Red Hat released multiple security updates for OpenShift Container Platform 4.12, including versions 4.12.84 and 4.12.87, and urged customers to upgrade through the appropriate release channel using the OpenShift CLI or web console. The advisories cover updated RPMs and container images across RHEL 8 and RHEL 9 deployments for x86_64, ppc64le, s390x, and aarch64, and address several flaws in bundled components. Among the issues fixed are runc container escape vulnerabilities CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, as well as the grub2 use-after-free flaw CVE-2025-61662.
A broader OpenShift 4.12 advisory also included fixes for vulnerabilities in podman, expat, sssd, runc, and bind. Red Hat-linked bug reports describe CVE-2025-4953 as a Podman image-build issue that could temporarily expose sensitive build-context files to unprivileged local users, and CVE-2025-11561 as an SSSD Kerberos configuration weakness that could let attackers who can alter Active Directory attributes impersonate privileged accounts on AD-joined Linux systems. Although the notices were labeled Important in the portal, Red Hat Product Security rated the OpenShift updates' overall impact as Low.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat announced OpenShift Container Platform 4.12.87 as a bug fix and security update for the 4.12 stream. The release updated packages and container images and fixed runc flaws CVE-2025-31133 and CVE-2025-52565 plus grub2 flaw CVE-2025-61662.
Red Hat published RHSA-2026:0316 for OpenShift Container Platform 4.12.84 as a bug fix and security update with refreshed packages and container images. The advisory included fixes for CVEs affecting podman, expat, sssd, runc, and bind, and Red Hat rated the overall impact as Low.
Red Hat issued RHSA-2026:0315 for OpenShift Container Platform 4.12.84 with updated RPM packages and images addressing runc vulnerabilities CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881. Red Hat rated the update's security impact as Low and advised 4.12 users to upgrade.
A Red Hat Bugzilla entry documented CVE-2025-11561 in SSSD, describing how the default Kerberos configuration on AD-joined Linux systems could allow attackers who can modify AD attributes to impersonate privileged accounts.
A Red Hat Bugzilla entry documented CVE-2025-4953 in Podman, where a build context directory could remain accessible for 300 seconds during image builds, allowing an unprivileged host user to access exposed files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.