关键信息 漏洞概述 公告编号: RHSA-2025:14396 类型/严重性: 重要安全公告 主题: Red Hat OpenShift Container Platform 4.15.57 的更新,包含多个漏洞修复和增强功能。 影响的产品 Red Hat OpenShift Container Platform 4.15 for RHEL 9 x86_64 Red Hat OpenShift Containers Platform for Power 9 for RHEL 9 ppc64le Red Hat OpenShift Containers Platform for IBM Z and LinuxONE 4.15 for RHEL 9 s390x Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 9 aarch64 漏洞详情 CVE-2025-7425: libxml2: Heap Use-After-Free in libxml caused by atype corruption in xmlWtrPtr CVE-2025-48584: git: Arbitrary code execution CVE-2025-48585: git: Arbitrary file writes CVE-2025-6071: libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-48062: jq: AddressSanitizer: stack-buffer-overflow in jq_json_write (js_string_write) 解决方案 用户应升级到OpenShift Container Platform 4.15.57,并应用相关的更新包和镜像。 使用OpenShift CLI (oc) 或web控制台检查可用更新并进行升级。 参考链接 Red Hat 安全更新分类