Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2025:9646 - Security Advisory
发布:
2025-06-25
已更新:
2025-06-25

RHSA-2025:9646 - Security Advisory

  • 概述
  • 更新的镜像

概述

Important: OpenShift API for Data Protection (OADP) 1.3.7 security and bug fix update

类型/严重性

Security Advisory: Important

标题

OpenShift API for Data Protection (OADP) 1.3.7 is now available.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

描述

OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.

Security Fix(es) from Bugzilla:

  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
  • golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868)
  • golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • OpenShift API for Data Protection 1 for RHEL 9 x86_64
  • OpenShift API for Data Protection for ARM 64 1 for RHEL 9 aarch64
  • OpenShift API for Data Protection for IBM Power, little endian 1 for RHEL 9 ppc64le
  • OpenShift API for Data Protection for IBM Z and LinuxONE 1 for RHEL 9 s390x

修复

  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • BZ - 2348366 - CVE-2025-22868 golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
  • BZ - 2354195 - CVE-2025-30204 golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
  • OADP-5905 - backport oadp-mustgather for 1.3

CVE

  • CVE-2024-12087
  • CVE-2024-12088
  • CVE-2024-12133
  • CVE-2024-12243
  • CVE-2024-12747
  • CVE-2024-45338
  • CVE-2025-4802
  • CVE-2025-22868
  • CVE-2025-24528
  • CVE-2025-30204

参考

  • https://access.redhat.com/security/updates/classification/#important

aarch64

oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:b6739563bbbc01ac7f5a1423c937ce0b861e078d1fbe9fa9c202652af9ec78aa
oadp/oadp-mustgather-rhel9@sha256:00fab8e4e280de478aa50dc4882b89fb0a114addb9ae66b4fc6b731fd445dc67
oadp/oadp-operator-bundle@sha256:4d76c79bb02b2ef7651c9e59c5f57fa925d20ad8663b58963e15fffa2794fc70
oadp/oadp-rhel9-operator@sha256:ef3529ff6280be2c727e2c2aede19e379941bd54ffec631e024404e6aff4adec
oadp/oadp-velero-plugin-for-aws-rhel9@sha256:f1c80831e1e2caacc68123f96d7154dbe7ea1cb0dc479388e72489031e97e4f7
oadp/oadp-velero-plugin-for-csi-rhel9@sha256:18ac5962273cc2e3cbd3efd0455c796590a4e88167c40bc7a7563a7455546470
oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:8af0c3d5e1f84f3039edcd4ec1b5f3f9815203a13640a24b60c3000d0109a92e
oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:9617676a430141cea46deaf50f4185ae59723c187720125339f8df0dabd4579f
oadp/oadp-velero-plugin-rhel9@sha256:57edd04953cb245d0c249c70d112c503ada950ddd3433094a8b8a3585fa350f5
oadp/oadp-velero-restic-restore-helper-rhel9@sha256:4aa044923e7c084194d0306ee8b2e801dd9348dd14ac50a028cd3471d524a05c
oadp/oadp-velero-rhel9@sha256:5d427598650191c4484be55b8f6ba810e3ffa2d4be56503c114551dc328eccef

ppc64le

oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:ea79cf0e5d7983922215e568ec58eae31d4f39d8749033c6fd8bf33f8ffef9e5
oadp/oadp-mustgather-rhel9@sha256:c5ee79a52f22e1dfc67dec3279b29bbba660bc7b2247a30bc0221470b3597486
oadp/oadp-operator-bundle@sha256:78d48aa0b802b8f0418dbe7e6bc89dfd662364d1fe66c44bebedf5e761bd96de
oadp/oadp-rhel9-operator@sha256:842322ed6b054428e8e6c8b23bfd74ebd557383fce296c625f7eea4bca9fc483
oadp/oadp-velero-plugin-for-aws-rhel9@sha256:99885b28c3bc08b5f7311d99d6bf4c3a8c0d43658488ab4981f668b1d77d0862
oadp/oadp-velero-plugin-for-csi-rhel9@sha256:f2e33c6b9d64ae233cd94df5639593149624117f0642b2d5eed7819c365d5cd0
oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:0a80d18f9bb1351b3dd2a133c3611ea3d7a5c0cc6bf53914291b638d96827a9d
oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:d4d5dd775e0eab8770787c048708eb28dc79577bc4142df8ab7799ad45cb1c36
oadp/oadp-velero-plugin-rhel9@sha256:a6c8dcb04e400fc2190a9a40f0ece5542925797863971758945140d2f7313ceb
oadp/oadp-velero-restic-restore-helper-rhel9@sha256:559399102682c8e8a3b62d9bc81954de1d92f49c24bb4f9c0846e44363860bc8
oadp/oadp-velero-rhel9@sha256:e60e1252b37e14c404ce36973a0fe43f26051c83cba11561c820a02a7869c737

s390x

oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:11c111b7dc54689ef1a9597ba310994dd18e2532b3119703cad6f648bbead7df
oadp/oadp-mustgather-rhel9@sha256:5c24f2611c0780bdf2e4dd048d1dd931439528c833563e88f06ffc979f71e24f
oadp/oadp-operator-bundle@sha256:68f5902609b95c8612d9e22ef709df11767e90620088d8a616c54efba2b288ef
oadp/oadp-rhel9-operator@sha256:a0ce84b6445d4783faf91adf123079f12d204329f3393d92653ebe34ff6d1c19
oadp/oadp-velero-plugin-for-aws-rhel9@sha256:b712e88e0ec6b9c6510807793d06b7c80ad66ae3e110eaf1bb85cfb1f4ebaa0e
oadp/oadp-velero-plugin-for-csi-rhel9@sha256:dfebc81f78b18d48418d82336ddbad8860b4cd46cbe02b5145431c2df716455c
oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:d15c779cf7487d3fc65c1246581dd58a275fbb1c86a56f295262971db069cce3
oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:6f19955b2f17b4768d31bcd5b16d577b666129ff12ea55e429df1642749f5a10
oadp/oadp-velero-plugin-rhel9@sha256:c95f7d1fa0aa51e5a0e520ee9b225ab88e69418e3009012a6f60d53a0b2a7f9e
oadp/oadp-velero-restic-restore-helper-rhel9@sha256:1b127bcd020e8fa246eea8e15221adbca90c6dd18b946e94dffb5f207c403e5b
oadp/oadp-velero-rhel9@sha256:145c588eb8dca79c7ea4c00bbca91ba668f2e4b9b04ac8956e1e1188bafa2266

x86_64

oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:ce4b69a7ec86aa550a50bd2fdc345111ee5215a148e03a04e14c99363ec47fd6
oadp/oadp-mustgather-rhel9@sha256:654bf711d7d2ae39a55a0e063de7983bee108217a070a393b403da8cf63096c5
oadp/oadp-operator-bundle@sha256:9486583a82697f6df158586a6cc0a3b3dfc97d39402a0979a6290e7573b99801
oadp/oadp-rhel9-operator@sha256:c08280477b2352694e9cbd6265fd5b5f5bf44b1d8567dadc90002e960f8b6edf
oadp/oadp-velero-plugin-for-aws-rhel9@sha256:7a3d5275c23243443284c7eac552cdb0f54c4820db2c6b73336409d542359623
oadp/oadp-velero-plugin-for-csi-rhel9@sha256:2cc20934f7dcd73339565cf48320d1d9050497a59e98e48ac923d1962306f2a2
oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:e206bd7dfc2650f26201a48de67f71267d4a819298ba179327a45cef9db207be
oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:e8d08ea92ebd8049b6cd1954cea431498206a86f9809f315423bfe736d049ce8
oadp/oadp-velero-plugin-rhel9@sha256:6de39b90b8e736207fbc5d4d4f72d1657846a9a698b1cf9a85ef1e50698ef852
oadp/oadp-velero-restic-restore-helper-rhel9@sha256:6b3539f667a01214b6c8b499b1fc5ec8420d0847baa4c3b8ba269f2b195225dc
oadp/oadp-velero-rhel9@sha256:7dadfa29ff2abb0a2fcc405b51ff1c646557b8ed809f268b1e12904e56a8e966

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility