Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:3565 - Security Advisory
Issued:
2025-04-09
Updated:
2025-04-09

RHSA-2025:3565 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.17.24 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.17.24 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.17.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.24. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2025:3567

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

Security Fix(es):

  • golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Solution

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as follows:

(For x86_64 architecture)
The image digest is sha256:65fbb79f801b621121793d347e4405d52edf114d7eea4f4b8c11115db57e5aa4

(For s390x architecture)
The image digest is sha256:d3330b797214675c88c1f0d67a17f95bbdd8fdbefa1425099f8cdea57a57ac65

(For ppc64le architecture)
The image digest is sha256:c9ad983765264daa460d987550e396808a1f21d615eab103c269c253d0c819d7

(For aarch64 architecture)
The image digest is sha256:f6e73fb9cbfe14f812b66d5e0468b2055563661bf0e96e6b8e0ddd7d60ce496e

All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Affected Products

  • Red Hat OpenShift Container Platform 4.17 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.17 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.17 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 8 aarch64

Fixes

  • BZ - 2354195 - CVE-2025-30204 golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
  • OCPBUGS-34228 - ART requests updates to 4.17 image ose-service-ca-operator-container
  • OCPBUGS-51277 - Oh no! Something went wrong.
  • OCPBUGS-52951 - [release-4.17] Unexpected Behavior During Cluster Upgrade (4.14.23 to 4.15.15) for the ovn-ipsec-host pods.
  • OCPBUGS-53378 - OCP 4.16 "openshift-install agent create image" returns "error: unable to read image quay.io" in disconnected env
  • OCPBUGS-54357 - [IBMCloud] the CIS "plugin did not respond" blocked the public install

CVEs

  • CVE-2023-52653
  • CVE-2024-23848
  • CVE-2024-26976
  • CVE-2024-27010
  • CVE-2024-27410
  • CVE-2024-35810
  • CVE-2024-35888
  • CVE-2024-35925
  • CVE-2024-50264
  • CVE-2025-24855
  • CVE-2025-27363
  • CVE-2025-30204

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/network-tools-rhel9@sha256:e2f4bf7ee2505145af9879f1d057b6dd089565f6c2dc02cf4f65fef8927233d2
openshift4/ose-agent-installer-api-server-rhel9@sha256:c69e3500230c158129bf2bb350324e0d930fe49402353bd9e4de388c0c722fe1
openshift4/ose-azure-workload-identity-webhook-rhel9@sha256:dcc8cd8fce69481d4ddc5e4fc1d101b78ad0dd3abdc00924281c6cc2526e7fcf
openshift4/ose-baremetal-installer-rhel9@sha256:b5ec01eecf8f3377a34374bb36a36a00ab8305f7dfa9771022a827a11f9b6f16
openshift4/ose-cloud-credential-rhel9-operator@sha256:3fb12f61b7c7edf41f37dc8a0aca8cb4baa369eed056cc576e426d5c668973e4
openshift4/ose-cluster-network-rhel9-operator@sha256:9f4c11ab90c881aca17ca108d9936e839e17ae7c4b2d44f6e4a6dbf82577a0cf
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c1a02ca9e54df26145a85dc12174dc0c204d6c1eefff723a3a6117f2eb757a9e
openshift4/ose-cluster-samples-rhel9-operator@sha256:7de776c05301ddb4c3005a3a7d3440e1899371de9f72301fce4e5a151c95f694
openshift4/ose-console-rhel9@sha256:66e26eb06893275991fa8e72feaa76607b6cc925c5e3d59dffe5b64d8df02634
openshift4/ose-docker-builder-rhel9@sha256:58b3eeabdd1d248bb706b7060110456915327d459901a663a917aff828b10745
openshift4/ose-hyperkube-rhel9@sha256:9047da4d23cfce8b59f3ccdc52628ed8b54f47c4052a3d442148d263a0ff62c8
openshift4/ose-hypershift-rhel9@sha256:a4866f8ed2d4ac87f1fb4af0514ee984c4e7769cdce75e8e55ae6aeed1469992
openshift4/ose-installer-altinfra-rhel9@sha256:fabf577016ed47db8a337e1e0a7850528d91e69d55c72c82875f6bb01a531077
openshift4/ose-installer-artifacts-rhel9@sha256:ac70c909a3adc3217ff1787ba1115727690fe63b5ea68e91618a2350223c4d5b
openshift4/ose-installer-rhel9@sha256:9b36ddc8dce160fdf0d862e24089ad098f6f5f806a844105fe31c5eb50a157b6
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:6b2212da2f61dd5cf8217aa9578721787668bb656b20cddc1f61c63b0f357899
openshift4/ose-ironic-rhel9@sha256:af398edf44d883549d223fe002cc4b891b42c08eb5fb00436036a7665fc83eb9
openshift4/ose-machine-config-rhel9-operator@sha256:af07530311b96690bb447fb89a7177d386155b586305c55636e515233df8457c
openshift4/ose-machine-os-images-rhel9@sha256:295d1ae21ab9b1fbb8ec2aec4ce14fe8accfe6d1dbc7c49967b5cf54ee13acb2
openshift4/ose-monitoring-plugin-rhel9@sha256:eed7532e5bd28c248ba0254a676e1ef407bea92f5c61cc7ac4e4175835ed8caf
openshift4/ose-networking-console-plugin-rhel9@sha256:49f27d654662154febc84e5b3eb9b30d492cf4cfa2d1fdeaa59616f2bb9e0aa3
openshift4/ose-pod-rhel9@sha256:b795da88251d1e00d713923c8e444ee0ff7306ffd3d4f5fb036ee46626764457
openshift4/ose-service-ca-rhel9-operator@sha256:1836b8867ef16eeede9d9d4faf27e9de02f2b7047646e0753db097b152b02247
openshift4/ose-tests-rhel9@sha256:765a0369a8ff16598a8d0b3b5b7d2e70c38bb2b3e69771006acc608b0ccc360d
openshift4/ose-tools-rhel9@sha256:222230e5d28885276249325df08464d4d5d69f11d68a4c839b1e01e23b8568c1

