Red Hat released OpenShift Container Platform 4.13.56 through advisory RHSA-2025:2701, an Important security and bug-fix update for OCP 4.13 deployments. The release refreshes platform container images and remediates flaws in Buildah, Podman, rsync, runc, golang.org/x/net/html, the Linux kernel, and libxml2, including vulnerabilities that could enable container breakout or arbitrary directory mounts.
The update applies to OCP 4.13 on RHEL 8 and RHEL 9 for x86_64, IBM Power, IBM Z/LinuxONE, and ARM64 systems. Red Hat advises affected customers to upgrade to 4.13.56 through the applicable OpenShift release channel using the OpenShift CLI or web console.

See real exploitation activity before you spend the cycle.
18 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated advisory RHSA-2025:2700, delivering RPM packages for OpenShift Container Platform 4.13.56 on RHEL 8 and 9. The update fixes CVE-2024-45338 in golang.org/x/net/html and the Jinja2 sandbox-breakout vulnerability CVE-2024-56326, among other CVEs.
The 4.13.56 update fixes vulnerabilities including arbitrary-directory mounting in Buildah (CVE-2024-9675), a Podman/Buildah container breakout (CVE-2024-11218), rsync information disclosure, runc file-descriptor leakage, Linux kernel flaws, and a libxml2 use-after-free. Red Hat advised users to upgrade through the appropriate release channel using the OpenShift CLI or web console.
Red Hat issued RHSA-2025:2701, an Important-rated security and bug-fix advisory releasing OpenShift Container Platform 4.13.56. The update provides container-image fixes for affected OCP 4.13 deployments on RHEL 8 and 9 across x86_64, Power, IBM Z/LinuxONE, and ARM64 architectures.
Red Hat issued Important-rated advisory RHSA-2025:2712 for OpenShift Container Platform 4.14.49, providing updated Buildah and CRI-O packages that remediate the Podman/Buildah race-condition container-breakout vulnerability CVE-2024-11218. The update applies to OCP 4.14 deployments on RHEL 8 and 9 across x86_64, ppc64le, s390x, and aarch64 architectures.
Red Hat issued Important-rated advisory RHSA-2025:2456 for OpenShift Container Platform 4.15.47, supplying updated packages and images that remediate the Podman/Buildah race-condition container-breakout flaw CVE-2024-11218. The update includes Buildah 1.29.5-1.rhaos4.15 and updated CRI-O packages for supported RHEL 8 and 9 architectures.
Red Hat issued Important-rated advisory RHSA-2025:2441, releasing updated container images for OpenShift Container Platform 4.12.74 on RHEL 8 and 9. The update remediates vulnerabilities including CVE-2024-11187, CVE-2024-11218, CVE-2024-21626, CVE-2024-45338, and CVE-2024-50302.
Red Hat issued Important-rated advisory RHSA-2025:1910 for OpenShift Container Platform 4.16.37, remediating the Podman and Buildah race-condition container-breakout vulnerability CVE-2024-11218. The update includes updated Buildah, OpenShift, and CRI-O packages, plus applicable RHEL 9 kernel packages, for supported RHEL 8 and 9 architectures.
Red Hat issued Important-rated advisory RHSA-2025:1914 for OpenShift Container Platform 4.17.19, remediating the Podman and Buildah race-condition container-breakout flaw CVE-2024-11218. The update includes Buildah 1.33.12-1.rhaos4.17 and updated CRI-O packages for supported RHEL 8 and 9 OCP 4.17 architectures.
Red Hat issued Important-rated advisory RHSA-2025:1713, providing OpenShift Container Platform 4.15.46 RPM updates for RHEL 8 and 9. The update remediates the Podman/Buildah race-condition container-breakout flaw CVE-2024-11218 and includes updated Podman and CRI-O packages across supported architectures.
Red Hat issued Important-rated advisory RHSA-2025:1453 for OpenShift Container Platform 4.14.48, providing updated Podman 4.4.1-22.rhaos4.14 packages that remediate the Podman/Buildah race-condition container-breakout vulnerability CVE-2024-11218. The update applies to OCP 4.14 deployments on RHEL 8 and 9 across x86_64, Power, IBM Z/LinuxONE, and ARM64 architectures.
Red Hat released RHSA-2025:0224 with fixed Cryostat 3 on RHEL 8 components, remediating the golang.org/x/net/html denial-of-service vulnerability CVE-2024-45338. The advisory covers Cryostat-related images and components including cryostat-db-rhel8, cryostat-rhel8, cryostat-storage-rhel8, and jfr-datasource-rhel8.
Red Hat reported Bug 2333122 for CVE-2024-45338, a high-severity denial-of-service flaw in golang.org/x/net/html where crafted case-insensitive HTML content can cause non-linear, extremely slow parsing. The issue was fixed in golang.org/x/net v0.33.0, and Red Hat issued errata for affected OpenShift and related products.
Red Hat released Important-rated OpenShift Container Platform 4.16.36 for RHEL 9, remediating the Podman/Buildah race-condition container-breakout flaw CVE-2024-11218. The update applies across x86_64, Power, IBM Z/LinuxONE, and ARM64 architectures and also includes reliability fixes.
Red Hat documented that Buildah and podman build cache mounts could use a user-controlled cache ID to mount an arbitrary host directory readable by the Buildah-running user into a build container. The vulnerable code relabeled the selected directory for SELinux, so SELinux did not prevent build access; Red Hat issued fixes across multiple RHEL and OpenShift streams.
CVE-2024-11218 was publicly known by January 22, 2025. The flaw affects Podman build and Buildah: a malicious Containerfile built with --jobs=2 can exploit a race condition to break out of the container and access host files and directories; SELinux may limit impact but not host filesystem enumeration.
Red Hat documented CVE-2024-12085 in rsync, where manipulation of the checksum-length value can make comparisons use uninitialized bytes in the sum2 stack buffer. An attacker can repeatedly disclose stack memory one byte at a time, potentially obtaining data useful for bypassing ASLR; Red Hat issued fixes across affected RHEL, OpenShift, and RHOL streams.
Red Hat released RHSA-2025:1333, fixing CVE-2024-45338 in the gatekeeper-operator-bundle component for gatekeeper 3.14 on RHEL 9. The flaw in golang.org/x/net/html can cause resource exhaustion through non-linear parsing of crafted case-insensitive content.
Red Hat documented CVE-2024-21626 in runc, where a file descriptor can remain open during setcwd(2) in container setup, allowing a container working directory resolved through it to retain a reference into the container. The fix closes unneeded descriptors, including measures to handle execve-based attack paths that bypass simple verification.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcedocs.openshift.com
Open sourcebugzilla.redhat.com
Open sourcedocs.openshift.com
Open sourcedocs.openshift.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.