Red Hat released OpenShift Container Platform 4.16.25 and 4.17.7 with fixes for CVE-2024-7409, a QEMU flaw that can let an unauthenticated remote attacker crash a temporary Network Block Device (NBD) server during storage migration. An attacker can open a second socket, stall its NBD handshake before TLS negotiation, and trigger socket closure after the temporary server stops; the condition is reachable even where the NBD server requires valid TLS credentials.
The OpenShift 4.16.25 update also remediates CVE-2024-10963 in PAM/pam_access and CVE-2024-24968 in microcode_ctl, while version 4.17.7 additionally fixes CVE-2024-10963, sensitive-information logging in go-retryablehttp (CVE-2024-6104), and a regular-expression DoS in cross-spawn (CVE-2024-21538). Red Hat also issued fixes for affected RHEL 8 and 9 variants; administrators should upgrade OpenShift through the appropriate release channel and apply the relevant Red Hat errata.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Moderate advisory RHSA-2024:10908 for OpenShift Service Mesh Containers 2.5.7. It remediated cross-spawn regular-expression denial of service CVE-2024-21538 in Kiali containers and PostCSS improper input validation CVE-2023-44270 in the openshift-istio-kiali-rhel8 container.
Red Hat issued Important advisory RHSA-2024:10528, releasing OpenShift Container Platform 4.16.25 for RHEL 9 architectures. The update addressed CVE-2024-10963 in PAM, CVE-2024-7409 in the QEMU NBD server, and the microcode_ctl denial-of-service flaw CVE-2024-24968.
Red Hat released Important advisory RHSA-2024:10518 for OpenShift Container Platform 4.17.7 with refreshed container images. It addressed flaws including PAM access-control bypass CVE-2024-10963, QEMU NBD-server denial of service CVE-2024-7409, sensitive-information logging CVE-2024-6104, and cross-spawn ReDoS CVE-2024-21538.
Red Hat issued Important advisory RHSA-2024:5194, updating the container-tools:rhel8 module for RHEL 8.8. The update remediated CVE-2024-6104, which could log sensitive URL information, and CVE-2024-37298, a gorilla/schema memory-exhaustion flaw.
Red Hat released Moderate-severity advisory RHSA-2024:6818 for OpenShift Container Platform 4.15.34, including updated container images for RHEL 8 and RHEL 9 architectures. The release remediated the QEMU NBD-server denial-of-service flaw CVE-2024-7409 and included multiple operational fixes affecting OLM, EgressIP, HyperShift, image registry, and other components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.