Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI
Release of RHOAI 2.25.11 provides these changes:
AI Analysis
Technical Summary
CVE-2025-61729 is a denial of service vulnerability in the golang crypto/x509 package used by the cert-manager Operator for Red Hat OpenShift. The flaw occurs during error string construction in the HostnameError.Error() function when handling a specially crafted certificate, causing unbounded string concatenation and excessive resource consumption. This can lead to degraded performance or denial of service. The cert-manager Operator for Red Hat OpenShift versions from 1.18.0 up to but not including 1.19.0 are affected. Red Hat's advisory (RHSA-2026:0981) details the issue and recommends upgrading the operator. The default installation policy is automatic upgrade, which will apply the fix when available. Manual upgrade requires user approval. No explicit fixed version is provided in the advisory, so users should monitor Red Hat errata for updates.
Potential Impact
Successful exploitation of this vulnerability can cause excessive CPU and memory consumption on the affected system, resulting in denial of service conditions. There is no impact on confidentiality or integrity. The vulnerability affects availability by degrading system performance or causing service outages in the cert-manager Operator for Red Hat OpenShift.
Mitigation Recommendations
Red Hat recommends ensuring that all previously released errata relevant to your system are applied before upgrading. If the cert-manager Operator approval policy is set to 'Automatic' (the default), the operator will upgrade automatically when a new version is released, requiring no further action. If the policy is set to 'Manual', users must manually approve the upgrade. Users should follow the official Red Hat documentation for cert-manager Operator upgrades at https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html. Monitor Red Hat advisories for the availability of fixed versions and apply updates promptly.
Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI
Description
Release of RHOAI 2.25.11 provides these changes:
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-61729 is a denial of service vulnerability in the golang crypto/x509 package used by the cert-manager Operator for Red Hat OpenShift. The flaw occurs during error string construction in the HostnameError.Error() function when handling a specially crafted certificate, causing unbounded string concatenation and excessive resource consumption. This can lead to degraded performance or denial of service. The cert-manager Operator for Red Hat OpenShift versions from 1.18.0 up to but not including 1.19.0 are affected. Red Hat's advisory (RHSA-2026:0981) details the issue and recommends upgrading the operator. The default installation policy is automatic upgrade, which will apply the fix when available. Manual upgrade requires user approval. No explicit fixed version is provided in the advisory, so users should monitor Red Hat errata for updates.
Potential Impact
Successful exploitation of this vulnerability can cause excessive CPU and memory consumption on the affected system, resulting in denial of service conditions. There is no impact on confidentiality or integrity. The vulnerability affects availability by degrading system performance or causing service outages in the cert-manager Operator for Red Hat OpenShift.
Mitigation Recommendations
Red Hat recommends ensuring that all previously released errata relevant to your system are applied before upgrading. If the cert-manager Operator approval policy is set to 'Automatic' (the default), the operator will upgrade automatically when a new version is released, requiring no further action. If the policy is set to 'Manual', users must manually approve the upgrade. Users should follow the official Red Hat documentation for cert-manager Operator upgrades at https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html. Monitor Red Hat advisories for the availability of fixed versions and apply updates promptly.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:0981
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-66471","CVE-2026-21441"]
- State
- PUBLISHED
Threat ID: 6a160972e29bf47b5063a4a7
Added to database: 05/26/2026, 20:58:26 UTC
Last enriched: 08/10/2026, 18:03:44 UTC
Last updated: 09/14/2026, 10:01:28 UTC
Views: 117
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.