SB2025112701 - Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18



SB2025112701 - Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18

Published: November 27, 2025

Security Bulletin ID SB2025112701
Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 25% Low 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Improper privilege management (CVE-ID: CVE-2025-11561)

The vulnerability allows a remote user to bypass authorization checks.

The vulnerability exists due to improper privilege management within the Active Directory integration feature. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.


2) UNIX symbolic link following (CVE-ID: CVE-2025-31133)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue within the maskedPaths feature. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


3) UNIX symbolic link following (CVE-ID: CVE-2025-52565)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue related to /dev/console mounts. A local user can escape the container using a malicious config and escalate privileges on the system.


4) UNIX symbolic link following (CVE-ID: CVE-2025-52881)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue related to procfs write redirects. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Remediation

Install update from vendor's website.