a6bd4b0b5bb11d86d0397d5d3bde79b71e8981f4e27550141e2e9
odf4/odf-csi-addons-sidecar-rhel9@sha256:f178e112ab8db833aec6e85c48227604cde25ec02b0e1a8a291efa959afcf7e1
odf4/odf-multicluster-rhel9-operator@sha256:5fb6dc48aedd9ca60676f5f3e81b9fe9060fb4c62d22bae50da3c0ba09bf4f2f
odf4/odf-must-gather-rhel9@sha256:2e25f7fd188cd070d77a85f41f9b59d9471ba6dbef4dbdfc0df7b34f87bc605c
odf4/odf-rhel9-operator@sha256:d13a6ec8126d862628abdeb4a98f4cb6c177e10856c347d118ec2ce02a550055
odf4/odr-rhel9-operator@sha256:d824b7fb9d7e36f008ce9541fd945aaa22042ad25360ccb2e50e81bc2b75522d

ppc64le

odf4/cephcsi-rhel9@sha256:6d47ae3d82057f74c134d0991aec82f792fc5f5e8be68c2cd355e839ed164cbe
odf4/mcg-core-rhel9@sha256:039d7784c93a2432dfdb38db7685c74c49b58add758fc3a89eadf0d0b0e449a5
odf4/mcg-operator-bundle@sha256:5e2db5f8ef6366f227c564fc9ded923ad0d6c3b190113e480d3eb2165ef82c5d
odf4/mcg-rhel9-operator@sha256:90ea93b88a80e33ab56e8fa4ae37ce34b8bef80281824dc27c4427355a4cd0d4
odf4/ocs-client-console-rhel9@sha256:f60a40d72b734d429221ae60ec638a2ff3db1227ac46aefc2f6268dd9e0f6659
odf4/ocs-client-operator-bundle@sha256:c81ab813061a01f78cfd4c278f0dfee3c8dc15f04c87d924eae9866adf020309
odf4/ocs-client-rhel9-operator@sha256:c3a22d7caa7ef8da08ceea2593f7ea3c5fd20d6de387f5c108deaec0ef482b7b
odf4/ocs-metrics-exporter-rhel9@sha256:063ce7011522181d92e55998f9130d7e1cf757831f6682e5a2bd30abf76e2661
odf4/ocs-operator-bundle@sha256:84d7c1cb1faf9589c057b938d731ddeb0b57f9a376cef5069ba49b14a95e9891
odf4/ocs-rhel9-operator@sha256:f74dafa055278595d6d57309d392cb5dd5ad238ae8963ca8bdaeb21b6cb5bc2e
odf4/odf-cli-rhel9@sha256:78e677cce335b1df23da8911e6f989876b82deea6e5a53420c25caf5ac72edea
odf4/odf-console-rhel9@sha256:a945d69d070e0a5358d8451fcc50e67ca77b09f946c46bd2b1419fc5f38fb37a
odf4/odf-cosi-sidecar-rhel9@sha256:d8a9b21e27185f57c6da96846f74cfac9d3361d8c7ce4805bdb89d4edc6c1b29
odf4/odf-csi-addons-operator-bundle@sha256:450915fa93b94ccbbf053e62df503b53537435a3f41a0c38198f78ea1e94b80b
odf4/odf-csi-addons-rhel9-operator@sha256:59b2a8b5c61d30b627a66348614df3bbd9a39f2b31c9b15dc69e665c23eb15bf
odf4/odf-csi-addons-sidecar-rhel9@sha256:7c39222532f3d3247432d439f179f457eb55748b1d252173692b5feb50aa03a4
odf4/odf-multicluster-console-rhel9@sha256:cc50af7805f11da9c2820bc3cd6258b3d739878d82faf38debed2fbff3226643
odf4/odf-multicluster-operator-bundle@sha256:ed1f1d9c52cae74b9ba277d8b458235a6f889c6970939da5d14566a4df33ca9d
odf4/odf-multicluster-rhel9-operator@sha256:2b2335ac98fa4687353ab96055d5a11c15653e8ee61e102029b31d6b8eec7293
odf4/odf-must-gather-rhel9@sha256:ad4705d6e080d91c497d3d5d60694f0b3c867036977c7229a3321414e7a6c261
odf4/odf-operator-bundle@sha256:b48272102bd84914525944f43b25424ac8107684604c5467dc8fe8621567368c
odf4/odf-rhel9-operator@sha256:7208254fcdcdc8544cc7e14ed788fa481ae47fd574a3e72fc82ea3bd42b01e2e
odf4/odr-cluster-operator-bundle@sha256:1555cb387d9245294fb2a4a769d16850fa81d23c3cd37ae12db1b236958920bd
odf4/odr-hub-operator-bundle@sha256:16883eec33baacfd7397f06defdb64d7f6ae0a41ef1cfd9f4b8c3523687abe54
odf4/odr-rhel9-operator@sha256:efc7101ccfaee51eb247d19970a29d91c2163f570bfbc7cfb05ea9bc518500e1
odf4/rook-ceph-rhel9-operator@sha256:312d28ca82c64be6453547f52184a78f1096726ece096ed28e8059585842e796

