关键信息 漏洞概述 类型/严重性: 重要 主题: 更新了基于RHEL-8的Middleware Containers容器镜像 影响的产品 Red Hat OpenShift Container Platform 4.12 (for RHEL 8 x86_64) Red Hat OpenShift Container Platform 4.11 (for RHEL 8 x86_64) Red Hat OpenShift Container Platform 4.10 (for RHEL 8 x86_64) 固定的漏洞 CVEs: - CVE-2024-1779 - CVE-2025-4138 - CVE-2025-4133 - CVE-2025-4143 - CVE-2025-4517 - CVE-2025-6020 - CVE-2025-6021 - CVE-2025-6022 - CVE-2025-6023 BZs: - BZ-2370010: CVE-2025-4135 cpython: Tarfile extracts filtered members when errorlevel=0 - BZ-2370011: CVE-2025-4137 cpython: python: Bypass extraction filter to modify file metadata outside extraction directory - BZ-2370012: CVE-2025-4138 cpython: Extraction filter bypass for linking outside extraction directory - BZ-2370013: CVE-2025-4517 python: Arbitrary writes via tarfile colpath overflow - BZ-2372371: CVE-2025-49794 libvirt: Heap use after free (UAF) leads to Denial of service (DoS) - BZ-2372385: CVE-2025-49796 libvirt: Type confusion leads to Denial of service (DoS) - BZ-2372406: CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 - BZ-2372426: CVE-2025-4138 cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory - BZ-2372516: CVE-2025-6020 linux-pam: Linux pam directory Traversal 参考链接 Red Hat 安全更新分类 RHSA-2025:10698 Red Hat 容器目录