Red Hat released security updates across OpenShift Container Platform, OpenShift Data Foundation, OpenShift Serverless, distributed tracing, and the Red Hat build of Cryostat. The updates remediate vulnerabilities in shared Go, OpenSSH, networking, image-handling, and third-party libraries that could enable denial of service, resource exhaustion, memory leakage, sensitive-information exposure, or improper privilege propagation. Affected deployments span RHEL 8 and RHEL 9 and supported x86_64, ARM64, IBM Power, and IBM Z/LinuxONE architectures.
Notable fixes include CVE-2023-48795 (Terrapin), which permits an active attacker to truncate initial SSH secure-channel messages under vulnerable ChaCha20-Poly1305 or Encrypt-then-MAC configurations, and CVE-2024-1394, an RSA error-path memory leak in golang-fips/openssl that can cause resource exhaustion. OpenShift Container Platform updates also address a possible OpenSSH remote-code-execution condition on RHEL 9 associated with a signal-handling race. Red Hat advised customers to install relevant prior errata and upgrade clusters and operators through their supported release channels; temporary Terrapin mitigations include disabling chacha20-poly1305 and EtM MAC algorithms where updates cannot be deployed immediately.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:3560 for updated OpenShift Data Foundation 4.14 container images on RHEL 9 for x86_64, ppc64le, s390x, and aarch64. The advisory fixed golang.org/x/crypto/ssh authorization bypass CVE-2024-45337 and golang.org/x/net/html parsing flaw CVE-2024-45338, listed additional CVEs, and upgraded Ceph to RHCEPH-7.1z3 at ODF-4.14.17.
Red Hat issued Important-rated RHSA-2025:1866 for OpenShift Data Foundation 4.14 on RHEL 9 across x86_64, ppc64le, s390x, and aarch64. The updated images address go-retryablehttp sensitive URL logging, PostCSS input validation, a golang.org/x/crypto SSH authorization-bypass condition, and golang.org/x/net/html parsing issues.
Red Hat issued Important-rated RHSA-2025:0224 for the Red Hat build of Cryostat 3 on RHEL 8. The update supplied updated technical-preview container images and remediated CVE-2024-45338, a golang.org/x/net/html non-linear parsing flaw involving case-insensitive content.
Red Hat issued Moderate-rated RHSA-2024:4955, delivering OpenShift Container Platform 4.15.25 container images for supported RHEL 8 and RHEL 9 architectures. The update remediated the Terrapin SSH prefix-truncation vulnerability (CVE-2023-48795) and the RHEL 9 OpenSSH signal-handling race condition (CVE-2024-6409), along with additional bug fixes.
Red Hat issued Important-rated RHSA-2024:4960 with OpenShift Container Platform 4.14.34 images and updates. It remediated vulnerabilities including HTTP/2 denial of service, RSA memory leaks, SSH prefix truncation, image digest validation, sensitive URL logging, and a possible OpenSSH RCE condition on RHEL 9.
Red Hat issued Moderate-rated RHSA-2024:4872 for OpenShift Serverless 1.33.1, supported on OpenShift Container Platform 4.12 through 4.16. The release fixed Go DNS, ZIP-processing, IPv4-mapped IPv6, and sensitive-information logging vulnerabilities.
Red Hat issued Moderate-rated RHSA-2024:4613 with OpenShift Container Platform 4.16.4 container images for RHEL 9. The release fixed the Terrapin SSH prefix-truncation issue, possible OpenSSH signal-handling RCE, and Go, containers/image, and go-retryablehttp vulnerabilities.
Red Hat issued Important-rated RHSA-2024:4479 for OpenShift Container Platform 4.14.33. The update provided packages and container images for RHEL 8 and RHEL 9 architectures, fixing regreSSHion, the Terrapin SSH prefix-truncation flaw, and go-retryablehttp sensitive URL logging.
Red Hat published Important-rated RHSA-2024:4591, updating OpenShift Data Foundation 4.16.0 on RHEL 9. It addressed vulnerabilities including a Submariner Operator RBAC issue that could spread node compromises, Go flaws, Node.js denial-of-service flaws, and secret exposure in NooBaa logs.
Red Hat issued Critical-rated RHSA-2024:0040 for OpenShift Container Platform 4.16.0, providing updated RPM packages for RHEL 9 architectures. The update remediated the Terrapin SSH prefix-truncation flaw, a Go protobuf JSON unmarshalling infinite-loop denial of service, and a CloudEvents Go SDK credential-leak issue.
Red Hat issued Important-rated RHSA-2024:3621 for OpenShift distributed tracing 3.2.0 operator and operand containers. The update fixed vulnerabilities in Go, go-resty, and golang-protobuf, alongside Jaeger, Tempo, and OpenTelemetry fixes and enhancements.
Red Hat issued Important-rated RHSA-2024:2088 for the Red Hat build of Cryostat 2 on RHEL 8, fixing six vulnerabilities including Vert.x memory leaks, Go denial-of-service and certificate-verification flaws, and a Netty resource-exhaustion issue.
Avinash Hanwate reported CVE-2024-1394, a high-severity memory leak in golang-fips/openssl RSA encryption and decryption error paths that could permit resource exhaustion with attacker-controlled inputs.
Avinash Hanwate described CVE-2023-45286 (GO-2023-2328), a go-resty race condition in which retry handling can return an unreset pooled buffer and cause HTTP request bodies from unrelated requests to be sent to another server.
Red Hat documented CVE-2024-6409, a signal-handler race condition in the sshd unprivileged child's cleanup_exit() path in OpenSSH shipped with RHEL 9, introducing the same vulnerability as CVE-2024-6387. Red Hat issued fixes for RHEL 9, RHEL 9.2 EUS, RHEL 9 SAP Update Services, and supported OpenShift Container Platform 4.13 through 4.16 releases.
Red Hat tracked CVE-2023-48795 across affected Fedora, EPEL, OpenStack RDO, RHEL, OpenShift, and related products. The issue allows an active attacker manipulating SSH handshake sequence numbers to remove initial secure-channel messages when ChaCha20-Poly1305 or Encrypt-then-MAC modes are used.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.