Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:4408 - Security Advisory
Issued:
2025-05-08
Updated:
2025-05-08

RHSA-2025:4408 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.12.76 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.12.76 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.12.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.12.76. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:4409 Security Fix(es):

  • jinja2: Jinja sandbox breakout through attr filter selecting format

method (CVE-2025-27516)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor.

Solution

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 8 aarch64

Fixes

  • BZ - 2350190 - CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method

CVEs

  • CVE-2025-27516

References

  • https://access.redhat.com/security/updates/classification/#important

x86_64

openshift4/metallb-rhel8@sha256:798e60e117dc0c8d10191a5e4a7d74acfe342a5f79777938e4e92db87f7a8929
openshift-tech-preview/metallb-rhel8@sha256:798e60e117dc0c8d10191a5e4a7d74acfe342a5f79777938e4e92db87f7a8929
openshift4/cloud-event-proxy-rhel8@sha256:5778a102f8361e9c7489d6d5fb6b69a6c50bfaf745d598bfd4da48ed64fbf3c9
openshift4/ose-cloud-event-proxy-rhel8@sha256:5778a102f8361e9c7489d6d5fb6b69a6c50bfaf745d598bfd4da48ed64fbf3c9
openshift4/ose-cloud-event-proxy@sha256:5778a102f8361e9c7489d6d5fb6b69a6c50bfaf745d598bfd4da48ed64fbf3c9
openshift4/frr-rhel8@sha256:f03618d603dc984ab9a2b9ee4465869be915b1af424acd67c80d9b9fb29aee9e
openshift4/kubernetes-nmstate-rhel8-operator@sha256:ccbd261293cba8c6ac4fbc70b998bccf3df5ae6d1376b8e3a058a9a61a23c9c2
openshift4/metallb-rhel8-operator@sha256:ff4f3a9d196915ff3368b61d9a729e2cb033cebbb79912de46098baa094218e9
openshift4/ose-ansible-operator@sha256:46c30b6fd3b0c58582325ad007e06307144781ed16ed958825762ab6d32c32d2
openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:717f0ef90664b91299827d2ba63008b14c1c35361b9d27af5dd0132449aa29e3
openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:fe8f31e9ab99130065f004bcaf99962380b7831f05fb52aa926f9d1a7b83e911
openshift4/ose-cluster-capacity@sha256:c13ca498134838df1e0503c965f7e97b5f5d4954b41162553d5b0bb467ca96fb
openshift4/ose-cluster-nfd-operator@sha256:f988abd875198a754162eb58d88d204c04e61df9648b07abc32a7a8144942a3d
openshift4/ose-clusterresourceoverride-rhel8@sha256:cc6a83695966518acd2c8f6fdaa0d1f31029ea1199fe231880bbe9cb10e11d90
openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:878d9c0b562ce0b100bc3cd8d4ed158745b4a3e4909bcd4a497936219e087e64
openshift4/ose-contour-rhel8@sha256:c1bc04c491076ddc2c63b62c8133593feea3266271cf49d2517d010a74dd44da
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3265c5298ffcff3e922ab397df23447d0c0ccd69882df3b77393269da46f82e5
openshift4/ose-egress-dns-proxy@sha256:f6047c52c79301541a53c6b46963b0960c455d007b403e0f709eaac6f7e2b23b
openshift4/ose-egress-http-proxy@sha256:5d40f09eb29775a64d059cb9b02a93fe4a0128c06cb3690756334c0b0db1ce2e
openshift4/ose-egress-router@sha256:75f8b42c27f3d13e416f95680bf9ca221a90172083876d66eb00c5de979706b5
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:d5ad3f691967138bed0824a3f523caeea3e20ec8dc63874d3fd8db856ac42599
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:f9380895972a1362d2fce6394bf5952ea1517f4f43a5670ec04fc1e3cbca4abc
openshift4/ose-helm-operator@sha256:c8a2c96d2f80306c4e0f12e52f231d4892ddc0fa09ac5bf64399507fd79dbc75
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:ad218406ce14565a5e5945b139ea605d0971335c9f44d729c4845c4ee52b06fe
openshift4/ose-local-storage-diskmaker@sha256:4507ad38497fe51660fb57a8731900a6f97f76341f372e6667b6f55b9ea9af06
openshift4/ose-local-storage-operator@sha256:cfa2b822a6805ccb10b77e7a46f6ac85e30ba6cdb8bcac9cee3c53a42ffd6eb8
openshift4/ose-node-feature-discovery@sha256:62b003061362514fdeb95b4405efe40cdaa7235ff2b289171b48da694ea8474e
openshift4/ose-operator-sdk-rhel8@sha256:ace47e5568655a2e95826f04518e72e955d9ee5485850e8c1b7e3e063e1afeef
openshift4/ose-ptp@sha256:66193b5a7fcb813e2d400ed5e689307ff1ec4e00d4b1ba9fbfcfde0f928f84c7
openshift4/ose-ptp-operator@sha256:000dc197fb76fef681aa813ed55e62b579ef5a1b1649fd151d8dac91524bcd56
openshift4/ose-sriov-cni@sha256:71d94456ec0d28809136a549d486f48a794c04c2582399a3671bd2ec339b4079
openshift4/ose-sriov-dp-admission-controller@sha256:8e2bc209038afbcc2199522273e28755ca6c10540b319fc81a2f3ad1b25c089b
openshift4/ose-sriov-infiniband-cni@sha256:24e43ba923b7dce5acf0770d60de0093376f32dd3ce9e16001ead0a60fd8777e
openshift4/ose-sriov-network-config-daemon@sha256:67accecb157b7c6e6aac3903a0682b2da58633a193bfd80f126ebc03aa9227b2
openshift4/ose-sriov-network-device-plugin@sha256:f0152a0646efed730c64bc5ed492befd55f37c2229554721ee498a9e20d65d1a
openshift4/ose-sriov-network-operator@sha256:6c03954322b14e438c256b619ae449fafcbb2a137c1f2ffad62df7b9d4a2f658
openshift4/ose-sriov-network-webhook@sha256:7fe0659e85854d24f65bb76103ed3a5a90edb43ad17fb0d2639f7c193f014109
openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:c5b9ced7487aec7dcacde19ccbfe311618bbc0c177e4af6636107d6fe4eeb05d
openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:a1f2fe0cdf086aff3b06bfdc78be0c0e651a5d4db7525e8ef851c32cf1fc773d
openshift4/ptp-must-gather-rhel8@sha256:129f48a1160d7adc34d655153cb6a9021b4843191f601629df6e4bfd9f5bc4cf

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility