Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:3560 - Security Advisory
Issued:
2025-04-03
Updated:
2025-04-03

RHSA-2025:3560 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHODF-4.14-RHEL-9 security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for RHODF-4.14-RHEL-9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)
  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2331720 - CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • DFBUGS-1672 - [Critical] Upgrade ceph version to RHCEPH-7.1z3 at ODF-4.14.17
  • DFBUGS-980 - [Clone to 4.14][2315666] [Stretch cluster] Network Fence for non-graceful node shutdown taint blocked volume mount on surviving zone
  • DFBUGS-914 - dataloss due to the concurrent RPC calls (occurrence is very low)

CVEs

  • CVE-2024-11187
  • CVE-2024-45337
  • CVE-2024-45338
  • CVE-2024-56171
  • CVE-2025-1244
  • CVE-2025-24855
  • CVE-2025-24928

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-cli-rhel9@sha256:9dc4eef7e8cff11cfe839d7e2162c35837ad9cdc35110667d6c38e35953f64c6
odf4/mcg-core-rhel9@sha256:6ba1c8be2c7a4b2868711e5d602a794fc6f37a0b162e43a990e3f434cdf0044d
odf4/mcg-rhel9-operator@sha256:457dadf63904e569adc44f7803bc68ef48a91a14eda8d7ede6ff2f1b85d6c328
odf4/ocs-client-rhel9-operator@sha256:d07a2e543f9d6fc673c89bba4ca4ef051dfc6c59a77868de9d8086ff9f923e88
odf4/ocs-rhel9-operator@sha256:bab9292348c97ea13be4ef8125107b6af68c16b862d9048589ed35cd883072f3
odf4/odf-csi-addons-rhel9-operator@sha256:42aac31311256868599022bceb0225ed8acedd1591ba55255122c954bd4346b4
odf4/odf-csi-addons-sidecar-rhel9@sha256:7e2a8ed76d0d6a8eeb15da107f3feab2c05336379615d9c136804e9e6d1bfc12
odf4/odf-multicluster-rhel9-operator@sha256:e8c762314f9f999ad8d113b6814fc25412cee0ad102b51e059b9282bb9d7df75
odf4/odf-must-gather-rhel9@sha256:93b2febe6c5614c27286f6c7c49b445d310bfe55a345b27380fb4126067926bb
odf4/odf-rhel9-operator@sha256:c243ce3e35d5b53c0aef562cfd3172a4cd7bcf74c089c6da8a70f19887a5e85c
odf4/odr-rhel9-operator@sha256:aad670bf97788c301af437b9dbe28377a062cc4b5f74c3f1e60951b32cf5bdb2

ppc64le

odf4/cephcsi-rhel9@sha256:acc3553f74e28e79aee4002f7f1bd274672b8ee86866fcf2a44b75666d499434
odf4/mcg-cli-rhel9@sha256:f8466123c3d888a8bfacad9367e3192a99b889bb512c9e40d69c0b00b2148989
odf4/mcg-core-rhel9@sha256:a1c20ae7ee43bd06021cefee3050f9ca2fe7e9f067c7bdf1bdd6b53dfc533038
odf4/mcg-operator-bundle@sha256:c6956ed3943f33674a897e501b65a36d6148a76a2d495101a0de205f06cabf9b
odf4/mcg-rhel9-operator@sha256:d117e6618f677d3e9c98a0fc3f6cc3a60361cfdbb33506c2607561c8a8c94eda
odf4/ocs-client-console-rhel9@sha256:1eea45ef55ccbf347341ee1b3a1bc796da7dcea9744f39d8fe996ef98be16860
odf4/ocs-client-operator-bundle@sha256:6f5ba9a0ba19e976054f339f22f18a73c3faea22df2eea9f71eba3dc48b40563
odf4/ocs-client-rhel9-operator@sha256:f4dc7ada5cd9c6e89a4fcc11f8386476db827f0946f986d49b1540029264b1ff
odf4/ocs-metrics-exporter-rhel9@sha256:1bee145861954a0a4136b42ab4489fc6fd79c8f1b330f2fc39862cc0a46fc830
odf4/ocs-operator-bundle@sha256:358960d56346472a6351d0e8d48bf9aafba868c65d96fc4113b468902bb58d2b
odf4/ocs-rhel9-operator@sha256:c60272213c4184fd7ab0692259a66cb505bf224b6e6c0c08cec1ea8a02dcabbb
odf4/odf-console-rhel9@sha256:20df1088e79e9bd16ebf48751811440cd8667e3c9f92734608b6f06551339c0a
odf4/odf-cosi-sidecar-rhel9@sha256:d13b487c7fc20a394532ed4ef1a2ab29876a6178971277c39d378efaa4d1c2ec
odf4/odf-csi-addons-operator-bundle@sha256:74342c8b5a6475d8f4192963321504c0167d287a890ba1b2ea1a70497f1f5dbe
odf4/odf-csi-addons-rhel9-operator@sha256:39f4170fdda7f6c6d9a4fb52057a1181bfbd9d5bd0aaeba47057915daf8f5d33
odf4/odf-csi-addons-sidecar-rhel9@sha256:2cdbdf40501fcc356ad5681b7dd64ff734db0b64dbc6968ae464c78834814d98
odf4/odf-multicluster-console-rhel9@sha256:53ca31a31cbc5eb76697ff8b4e061ce154c75da75bb269fd27fbf4b725cfc809
odf4/odf-multicluster-operator-bundle@sha256:820c5a297ec0ebf76eac82c042e5195ab21e3e93ccd58e4e464229a597f3f28d
odf4/odf-multicluster-rhel9-operator@sha256:261cd55bf4de02d4ca8253d050cf6a05330d42a3a71649cfb574c664116f49dd
odf4/odf-must-gather-rhel9@sha256:ecbf48f170244bb45337f0ee4757a0011cdf17bf56da49a4fc040d19fb3d54f5
odf4/odf-operator-bundle@sha256:670eb396ad25bd23a65bbcc05a3049fb8327aa106682524e98907321d194b5ff
odf4/odf-rhel9-operator@sha256:2b7c2749f0a18219dac1ef0532d734066d87003810be70b10c0e40905ed9ba77
odf4/odr-cluster-operator-bundle@sha256:965ea4d68d1edaff4ebbc961d93639dbce32acf6223a24378f72d167445dab83
odf4/odr-hub-operator-bundle@sha256:c83e5dd280e456c4ba90790d793d716fba85cdb3c45fcca6607ce1ed8d5b2542
odf4/odr-rhel9-operator@sha256:040a4c7622f9a4408e8d209fb87885415e79bd421a45de2547cbee1d64265379
odf4/rook-ceph-rhel9-operator@sha256:2aa4235e804c11a16ac9ef945790134848493d6c68ec59818f036c5ce20d74a8

s390x

odf4/cephcsi-rhel9@sha256:d83fc3642d9bd3a4e4630e2dac4fb561c6f7f7e727349f6b7d1f6edfa30dabcf
odf4/mcg-cli-rhel9@sha256:a89ebda472f7f4b0fba51d050d944014592fb2ed6d14b8fbfce1ceed849e988f
odf4/mcg-core-rhel9@sha256:8797421d8b1de01b8f797b4f7d31bd741c2dfa612c5de01bd34fe957476b2e91
odf4/mcg-operator-bundle@sha256:8d3cbcfe7dc3d7e8a3eb3b29fa6200dbf3d9cf3330ccbed1c1a078a5017b07a7
odf4/mcg-rhel9-operator@sha256:c5dc4d1542df960599b8f22218ef38bb849a806cc1d46d6e45a1a10255e7c8d3
odf4/ocs-client-console-rhel9@sha256:1a468c30509ca31644eefd8f529b8a44f5f7491b0862e80189b53a29abac0c43
odf4/ocs-client-operator-bundle@sha256:b258b9bbd6c60f50f5efc54acb6b67ba1aa9d28aac8f148ebcc49f14d09f90a9
odf4/ocs-client-rhel9-operator@sha256:239a8a479e05cdf4035ea8460d7a31cd3e4f148244f8b0f6f83997e992e319d3
odf4/ocs-metrics-exporter-rhel9@sha256:75ec57b5f25da941662411e6176b7ea0335f28cafd252d27fa7dda9fab991948
odf4/ocs-operator-bundle@sha256:7f1dce9abb8db51a33e89536330f5100c15aeb15cc399ee5b1a0786dc5f22dab
odf4/ocs-rhel9-operator@sha256:f2cf1c7f5f0f01735c5a6b5fd7933cebfeeb6705e72eb396c69f1f2073c59ec3
odf4/odf-console-rhel9@sha256:4c8672467bc7700a7b35f8b96719123a43e4e37844317cab1e24d362711a60ec
odf4/odf-cosi-sidecar-rhel9@sha256:92b7442ce15ff9d0c521269b456116ef84ad75385715c60a7d3c121fcd1f29f6
odf4/odf-csi-addons-operator-bundle@sha256:d2344483504bf0da9153ee8eb552d00f37c16b8ca9adaedf8f76eaf58f931a79
odf4/odf-csi-addons-rhel9-operator@sha256:f8c10ac336350424b46225e7e8ff5221075074c37063056e75d70e50b6fd4987
odf4/odf-csi-addons-sidecar-rhel9@sha256:8c98f31565bafa6d396af1f2d4e2b10078fb20420ee59969b17f70455611b90c
odf4/odf-multicluster-console-rhel9@sha256:6bedadb6458a45832d41e65799e1e28d23d5555a97929ec45e51c6b3e26644c2
odf4/odf-multicluster-operator-bundle@sha256:835e71c30e2eedae7eeadf695e800826a50310364f29edbb288385417e20c1ed
odf4/odf-multicluster-rhel9-operator@sha256:42c5ad8992906002d9f417b2f03bd46bd43d7ef96bf29d9281bd6684a83d83f2
odf4/odf-must-gather-rhel9@sha256:46cf77f7df2251085643694337d68b6169c23e51a7dc05181ad77b031134ec7e
odf4/odf-operator-bundle@sha256:635ba6d730df39baadee79858f9320596d9cc33db5efa5d62066987ef986e457
odf4/odf-rhel9-operator@sha256:9ea2ef36fc9569622225e4b03f001cbd8cedd0dc6aa5684a2618056a7a5e4cde
odf4/odr-cluster-operator-bundle@sha256:ec7b0b2e4590c387e764b9a8f9927ce379bb78ccd4e342fcaa73448f312935f7
odf4/odr-hub-operator-bundle@sha256:515dfb239cacdb0d4530780eea8eb769a5ae7176a0554fb445ee134250a2d96c
odf4/odr-rhel9-operator@sha256:e45ec88513685282a85811e44a673d3d69bc2355d1730bbd4ac6b139b394935b
odf4/rook-ceph-rhel9-operator@sha256:2a51684ca0bbfa735fe89dac6f3ada1c078a00fa5722c4bc5f57e98f918e4122

