Red Hat released Important-rated security updates for OpenShift Container Platform (OCP) 4.15, 4.16, and 4.17, delivering refreshed container images and packages. The advisories address the runc file-descriptor leak tracked as CVE-2024-21626, the non-linear case-insensitive HTML parsing flaw in golang.org/x/net/html (CVE-2024-45338), and, in OCP 4.17.12, an OpenShift GraphQL introspection information-disclosure issue (CVE-2024-50312). OCP 4.16.32 also includes a fix for Python CVE-2023-6597.
Later OCP releases additionally remediate CVE-2024-53104, an out-of-bounds-write vulnerability in the Linux kernel uvcvideo driver caused by parsing UVC_VS_UNDEFINED frames without accounting for them in frame-buffer sizing. Affected releases include OCP 4.15.43 and 4.15.46, 4.16.32 and 4.16.35, and 4.17.12 and 4.17.17, across supported RHEL 8 and RHEL 9 deployments on x86_64, aarch64, ppc64le, and s390x where applicable. Red Hat advises customers to upgrade through the appropriate OpenShift release channel using the CLI or web console.

See real exploitation activity before you spend the cycle.
19 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:12370, releasing OpenShift Container Platform 4.15.56 container images for RHEL 8 and 9 across supported architectures. The update remediates CVE-2024-45338, CVE-2024-45339, CVE-2025-32462, and numerous additional CVEs.
Red Hat issued Important-rated RHSA-2024:11037 for OpenShift Container Platform 4.19.0, providing updated RPM packages for RHEL 8 and 9 architectures. The update remediates CVE-2024-45337, CVE-2024-45338, CVE-2025-22868, and CVE-2025-22869 in Go dependencies.
Red Hat issued Important-rated RHSA-2025:3131 for Logging for Red Hat OpenShift 6.1.4. The update addresses CVE-2024-45338, CVE-2024-45336, CVE-2025-27144, and other vulnerabilities affecting OpenShift Logging 6 components.
Red Hat issued Important-rated RHSA-2025:1711, releasing OpenShift Container Platform 4.15.46 container images. The update addresses CVE-2024-21626, CVE-2024-45338, and the Linux kernel UVC flaw CVE-2024-53104.
Red Hat issued Important-rated RHSA-2025:1386, releasing OpenShift Container Platform 4.16.35 for RHEL 9 deployments. It fixes CVE-2024-45338 and CVE-2024-53104.
Red Hat issued Important-rated RHSA-2025:1403 and released OpenShift Container Platform 4.17.17 with updated packages and container images. The release remediates CVE-2024-53104 in the Linux kernel uvcvideo component.
Red Hat issued Important-rated RHSA-2025:1242 for OpenShift Container Platform 4.12.73 on RHEL 8 and 9. The update remediates the rsync information-disclosure flaw CVE-2024-12085 and Linux kernel UVC video-driver flaw CVE-2024-53104.
Red Hat issued Important-rated RHSA-2025:1128, releasing OpenShift Container Platform 4.15.45 for RHEL 8 and 9 deployments. The update provides container images fixing CVE-2024-12085 in rsync and CVE-2024-45338 in golang.org/x/net/html.
Red Hat issued Important-rated RHSA-2025:1119, releasing OpenShift Container Platform 4.17.16 packages for RHEL 8 and 9. The update fixes CVE-2024-45338 in golang.org/x/net/html and go-git flaws CVE-2025-21613 (argument injection) and CVE-2025-21614 (denial of service).
Red Hat issued Important-rated RHSA-2025:1269 for the real-time Linux kernel on RHEL 9.2 Extended Update Support channels. The kernel-rt update fixes the uvcvideo flaw CVE-2024-53104 and the alloc_pages_bulk_noprof NULL-pointer dereference CVE-2024-53113.
Red Hat issued Important-rated RHSA-2025:0121, releasing OpenShift Container Platform 4.15.43 for supported RHEL 8 and 9 architectures. The update includes a fix for CVE-2024-45338 in golang.org/x/net/html.
The upstream announcement for CVE-2024-53104 disclosed an out-of-bounds-write vulnerability in the Linux kernel uvcvideo driver's handling of UVC_VS_UNDEFINED frames. The upstream fix skips parsing those frame types in uvc_parse_format.
Red Hat issued Important-rated RHSA-2024:0748 for the RHEL 8 container-tools:4.0 module, updating Podman, Buildah, Skopeo, and runc. The update remediates the runc Leaky Vessels flaw (CVE-2024-21626) and Go vulnerabilities CVE-2023-39326 and CVE-2023-45287.
Red Hat issued Moderate-rated RHSA-2024:0666 for OpenShift Container Platform 4.12.49 on RHEL 8. The update remediates CVE-2024-21626, the runc file-descriptor-leak vulnerability known as Leaky Vessels.
Red Hat addressed CVE-2025-21614, a go-git denial-of-service flaw in which malicious Git server responses can exhaust client resources, through advisories affecting RHEL, OpenShift, Advanced Cluster Security, OpenStack Platform, and OpenShift GitOps. The vulnerability affects go-git versions earlier than 5.13; users of version 4 or later are advised to upgrade to 5.13.
Red Hat addressed CVE-2024-50312, a GraphQL introspection information-disclosure vulnerability, in the OpenShift Container Platform 4.16 release stream through RHSA-2025:0140. The flaw could expose the server's available GraphQL queries and mutations to unauthorized actors.
Red Hat released Important-rated OpenShift Container Platform 4.16.34 with updated RPM packages and images. The update fixes CVE-2024-45338 in golang.org/x/net/html and Jinja2 sandbox-breakout vulnerabilities CVE-2024-56201 and CVE-2024-56326.
Red Hat released Important-rated OpenShift Container Platform 4.16.32 for RHEL 9 deployments. The update remediates CVE-2023-6597, CVE-2024-21626, and CVE-2024-45338.
Red Hat released Important-rated OpenShift Container Platform 4.17.12 with updated packages and container images. The update fixes CVE-2024-21626, CVE-2024-45338, and CVE-2024-50312, an OpenShift GraphQL introspection information-disclosure issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcedocs.openshift.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.