Red Hat released OpenShift Container Platform 4.12.76 under Important-rated advisory RHSA-2025:4409, updating platform container images to remediate multiple vulnerabilities. The update addresses CVE-2025-29781, in which the Bare Metal Operator's BMCEventSubscription custom resource could expose secrets held in other namespaces, as well as flaws in FreeType, golang-jwt/jwt, the Linux kernel USB-audio subsystem, and the Bare Metal Operator API.
The release also remediates CVE-2022-49043, a use-after-free flaw in libxml2's xmlXIncludeAddNode function affecting versions before 2.11.0. Red Hat issued fixes for RHEL 8 and 9, associated Extended Update Support releases, RHEL 9 add-on products, and OpenShift versions 4.12 through 4.18; OpenShift 4.12 users should upgrade packages and container images through the appropriate release channel using the web console or OpenShift CLI.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2024:11038 for OpenShift Container Platform 4.19.0, providing updated container images that remediate six vulnerabilities, including CVE-2025-29781. The Bare Metal Operator flaw could expose secrets from other namespaces through the BMCEventSubscription custom resource.
Red Hat released RHSA-2025:1487 to remediate CVE-2022-49043 in Discovery 1 for Red Hat Enterprise Linux 9.
Red Hat released RHSA-2025:1350 to address CVE-2022-49043 in Red Hat Enterprise Linux 9.
Red Hat released RHSA-2025:7702 to remediate CVE-2022-49043 in OpenShift Container Platform 4.14.
Red Hat issued RHSA-2025:4677 to address CVE-2022-49043 in OpenShift Container Platform 4.13.
Red Hat released RHSA-2025:4422 to remediate CVE-2022-49043 in OpenShift Container Platform 4.15.
Red Hat issued Important-rated RHSA-2025:4409 for OpenShift Container Platform 4.12.76. The update remediated CVE-2022-49043 and other flaws, including CVE-2025-29781, which could expose secrets in other namespaces through the Bare Metal Operator BMCEventSubscription CRD.
Red Hat released RHSA-2025:3798 to remediate CVE-2022-49043 in OpenShift Container Platform 4.17.
Red Hat released RHSA-2025:3775 to remediate CVE-2022-49043 in OpenShift Container Platform 4.18.
Red Hat issued RHSA-2025:2678 to address CVE-2022-49043 in Red Hat Enterprise Linux 9.4 Extended Update Support.
Red Hat released RHSA-2025:2507 to remediate CVE-2022-49043 in Red Hat Enterprise Linux 8.8 Extended Update Support.
Red Hat issued RHSA-2025:1925 to address CVE-2022-49043 in Service Interconnect 1 for Red Hat Enterprise Linux 9.
Red Hat released RHSA-2025:1517 to remediate the libxml2 use-after-free vulnerability in Red Hat Enterprise Linux 8.
Red Hat issued RHSA-2025:1516 to address CVE-2022-49043 in Red Hat Enterprise Linux 9.2 Extended Update Support.
A use-after-free vulnerability was identified in libxml2's xmlXIncludeAddNode function in xinclude.c, affecting versions before 2.11.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcedocs.redhat.com
Open sourceaccess.redhat.com
Open sourcedocs.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.