Skip to main content
EPSS 0.8%top 47%

Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Jaeger) 3.5.1 release

0
Medium
Published: 07/23/2025 (07/23/2025, 16:11:26 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This release of the Red Hat OpenShift distributed tracing platform (Jaeger) provides security improvements. Breaking changes: * Nothing Deprecations: * Nothing Technology Preview features: * Nothing Enhancements: * Nothing Bug fixes: * https://access.redhat.com/security/cve/CVE-2025-4373 * https://access.redhat.com/security/cve/CVE-2024-34397 * https://access.redhat.com/security/cve/CVE-2024-52533 Known issues: * