RHSA-2025:3906: Important: Logging for Red Hat OpenShift - 5.9.13
Important: Logging for Red Hat OpenShift - 5.9.13
Other sources
Logging for Red Hat OpenShift - 5.9.13logging-fluentd-container: Net::IMAP vulnerable to possible DoS by memory exhaustion (CVE-2025-25186)logging-fluentd-container: Local File Inclusion in Rack::Static (CVE-2025-27610)lokistack-gateway-container: Go JOSE's Parsing Vulnerable to Denial of Service (CVE-2025-27144)lokistack-gateway-container: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3906?
The severity of RHSA-2025:3906 is classified as Important due to vulnerabilities that can lead to denial of service and local file inclusion.
How do I fix RHSA-2025:3906?
To fix RHSA-2025:3906, update your Red Hat OpenShift Logging Subsystem to the latest patched version.
What vulnerabilities are addressed in RHSA-2025:3906?
RHSA-2025:3906 addresses vulnerabilities including a denial of service risk in Net::IMAP and local file inclusion in Rack::Static.
Which products are affected by RHSA-2025:3906?
Affected products include the Logging Subsystem for Red Hat OpenShift across various architectures such as IBM Z, LinuxONE, Power, and ARM 64.
Is there a workaround for RHSA-2025:3906?
Currently, there are no specific workarounds recommended for RHSA-2025:3906; applying updates is the advised course of action.