Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:7698 - Security Advisory
Issued:
2025-05-21
Updated:
2025-05-21

RHSA-2025:7698 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.15.51 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.15.51 is now available withupdates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.15.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.51. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2025:7700

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/

Security Fix(es):

  • golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (CVE-2025-22869)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.

Solution

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/

You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at
https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as follows:

(For x86_64 architecture)
The image digest is sha256:9fdf7a2305973c26b4075ce1a16b295dbe25092b8ed0ae21506d93cafb6dd9a9

(For s390x architecture)
The image digest is sha256:061e78269860d8237515ab8ba70411655158844fbe3f824927b86bba67e04766

(For ppc64le architecture)
The image digest is sha256:d681578824d4c415402798788bcd0f1bde249ea0608d520cdae79513a333150c

(For aarch64 architecture)
The image digest is sha256:ec919619c51dad303a00f7d4c5607e91d4f22a723460776593984501fc4623a8

All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.

Affected Products

  • Red Hat OpenShift Container Platform 4.15 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.15 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 8 aarch64

Fixes

  • BZ - 2348367 - CVE-2025-22869 golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh
  • OCPBUGS-45257 - Enable topology e2e tests in CI
  • OCPBUGS-55266 - Problem with validatingWebhook on Hosted Control Plane
  • OCPBUGS-55410 - Component Readiness: [Cloud Compute / Unknown] [Other] test regressed
  • OCPBUGS-55411 - GCP MAPI seemingly reconciles MachineSet with incompatible shieldedInstanceConfig
  • OCPBUGS-55464 - Increasing Clock Class Reporting Frequency
  • OCPBUGS-55466 - [4.15]T-GM announces "Locked" too fast after holdover
  • OCPBUGS-55487 - T-GM: traceability flags 0 when clock class 6
  • OCPBUGS-55619 - Pod controller failed to run - Whereabouts
  • OCPBUGS-55733 - [release-4.15] Operator is visible twice in management console
  • OCPBUGS-55948 - pod deletion doesn't occur fast enough resulting in new pod multus interface failing ipv6 duplicate address detection

CVEs

  • CVE-2024-47745
  • CVE-2024-53141
  • CVE-2024-53920
  • CVE-2025-21756
  • CVE-2025-22869

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/driver-toolkit-rhel9@sha256:2d47e5754e78aa6ed425e6f3692358e5f8a65b645dad1eafa8ec5b33d6318dee
openshift4/network-tools-rhel8@sha256:aaa719b86294bb0f9d53eead93de2f516ec9cce65f8848838d8ee72b277edd00
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:f67d038be8ad213efc5c862a997208a10f3a53195df4c4ba58a53b61a27619cb
openshift4/ose-cluster-samples-rhel9-operator@sha256:6970447e64cddf99f85e4c9db9519934a8756caad2368266cc482acea2a9d39f
openshift4/ose-console@sha256:456078ef5c5dd0998f10f558b1b14b6cb4a3d2be2af89e1dc0919d5f84150f64
openshift4/ose-container-networking-plugins-rhel8@sha256:6bdc8705cbe7bab6ff61bf72de635d293258141e364e1126677e390e15b48040
openshift4/ose-hyperkube-rhel9@sha256:4c0e995f1d32f17d4651f49f7d3c955b1ee1303ae390b9110b506ed69cd26959
openshift4/ose-hypershift-rhel9@sha256:71c6f0bd06dd6424cb16ca8f7f29d32fcc3be49953a90341572d5a9c940e68a9
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:de8cb94478fce5b70aa05d270d259a193f7bbf231badf0ce84187f2a1229d30b
openshift4/ose-machine-api-provider-gcp-rhel9@sha256:49dc1c6ff9994a39cb936960fc3a9c27286201ae1a5f294ab2a71ff4eed23f78
openshift4/ose-machine-api-rhel9-operator@sha256:38d5caf877c5a392e5387649762173d750a331ffd3aba7f703234b5d167e6719
openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:e31f1f87bdda54dc6ab41e435d7b5b9b101d879fd32e514dd8861bde17455f86
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:78443828ef0e6ccb1a90cf90fbc191de34afcddc4782be2c55cff6da8176a92e
openshift4/ose-ovn-kubernetes-rhel9@sha256:dbcdc635afcdf0aa85f2c256cebafa30b3a7ccbf91717efd9750f361c7032b14
openshift4/ose-pod-rhel9@sha256:c540028138a50fc485a9c69ee55895b8848085ee6bd7cf8c2260d1c61934672e
openshift4/ose-sdn-rhel9@sha256:10fb6067be65e40802cca3df655c80dc5c467023380cce8ba2bbd466118249aa
openshift4/ose-tests@sha256:75f51253be90aff3710790b9563066812319e8cfbe5811703899d4ceb2952682
openshift4/ose-tools-rhel8@sha256:96728a01ef6e8906316e5afebebc254f38ec9a7825069715a7a1bf553f563b46

ppc64le

openshift4/driver-toolkit-rhel9@sha256:ab2397f3cd3d0e608d7ac532639680b3887c1bfd378d2890900f17983c726940
openshift4/network-tools-rhel8@sha256:9494008d128347ef2c86f47e1ddc6f86071e3a358bc760470fab80091174461e
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:85df64309c247233fa400f2ac953635f3cf3a50bab1da791bb4fbd0523be4c88
openshift4/ose-cluster-samples-rhel9-operator@sha256:115b7cb545f45408f3808cc47cc0139d891ec8dc3063788c83f7115bef7de7e3
openshift4/ose-console@sha256:88c38fd78eeec320ca89be9af11622d1743311432bdaf74555b13019b6a7e3e7
openshift4/ose-container-networking-plugins-rhel8@sha256:f8d39175a3a6f4d011429d0951fa4a24eac892050f41c3730671bb893d8fbaa1
openshift4/ose-hyperkube-rhel9@sha256:1cd545f4107d7008800d0e3e25189faf8cb01a3355437ff63cd18d677fd3765f
openshift4/ose-hypershift-rhel9@sha256:b62b832b2dbcf2e78106719b7528fd8d20dd9802cfd55e62f260f88869ea9944
openshift4/ose-machine-api-provider-gcp-rhel9@sha256:fdf524135665dd7b45c583b99a3ef9c2b80d5a5bccc84e50d359df7cb7e0302f
openshift4/ose-machine-api-rhel9-operator@sha256:dafb0c950389c75ad3b70cdaa316312db3ecee091208540109d3eb3b325e58bd
openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:a886e4720a9fbcc560e08e7c440dedddc7b0d10c83252ac369e78c1211c32c39
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:51eff4220c19638c143ec6ae872093bec46cd1b4d217a47f9d5d62f3d437804c
openshift4/ose-ovn-kubernetes-rhel9@sha256:bcdf8620a7e09a4a01bba7c533df9b9192a233b23a344b84d8429827cbc0080b
openshift4/ose-pod-rhel9@sha256:6aea0a9891cf9b1673bb6645d4edd1ece0a9a4035bfccf8de68db87fb30f60a7
openshift4/ose-sdn-rhel9@sha256:edb90e2fbdcf1d20c8f9486239278adeca86458c9d53e36a05096431cdb94e4c
openshift4/ose-tests@sha256:c42a5e8a6008350adfb3edcfce99078dfd3ba4c989844ff98954d41a9d3f84b6
openshift4/ose-tools-rhel8@sha256:bfe3c6fabb8d74c289d4469785f5be1c6688403b89c458edd404792c96dcca34

s390x

openshift4/driver-toolkit-rhel9@sha256:342c3f60af1fb76d755e7212826b310b4df141f1c592bb2cd9c81f057397231c
openshift4/network-tools-rhel8@sha256:e31b219cf9fab08e064baf65343c0d9fa2d595520e20e35eb40d143aea24c1d9
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:9e4f0e822c8ade723e5f7918b630563f492389c14abe7683d980eb0de712fcb4
openshift4/ose-cluster-samples-rhel9-operator@sha256:44d61713f92b55453d0e9904f049b87028fa57f7084e62ef081808f306f43d73
openshift4/ose-console@sha256:77df0adb69e4641be0f699aa4ea706da80fba3e97d2d95c4e598c0b6837fb043
openshift4/ose-container-networking-plugins-rhel8@sha256:5202cf0b783fba0837de98ad94cc47cfbd9b7a21c93f1d1b6599ec3d8933b19e
openshift4/ose-hyperkube-rhel9@sha256:12ad855533aa129c0368cbfebe5d6f5077708cc181af10e70a7603cff2faa17c
openshift4/ose-hypershift-rhel9@sha256:20fa7607c5be8c7b111c843d15f86ad68802d4d6062c14a219037a220ce73c83
openshift4/ose-machine-api-rhel9-operator@sha256:f8e01ee1299bd1e76cd3ad8c612aa2867b6a94191594a0fbfa51016f0d975088
openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:914c110aafa5632e4ff3540e74a8ce45e7d45d3f08311835c10fa982b0f9f3e1
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:7e0ad5ab6a10119f6c877d80c1e9b9d39d29ead9671f5ed6914372faf66a58cb
openshift4/ose-ovn-kubernetes-rhel9@sha256:5ed879f9e7ca7dcbea402405e729b5aa6c6f1e7a4f14f2e504708e2de6133da8
openshift4/ose-pod-rhel9@sha256:82e9477900aae1cd05c44b5e69dae0586286fed233644696bc216c9a96e6a7ec
openshift4/ose-sdn-rhel9@sha256:b2f4159d15c53d9ccb383599b70bcbdc68651b968b2197f80f7d1218a815f40c
openshift4/ose-tests@sha256:078bab212653fa5b19895d2ec6b1c621dbf4735ea0f69a29b8605bef5da473e6
openshift4/ose-tools-rhel8@sha256:e46a8d2dbaeaf03e1a6d332681355708a965110d9b2e7b9a9030a88ab5ab867b

x86_64

openshift4/driver-toolkit-rhel9@sha256:aec454f92990c246f8f8319d58dc92db147f00b376fc2c6f325afe5d01cc4330
openshift4/network-tools-rhel8@sha256:8c23e45cbf130887723ce08fac491f05d343062dabaf4341db64c0bc247981a4
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:756682cba6ca8f0f54506a65b48c2ec77639c33f8948de3b7b464e31a1268731
openshift4/ose-cluster-samples-rhel9-operator@sha256:86c7353e52357ed2cfd1f723b2312d45062bb301263bb148ebbf5e845b9029a3
openshift4/ose-console@sha256:95174be1a328c1e9ac315207032f1f6bb27fcae58d90fb9419f9586697e01e11
openshift4/ose-container-networking-plugins-rhel8@sha256:345b76a90de2c13e0245963d88cc574f81a3551ba03dde725cc071301e2fc076
openshift4/ose-hyperkube-rhel9@sha256:636f152fff201ea60382b0184b779ecb0034823d5dbdb52795f42d372edc04e6
openshift4/ose-hypershift-rhel9@sha256:f4cd6578606fb7377893186cccdb81d9f3412c3caa237cb0cbf9ceaef21f2d94
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:3b74a9a9edb542fdc39610f4ffc046e3bd56305df8300bd70cedc4f63bc0283f
openshift4/ose-machine-api-provider-gcp-rhel9@sha256:b22b9dbfa7fa62569fbcbac72e70582c6ad058a5b7c372396d7fc3e4b93a00c4
openshift4/ose-machine-api-rhel9-operator@sha256:fa3b57f3f666ce12f4dd36cd06976f4864d29220c8d4d6f837dde8689105c03c
openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:7b6e00f5135658c77e96a0ab925c103e9b598143cef4158c5cba6e6627554556
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:1f94f8be7704bf1b34a77042ac6c5b1e1189d2e622f49f5feade6211a3914c41
openshift4/ose-ovn-kubernetes-rhel9@sha256:1352013d207088689772f53d964389c1758bc1c9e77b98fa5a3ac627a4911e96
openshift4/ose-pod-rhel9@sha256:a7047505a082fe28643355c7354bcbb8ce849d0c84b6da996dbd49739a33b548
openshift4/ose-sdn-rhel9@sha256:9474d7ef24630ce3658b19e0615cdb0becdbfa8a00909f5a316d2fd49c5585ef
openshift4/ose-tests@sha256:d237ecf26656e5c05ed96f652fd9cd14b45842795539d86925af7f963458dced
openshift4/ose-tools-rhel8@sha256:8f796c5fcf27cbf4796bf2bbac322a673535bf73b06e92eb753b82868e864236

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility