RHSA-2025:8284: Important: OpenShift Container Platform 4.18.16 bug fix and security update
Important: OpenShift Container Platform 4.18.16 bug fix and security update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>This advisory contains the container images for Red Hat OpenShift Container<br>Platform 4.18.16. See the following advisory for the RPM packages for this<br>release:<br><a href="https://access.redhat.com/errata/RHBA-2025:8285" target="blank">https://access.redhat.com/errata/RHBA-2025:8285</a> Space precludes documenting all of the container images in this advisory.<br>See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:<br><a href="https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.18/html/releasenotes/" target="blank">https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.18/html/releasenotes/</a> Security Fix(es):<br><li> zlib: Out-of-bounds pointer arithmetic in inftrees.c (CVE-2016-9840)</li> <li> golang.org/x/oauth2/jws: Unexpected memory consumption during token</li> parsing in golang.org/x/oauth2/jws (CVE-2025-22868)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>All OpenShift Container Platform 4.18 users are advised to upgrade to these<br>updated packages and images when they are available in the appropriate<br>release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at<br><a href="https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.18/html-single/updatingclusters/index#updating-cluster-cli." target="blank">https://docs.redhat.com/en/documentation/openshiftcontainerplatform/4.18/html-single/updatingclusters/index#updating-cluster-cli.</a>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8284?
The severity of RHSA-2025:8284 is classified as important.
What vulnerabilities are addressed in RHSA-2025:8284?
RHSA-2025:8284 addresses bug fixes and security vulnerabilities in the Red Hat OpenShift Container Platform.
How do I fix RHSA-2025:8284?
To fix RHSA-2025:8284, update your Red Hat OpenShift Container Platform to the latest version as advised by Red Hat.
Which versions of OpenShift are affected by RHSA-2025:8284?
RHSA-2025:8284 affects several versions of Red Hat OpenShift Container Platform, including those for ARM 64, Power, and IBM Z.
Is RHSA-2025:8284 applicable to cloud deployments?
Yes, RHSA-2025:8284 is applicable to both on-premise and private cloud deployments of Red Hat OpenShift Container Platform.