ppc64le

openshift4/network-tools-rhel9@sha256:ca88626922e1cfa322077c99cac28be4e04845267188d9925dbc9c2d8ff73018
openshift4/ose-agent-installer-api-server-rhel9@sha256:05a8cf639d4f51644c34e86e732be0551d7db0b0287b28ae2df4e139a1f1f50c
openshift4/ose-baremetal-installer-rhel9@sha256:1440f78a610b0205e9ee0ffab7a99c035f9fab456dec76fc804aa14f87efda8c
openshift4/ose-cloud-credential-rhel9-operator@sha256:25e855545dad6fa69ae7c6b2d71acab49536f37dcc21c3f8ef2261a223d6eb1d
openshift4/ose-cluster-network-rhel9-operator@sha256:1bf4f7ad2a526175ea16d0cc432830ad0a76e043b4bbfd66bf19b82f5770627b
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:3c1b53d1829d379c251af96d81465e8788e0a5490dd887ffe7a8c71e1db4c3a7
openshift4/ose-cluster-samples-rhel9-operator@sha256:16655e1abd7fe21d4eff748185b9224f1a16a1b1cec6ffc40e099d1f0f502c15
openshift4/ose-console-rhel9@sha256:4a6d38fb6a2f07b3abd8e33c4a6349955044ad4e288918465257058c6596d283
openshift4/ose-docker-builder-rhel9@sha256:df428f1cfa76c3c471ef2cc23d0b5d70f99a0fe540e7e7c626ee86a876ba0eb5
openshift4/ose-hyperkube-rhel9@sha256:be6d0071f11769b8132ee98a9a04e1fe6354327ab5a0c9e620eb5c4b40d28545
openshift4/ose-hypershift-rhel9@sha256:4ad05565355b7b312765876f6c280d1c0175d7a0db948d2583da3ac48f75b46c
openshift4/ose-installer-altinfra-rhel9@sha256:cea2099e5c0697045622178ec5df6ffdaaf6d517d4f9d34fc7a4def2b11332dd
openshift4/ose-installer-artifacts-rhel9@sha256:10b015b52fb63fc2a56c395165255cbb5ef49bc5f5334deedbb6b21392cde205
openshift4/ose-installer-rhel9@sha256:00c32aeea5f5782473f39f411f00bbb6b2068f06c449e7f4c0d015e9aeaa7856
openshift4/ose-machine-config-rhel9-operator@sha256:52b67fc5ed2cba8634d325c4588da18270f2a4b40f8c7b7bb26a388d469fbf68
openshift4/ose-machine-os-images-rhel9@sha256:835c5f9664088a14a84e124c53fb87d1189a02188ce1d5aafd4e9c5f5ef11dff
openshift4/ose-monitoring-plugin-rhel9@sha256:2baeabbcf22bf1b003940c56ed11ff8a86fdb2960cdf0eabc7f5a8362a5aed79
openshift4/ose-networking-console-plugin-rhel9@sha256:ec42755c2f7e4abc06765776408c2d02a63ff7908fc6ed72a58d5e3c24bc3806
openshift4/ose-pod-rhel9@sha256:040b535f95689b081a0fc0b633496e8a1bccc6789766377550540d0a7b78420c
openshift4/ose-service-ca-rhel9-operator@sha256:a20d3679a754d383a3a98b1266863cec0e54269e5a9ee862fb18104f39b49a5e
openshift4/ose-tests-rhel9@sha256:33f0c8914e3eebcfb6178bd3275edb96905a995a1d36be722563f3cedf346f32
openshift4/ose-tools-rhel9@sha256:cb4ca0a9a5df2a7c93600acd4b1dd6814130904ed50c26740e10f49883e98912