s390x

odf4/cephcsi-rhel9@sha256:39987d89492b40620910dfea5bfcb4f5456faec3c5cc0f008cff3c62f48166de
odf4/mcg-core-rhel9@sha256:9132b7bae3bf3872f4cb2836136932d70a850ab04837a827d147bd007f61e907
odf4/mcg-operator-bundle@sha256:eabebc3a64689b08b82d49375f3c640574651a9ad3a3da75d250f92cd5dedb22
odf4/mcg-rhel9-operator@sha256:37a49dd28d4e4c70d67a5347df258ea7a0859224a1d648b04ff38b89aefead1f
odf4/ocs-client-console-rhel9@sha256:4d0a582844fc0a5da3de30ceeb47427f910c993aa76c8e29630e5a2125cf623c
odf4/ocs-client-operator-bundle@sha256:0c887785712767cecf50f89e09b194b1923082d8bdd5ed08f475c2f8335deb92
odf4/ocs-client-rhel9-operator@sha256:6dbbea183818a69e56b739b5434515008f9beeeab2a19b1de62f93ed21b40a41
odf4/ocs-metrics-exporter-rhel9@sha256:a83fb46285e3e5fb176799edbb7b58f75db44bee6e5bce5009b58d08f742bf5b
odf4/ocs-operator-bundle@sha256:4f46fc1c076c375fc15a7ef7aca1a9cd06a1dc783835ebec9b9dbd5bffe4fecf
odf4/ocs-rhel9-operator@sha256:5424e130fb363a582a73e9b6168323bf02c68a52b2d57fe6d08a8f15eb9329c6
odf4/odf-cli-rhel9@sha256:37964ea86c613e085111c1412f1eee7132c026aed976ae6cf8c34893af1294eb
odf4/odf-console-rhel9@sha256:36755587f839b2c47adaf398c2346743e25038c436daac7e7253b799ff8e690a
odf4/odf-cosi-sidecar-rhel9@sha256:ebe97465d3cd4574d2129e3ab38774bd38d450380e422d36be434dc1453d672e
odf4/odf-csi-addons-operator-bundle@sha256:f97ff3b4f983ddd30285d8e8c0816b47f93b3e389791363d14d2e912bfc7606b
odf4/odf-csi-addons-rhel9-operator@sha256:e04b7692f5d0bd0d48d990807c6d1c55ca2a7f284c3b48aa557aa9f11b841920
odf4/odf-csi-addons-sidecar-rhel9@sha256:869c78d037b918ed96f8288c189dffb3a73a2e056ca210483c7ef98866bbbfb8
odf4/odf-multicluster-console-rhel9@sha256:c20ff224739974a68d1397ee45520d0d1d00af115b0f8777a8a8ffb70811762f
odf4/odf-multicluster-operator-bundle@sha256:5ee30837a0b18143ed4410a879449197df831aa9da3f9e34d984bba54ea4933a
odf4/odf-multicluster-rhel9-operator@sha256:fbbb03b4b3860e0781ab33f33cfbaca2191d1ee2b8ab60b63cc1ffa7630a2932
odf4/odf-must-gather-rhel9@sha256:1e8cda9bda7d3a47b07a9174e08d1859b1c1205ca81d5951ee80987e7bd93e09
odf4/odf-operator-bundle@sha256:b9eac319261085e82a1ef2257560e6c42c75cbb93ea28c9a35687d1141e02b2d
odf4/odf-rhel9-operator@sha256:303719e90364646b758fb09b7d794fe3df667b433238e7eb5608fb1a68f0a916
odf4/odr-cluster-operator-bundle@sha256:38ecc809db4dc7555c1802e36be5d77e40c8e808039c4b39dff6c31477c213c0
odf4/odr-hub-operator-bundle@sha256:102ecaa53a174455c8392a9e221dd0f332613fc0c0e206182c4c483cbd7f9ff3
odf4/odr-rhel9-operator@sha256:ed32cb24e244040bb13d1ec5a8413e12c739f5ba8b184b885eb8838a32da6b63
odf4/rook-ceph-rhel9-operator@sha256:2bdda576e27f6b8688c4083845f5127643fd7c7d70e2873e2d8cb4074d02e3ce

x86_64

odf4/cephcsi-rhel9@sha256:dfa7a6da4c316172b117a80ca6d4dccd173193baa5207ac052dfcf16bd6e0649
odf4/mcg-core-rhel9@sha256:9ea768460f8017cbe5d2d48897be95d35ef8a415c6da84152517b55d7d27b584
odf4/mcg-operator-bundle@sha256:54996beca536094a30d924c43e3a52ff615437e08b0bfae28589194819bb7e7b
odf4/mcg-rhel9-operator@sha256:aff6272b9ae5b95a1552173fa28b00c3bd26ab001357fcd92beab2b4e82998f9
odf4/ocs-client-console-rhel9@sha256:8282a7990053ea1bfbbfcb2f58ded06dead846e4074c512a57065f6c9fe824f1
odf4/ocs-client-operator-bundle@sha256:76ff157ecf4135855e29b7cb6752512a54ad2f9b7d42337b4e5a0635003cccd7
odf4/ocs-client-rhel9-operator@sha256:6d76e5388f91606338eb730c7ab757352ec2c0e163c02222014262d953667810
odf4/ocs-metrics-exporter-rhel9@sha256:0af8d8f55c93aadd0bef2a6a092e972187e8cb020de54a0a6f547d7ecd7646e5
odf4/ocs-operator-bundle@sha256:47ae26a5548ad25ea602bf92cabee281fe76ad55cc5bb20878b7073a64a3b2d0
odf4/ocs-rhel9-operator@sha256:1a72b27098021c575f6720904963fb19f928c7c5e33928fdca909f17df513b98
odf4/odf-cli-rhel9@sha256:33b558053565e3839dbcd52f590aec522f64f43eb606379ba95cca46b67e24da
odf4/odf-console-rhel9@sha256:5d6e5a1075757bb435cb692024d2958e2292331a517d1032b65d2268036f3788
odf4/odf-cosi-sidecar-rhel9@sha256:dd2ca2b97888416c8b80afea093b72448dc86629bb1c639e9678c2c692e0ec39
odf4/odf-csi-addons-operator-bundle@sha256:7227150cea2a8adcc29e12b3da59587aa1a6c52a32cdd48c41c3a81b613b91cd
odf4/odf-csi-addons-rhel9-operator@sha256:040b6e9c9955e329a0f402f59e713609191700a064add10fd1a2a5f9e8e8a1aa
odf4/odf-csi-addons-sidecar-rhel9@sha256:cd913d30a4e7c6a65df4ae0415fa3fa2d945ae298b4cdb0f27f74205a7499814
odf4/odf-multicluster-console-rhel9@sha256:8f07f45728be81becd927d81513d1a4eb9cf119730f6104910519fd896c44f94
odf4/odf-multicluster-operator-bundle@sha256:6aadd2e1cbe192ec68406bdf96a3125b2b408ee1544b5379fee049d711c0ec7c
odf4/odf-multicluster-rhel9-operator@sha256:18cc0feb72e3373314a76d955ee7658f5ebfa2d7626a604a5a71cb0a6d377a99
odf4/odf-must-gather-rhel9@sha256:1d0044891f122b29fe37da51ba2058b0e35f40bcf382750d5953f2fa747df2e3
odf4/odf-operator-bundle@sha256:64bfb313027c6795160078915c238bc77379781c7316ba251cb3c762cdfd5c35
odf4/odf-rhel9-operator@sha256:58f4a8de4884bfafab44af61ed88de7ee89910e89607d0305a10c9f75400f877
odf4/odr-cluster-operator-bundle@sha256:b6277c661f62a2693a3dd522c555a3f9b7dc4f109f7eca7f6b77b4f662deef2c
odf4/odr-hub-operator-bundle@sha256:69c1d64898f84bfea2cf8d732560c529dea09a5e9cabe5a6d490dced46b8d565
odf4/odr-rhel9-operator@sha256:4c55cf259697e6add1bf6c007069e9c9662113c5ce1fad721bca824598d04e6f
odf4/rook-ceph-rhel9-operator@sha256:30c4ba553c28e92404dc3d608737573754afdd3bb36b9f8647b2d778d4dd9ae3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility