Red Hat released security updates for OpenShift Container Platform 4.12, 4.17, and 4.18, delivering updated container images and packages through the supported release channels. The advisories address CVE-2025-32462, a sudo flaw that permits misuse of the -h/--host option outside privilege-listing operations and can enable local privilege escalation under applicable sudoers rules, affecting Red Hat Enterprise Linux and multiple OpenShift releases.
The updates also remediate CVE-2025-22868 in golang.org/x/oauth2/jws, where JWS token parsing can trigger unexpected memory consumption. OpenShift 4.17.35 additionally fixes node pull-credential overwrite, HTTP request smuggling in Go net/http, and unsafe library-path searching by static setuid glibc binaries; OpenShift 4.18.16 also includes a fix for CVE-2016-9840 in zlib. Red Hat advises affected organizations to upgrade their clusters using the OpenShift CLI or web console.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:13289 and released OpenShift Container Platform 4.14.55 with updated images and packages. The update remediated vulnerabilities including CVE-2025-32462 in sudo, CVE-2025-6021 in libxml2, and CVE-2024-45339 in github.com/golang/glog.
Red Hat issued Important advisory RHSA-2025:12323 and released OpenShift Container Platform 4.12.79. The update remediated CVE-2025-22868 and CVE-2025-32462, a sudo host-option flaw that could enable local privilege escalation depending on sudoers rules.
Red Hat issued Important advisory RHSA-2025:10767 and released OpenShift Container Platform 4.18.20 with updated container images, security fixes, bug fixes, and enhancements. The release addressed CVE-2025-32462, a sudo host-option local privilege-escalation flaw, and CVE-2025-22871, a Go net/http HTTP request-smuggling flaw.
Red Hat issued Important advisory RHSA-2025:10294 for OpenShift Container Platform 4.17.35. The release fixed node pull-credential overwrite (CVE-2024-45497), JWS parsing memory consumption (CVE-2025-22868), Go HTTP request smuggling (CVE-2025-22871), and unsafe glibc library-path searching (CVE-2025-4802).
Red Hat issued Important advisory RHSA-2025:8284 and released OpenShift Container Platform 4.18.16 with updated images and packages. The update addressed, among other issues, CVE-2016-9840 in zlib and CVE-2025-22868 in golang.org/x/oauth2/jws.
Red Hat addressed CVE-2024-45339, a predictable glog log-file path flaw that can let local attackers overwrite files through planted symlinks, in OpenShift Container Platform 4.12 through 4.19. The remediation was delivered through multiple RHSA advisories, including RHSA-2025:12325, RHSA-2025:12370, RHSA-2025:11681, RHSA-2025:12437, RHSA-2025:11677, and RHSA-2025:11673.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.