Issued:
2025-04-16
Updated:
2025-04-16

RHSA-2025:3906 - Important: Logging for Red Hat OpenShift - 5.9.13


Synopsis

Important: Logging for Red Hat OpenShift - 5.9.13

Type/Severity

Security Advisory Important

Topic

Logging for Red Hat OpenShift - 5.9.13

Description

Logging for Red Hat OpenShift - 5.9.13 logging-fluentd-container: Net::IMAP vulnerable to possible DoS by memory exhaustion (CVE-2025-25186) logging-fluentd-container: Local File Inclusion in Rack::Static (CVE-2025-27610) lokistack-gateway-container: Go JOSE's Parsing Vulnerable to Denial of Service (CVE-2025-27144) lokistack-gateway-container: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ocp-4-14-release-notes

For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/logging/cluster-logging-upgrading

Affected Products

ProductVersionArch
Logging Subsystem for Red Hat OpenShift5x86_64
Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE5s390x
Logging Subsystem for Red Hat OpenShift for IBM Power, little endian5ppc64le
Logging Subsystem for Red Hat OpenShift for ARM 645aarch64

Fixes

CVEs

References


Additional information