- 发布:
- 2025-06-24
- 已更新:
- 2025-06-24
RHSA-2025:9541 - Security Advisory
概述
Important: Submariner 0.17.6 bug fixes and container updates
类型/严重性
Security Advisory: Important
标题
Submariner 0.17.6 packages fix bugs and adds enhancements that are now available for Red Hat Advanced Cluster Management for Kubernetes version 2.10.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE links in the References section.
描述
Submariner 0.17.6 enables direct networking between pods and services on different Kubernetes clusters that are on-premises or in the cloud.
This advisory contains bug fixes and enhancements to the Submariner container images.
Security fixes:
- golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868)
- golang-jwt/jwt: jwt-go allows excessive memory allocation during header
parsing (CVE-2025-30204)
解决方案
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
受影响的产品
- Red Hat Advanced Cluster Management for Kubernetes 2 for RHEL 9 x86_64
修复
- BZ - 2348366 - CVE-2025-22868 golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
- BZ - 2354195 - CVE-2025-30204 golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
CVE
aarch64
rhacm2/lighthouse-agent-rhel9@sha256:253bf5d0c941f36f3e1a404502707e642afa7e8697429e38fc00a24363cabe54 |
rhacm2/lighthouse-coredns-rhel9@sha256:b5ce237b6b29c64f982e66be6bf364a567ec8886873323a09eba29c4f013cfc0 |
rhacm2/nettest-rhel9@sha256:3d23ce573732fb5f71495367371997a771360283a741a6dd2be9113dff7bac25 |
rhacm2/subctl-rhel9@sha256:ded365e54845fb78144084e48a0089661a2e4de94078ba65322489aa591c8642 |
rhacm2/submariner-gateway-rhel9@sha256:39d7f9821665ec852f83742eb606d274f8f4eb1b1b960e601f4f74d58fdee836 |
rhacm2/submariner-globalnet-rhel9@sha256:c6ae49c2b32ad3dc7ee8835f10a4200420744cd4b0e0163b4244c168169db6d7 |
rhacm2/submariner-operator-bundle@sha256:470d07435a5d450c39d80201ec735f23f4c9c031575ff51880fdcf3e955d2d3c |
rhacm2/submariner-rhel9-operator@sha256:667a0f7ea6e85c371b1f082be6d15b2c651f8648cdd76d178b129699e8ac4b49 |
rhacm2/submariner-route-agent-rhel9@sha256:396ae805aea13296b42214b4632104396d3ac05a7a540636928eae7ff0cb8231 |
ppc64le
rhacm2/lighthouse-agent-rhel9@sha256:8f22385b2571331ce6d0577a296d1de34a17b7467ce5e93808ac67f51c36319f |
rhacm2/lighthouse-coredns-rhel9@sha256:a60db2a6d27346c76cf8ec322927052768fe7e7e7bbc11ce1778f6cd496b503c |
rhacm2/nettest-rhel9@sha256:500c726485f6f2646eb192e7d24569228197dafa13a60449fcfe0f1cb7e22a83 |
rhacm2/subctl-rhel9@sha256:37080498f5840acebbb5f4f96b1f75203baefd72302dcd6b66ffb14474e9ee94 |
rhacm2/submariner-gateway-rhel9@sha256:77b375c72aa1544af753acce5c1d6f45f615ec1e0bed1f0f48508d9d590f1963 |
rhacm2/submariner-globalnet-rhel9@sha256:1915bc542011a4841e0bfab92576e897c952ecfd703e78e0e81920bd6904a745 |
rhacm2/submariner-operator-bundle@sha256:af8795085bdf2582ff5bd2a2961cff4b5179b020370d2130e8f94f4bc91a999d |
rhacm2/submariner-rhel9-operator@sha256:608d3a9b8d043798567b98386259c575cccadc0d1edb38e7d77c0463beb6f2cd |
rhacm2/submariner-route-agent-rhel9@sha256:207eac9f5010090ca44651606d12f1c8fc7753301d473d37c43d52c3fa57450d |
s390x
rhacm2/lighthouse-agent-rhel9@sha256:09d7c636408b1ac86e063085f53b50b8c29578693f4bdd908f4e841b76d42946 |
rhacm2/lighthouse-coredns-rhel9@sha256:269ec218b3d32c46d89ac7c852cb09b59f24955b00d240694bfc989c889c5b35 |
rhacm2/nettest-rhel9@sha256:cac09886905e9b6824111a80883cd0f8563cbece5456f5df344943b79232223f |
rhacm2/subctl-rhel9@sha256:321cbc850197f323c69d4b8eed5195314f32b1ab5d32cbd59a9610226711f3ff |
rhacm2/submariner-gateway-rhel9@sha256:22330a1398cb9f2507baf7992800c8e2b75d8a7383fe983e95a78c9cc856cd69 |
rhacm2/submariner-globalnet-rhel9@sha256:da29d598738eb7c181eb78c2383f33b8a35379fe5d3e275ff8d1ba01d9d37b69 |
rhacm2/submariner-operator-bundle@sha256:2a9c8ac2535cd9686d245fae90fffb8b3424018a941a85fd5d4bcb19f8876736 |
rhacm2/submariner-rhel9-operator@sha256:5d2006edf7770901672de933f95d247dc036b314c5d07c692f3beca45ead3091 |
rhacm2/submariner-route-agent-rhel9@sha256:89234ac2f789db2832f0f46e4fd8bf62797d2495c3fe36bbceb9a5075d5e1ca3 |
x86_64
rhacm2/lighthouse-agent-rhel9@sha256:31670c11ab0fc4cc77fc2af6c6895be310e26b11aaa6f0ac0fcffd82663cc9c5 |
rhacm2/lighthouse-coredns-rhel9@sha256:bb36e9b43691443749a67f9020cf95f13c48622721cab751dec3c3c66525e090 |
rhacm2/nettest-rhel9@sha256:d3be8f6ab9b596bec97a8bde6a86bd74400105183b87d46afd20470c63d245a5 |
rhacm2/subctl-rhel9@sha256:c8987ca5f30462c04c29604157ca2ec443a1a2aa58837b62ce2a409be905dbc1 |
rhacm2/submariner-gateway-rhel9@sha256:5be0a19a5918aee1937b9a685623269cd8a4a50ada61e5624608c50ce8bfcd4c |
rhacm2/submariner-globalnet-rhel9@sha256:2ed8cf8929c729e2f8e84c12a13403212b8b925088688a3961ccd6398e172eb6 |
rhacm2/submariner-operator-bundle@sha256:e93f5f62c155f925288b579a7adfdd038ac358031a74173931116151abbef4ed |
rhacm2/submariner-rhel9-operator@sha256:542a633b598e178fb270745e6ae3d0d20bb31c28d71e7e245c8a4ff39ce643a7 |
rhacm2/submariner-route-agent-rhel9@sha256:00847c02f89ca5a1ed08dfd240236904f3a995af87dcc25be752f2183b1d5c94 |
Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。