s390x

openshift4/network-tools-rhel9@sha256:8cef420ca0d2fb07ebba67db82c6afc26a46721b422f7ab8b1100240d148f4d4
openshift4/ose-agent-installer-api-server-rhel9@sha256:0c04b96e6779d6fef8ab85e7e45b7af1ae861c599c6cba81acc6fe0cc68dbade
openshift4/ose-baremetal-installer-rhel9@sha256:c3f08afe2f6142eb824daab65329b99038a7ca86c94efad0795b559d92c14d5f
openshift4/ose-cloud-credential-rhel9-operator@sha256:af4eb215e629922be2b7e2d1f7de69be3aeb05db7c45321da70887e65b7950e6
openshift4/ose-cluster-network-rhel9-operator@sha256:94af888c71735513c0feefa9986053f9577a708197b86db706575f22666694f7
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:80039d520659915a61695bb747714a3fb445791a1ee9d0b27e5f0a96a31131fa
openshift4/ose-cluster-samples-rhel9-operator@sha256:27595cbc9fa36de1c069e1e559d78263af4faae0a96a4582fa923fe1676a9cb0
openshift4/ose-console-rhel9@sha256:cd4bd6adad24c82e4b143c02fee64731ad5326f8f0b028ef532cafaa17476429
openshift4/ose-docker-builder-rhel9@sha256:13c79a8969b5f579a434547225fc55f33703ab371ccc6f2c41bf9152f5bd7f7e
openshift4/ose-hyperkube-rhel9@sha256:c496b5b14d32b6647dae97f79f858303cfbd640c9e0c19bd5cabdbe73a5260b4
openshift4/ose-hypershift-rhel9@sha256:15af2a06a479bb72da1271839abc94ab2b9a570dd0a8efd8be24d90baf10aa2f
openshift4/ose-installer-altinfra-rhel9@sha256:c0e80e7f4348618003161bb693674aa2e239e182a17bbc5f7bc94aa3e4b9e063
openshift4/ose-installer-artifacts-rhel9@sha256:7690d11cf9b186239dd7cba36af47e668c91edab076af9861fa5c15333068604
openshift4/ose-installer-rhel9@sha256:4feb7d220196b24095e66df7dc5d73f82810e01d348efb11b79d9e074ac5fcd4
openshift4/ose-machine-config-rhel9-operator@sha256:ad7496211ecceec6768ad11f58250c19775bf4688d17d8727ddf6ce6f19407be
openshift4/ose-machine-os-images-rhel9@sha256:01b97b4cf175a385c4a5419d19ad07572cc055253ad4a680f9f06ec20a5c0d5d
openshift4/ose-monitoring-plugin-rhel9@sha256:b57a01ec09efd3a0a4c012ada2a8ed36075986eb5e6b647fed38842a6a856151
openshift4/ose-networking-console-plugin-rhel9@sha256:901c59ea45ca50177fbefdc3d7bca57b701fbe71a02040b0c8fe213d2629e216
openshift4/ose-pod-rhel9@sha256:5674001b4db3e742b1ab3f065154274231f88e346aa9453d52a52be2f8c3533e
openshift4/ose-service-ca-rhel9-operator@sha256:4a3c5f5c259d7840b851470093d6e0c8a6109b119c043b0b2312dc9f8b5a51c0
openshift4/ose-tests-rhel9@sha256:23c2f43aa987eb6ee06ce77411279135192936b02ad8c0bfcf49685e6f89d581
openshift4/ose-tools-rhel9@sha256:4135b690949ef89f47a2e9c32237533ad3971c207014e75f482e31ba83119ee5

x86_64

openshift4/network-tools-rhel9@sha256:ad9e32d48531d683bd63908b275fba5e31e8561e3b772a30daa57687bf16a2ac
openshift4/ose-agent-installer-api-server-rhel9@sha256:a03a9af376579c6739877bf254443b8659dab3762e991a8c64eb506ef2a75bc2
openshift4/ose-azure-workload-identity-webhook-rhel9@sha256:3f4de63bfac55ec000217d7f5ec0c7a0e192ebeb1e200edbc8a6b7e1b3813093
openshift4/ose-baremetal-installer-rhel9@sha256:cd35e666096119b0d18be277aa03f4fa66f25deb93a594a6c4e16990dc47584c
openshift4/ose-cloud-credential-rhel9-operator@sha256:279e3f653532d9fb4b0750161ad93757a9e610e8da6c771d3add7e64e83a2c15
openshift4/ose-cluster-network-rhel9-operator@sha256:0a90a7f5271a2dc014d99bc67884b7041aefc822cefa08f7edf070e74c745819
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:98d133066b0154170b174f96a9335dee4cf9b26ce728d8f5ec07fdc4248a2ad9
openshift4/ose-cluster-samples-rhel9-operator@sha256:966515651cfa31d6a1a544f4757424894e6a7fe1822b72452b75471f7ee3d2c2
openshift4/ose-console-rhel9@sha256:093bfc371a589e317bb7c587d5a5db7a5da5af306fa2724b6ce8bdc61086a2e2
openshift4/ose-docker-builder-rhel9@sha256:7a0ff0d9791a8c94d19d499cb2690392c4f5025152a65ee7fbf463ac74ffbf35
openshift4/ose-hyperkube-rhel9@sha256:feab113096d6ec632a449506cc26410ac1eb93ec718b16fd49bf1ef2381d21da
openshift4/ose-hypershift-rhel9@sha256:04428357abf3a7df2a5339fab9669a8e44f209600854b47bf900a88da3b47039
openshift4/ose-installer-altinfra-rhel9@sha256:3061d87e775265ca97c435b4dc39bf8c522f51fb1763e28cbc681c8b8e8e0f48
openshift4/ose-installer-artifacts-rhel9@sha256:704a5b484c9e25cc0e7ec27c180c5dd147f620107d5aa745c80b818dfd2f2fd6
openshift4/ose-installer-rhel9@sha256:c49a461c2d2addb2738c5f95627a14c5eeb6bc5fa06fe8a5adb3d09f772e07be
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:98eeef09e3078b70c4cd91d6ff1dfbf0236dfe8b49815810c88171c7367901e1
openshift4/ose-ironic-rhel9@sha256:b7ab350ff5914743507b12407f06cb2c8828770b326733f179a4c30244cde4a7
openshift4/ose-machine-config-rhel9-operator@sha256:21005d09c99222a70c40667cddc57ff97748e884f7ca1b14f5f4eff55c608dbd
openshift4/ose-machine-os-images-rhel9@sha256:9ceac6a208269e50e87e4be7271fadd78e25c82ca5e14454f8c77b6345e70507
openshift4/ose-monitoring-plugin-rhel9@sha256:ee994d84a9b8960fbe393a8d0a54382ee2daad68c37fa7e80b9fd3a7c5ac79b2
openshift4/ose-networking-console-plugin-rhel9@sha256:c52429f7541abb3c78c34e0b42befd6685747b9d124d01a6325c5fcd4457dbeb
openshift4/ose-pod-rhel9@sha256:307a3c31ab942bca535ee9b70b21d1a0de6e0261ca5ac2bf096f26940982e001
openshift4/ose-service-ca-rhel9-operator@sha256:047d48234ce95b4d04660c02033e06479d1d2a4e9ab25cfb09e5147a97d80115
openshift4/ose-tests-rhel9@sha256:06541a999eb5082db54f8cdd69be0552f11dcb3a3b568b4cfe5db86c1b3a1173
openshift4/ose-tools-rhel9@sha256:591c50ee39e4215707f1d8f59f4dba9c41b51d9634f80cc96f94477fa26f4f7e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility