RHSA-2025:4810: Important: RHSA: Submariner 0.18.5 - bug and security update
Important: RHSA: Submariner 0.18.5 - bug and security update
Other sources
Submariner enables direct networking between pods and services on different Kubernetes clusters that are either on-premises or in the cloud.<br>For more information about Submariner, see the Submariner open source community website at: <a href="https://submariner.io/." target="blank">https://submariner.io/.</a> This advisory contains bug fixes and enhancements to the Submariner container images.<br>Security fix(es):<br><li> quic-go: quic-go affected by an ICMP Packet Too Large Injection Attack on Linux (CVE-2024-53259)</li> <li> golang: net/<a href="http:" target="blank">http:</a> net/<a href="http:" target="blank">http:</a> sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)</li> <li> crypto/internal/nistec: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)</li> <li> golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (CVE-2025-22868)</li> <li> golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:4810?
The severity of RHSA-2025:4810 is classified as important.
How do I fix RHSA-2025:4810?
To fix RHSA-2025:4810, upgrade to Submariner 0.18.5 or later.
What software is affected by RHSA-2025:4810?
RHSA-2025:4810 affects Red Hat Advanced Cluster Management for Kubernetes.
What issues does RHSA-2025:4810 address?
RHSA-2025:4810 addresses bugs and security vulnerabilities in Submariner.
Is RHSA-2025:4810 related to Kubernetes?
Yes, RHSA-2025:4810 is related to Kubernetes as Submariner enables networking between different Kubernetes clusters.