x86_64

odf4/cephcsi-rhel9@sha256:f4f1ecc0a229b3c9e427282b7710afd888bea44b67fc5d3a6198da11e5725de9
odf4/mcg-cli-rhel9@sha256:1ac748e433cb39c9bbd4e184ac960286462b0f7406f73d2945325a3c3c2e609a
odf4/mcg-core-rhel9@sha256:0b9649ae85fb46bb0589923758be184056fe9ebd278aaced2d0d643d83718230
odf4/mcg-operator-bundle@sha256:efdcd380cb47edfbb65c2c535e1206d3b5a3dde4689e1da79401d0edbabe9349
odf4/mcg-rhel9-operator@sha256:5c283756969496f6ae2d6ce8c7757b982831fc2ddacaf7279d5f6b571af0d37b
odf4/ocs-client-console-rhel9@sha256:0ee124e4d939ee19fb6e9111fca7c319e25e54189283d6f0741f0c5d268c2f41
odf4/ocs-client-operator-bundle@sha256:e0cb8f162b6437a6f58b6252b10c808a353f0117ecce309381870da7aa265059
odf4/ocs-client-rhel9-operator@sha256:0dc53400a4bda89712ff275e78a0c18d52f5e0cbfe6ba68e59d4f79e989b6bc2
odf4/ocs-metrics-exporter-rhel9@sha256:951bf1e86d6cf0b98221cd2ca570bad1713340dc471e2eb720aeb5e50bb05598
odf4/ocs-operator-bundle@sha256:a74bcf4fec0071f318e267640147dfc2b8f875b88b12f06bd9274d31184d6b02
odf4/ocs-rhel9-operator@sha256:f115dd4a134490d9191fb09d8d75436fe25d1234b7249375e625caf1ecd7d293
odf4/odf-console-rhel9@sha256:ced8bc94fc45ece64cf315a6412557cab16e32140111e45ca169099ea18e98fd
odf4/odf-cosi-sidecar-rhel9@sha256:163496946bbcba554c761cb1a7d51b37847016682b5e28d6e4fe6ddf0f80de79
odf4/odf-csi-addons-operator-bundle@sha256:7b678bae7ef2cfc9ab23b95dc8d17ad0962e19095525107a1896afe0b233ae50
odf4/odf-csi-addons-rhel9-operator@sha256:9616a9be9307e7c7a7159e645c6b5b8909be4f23d1abc866b5e7d55ad2527af2
odf4/odf-csi-addons-sidecar-rhel9@sha256:fa3034c9854491e3b4d49339b7e11c248edc8b77928d2deb4410ec891ae834e0
odf4/odf-multicluster-console-rhel9@sha256:b1ecb2d81cd162a1e78e50a287dc3df5b6d14bf5feb1c1c1cce629ba05aea2a8
odf4/odf-multicluster-operator-bundle@sha256:6193c8b7c57c2f436d152faa46273777df16b7b73c982a5dc35c16755587b3fd
odf4/odf-multicluster-rhel9-operator@sha256:027d8968b71b031267da6e543baaaf2fcb20532aca623cb853ecc5e64e68af08
odf4/odf-must-gather-rhel9@sha256:2b6ac330ea876db86901b98f9ac1064c7ca21e3aba467c21dc570017d607f019
odf4/odf-operator-bundle@sha256:6a1986ff9493d7cab893ed4a7f486998c4afae8dcc527a218e070867a8474eef
odf4/odf-rhel9-operator@sha256:2cceb3e2d023f40ab611f35b8c60dc5589f4353d7a5199cad4f09284e0d0deb4
odf4/odr-cluster-operator-bundle@sha256:123bff07768cf928393ee40fa479bc9bfab55397787c7ac8cd7ece79f4b0ed33
odf4/odr-hub-operator-bundle@sha256:38c8500f955ad35dc1a724945f7ddfa159d2f725ead3d6a2af8f41edc77783dc
odf4/odr-rhel9-operator@sha256:54ccae475c14e3329240e15f43414652a2b8f4a9ccba626bec835bc3b582d919
odf4/rook-ceph-rhel9-operator@sha256:66e18662cae583fb5557c966b93476183813c1fd7fc07feb39f0ae212ae6c0f4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility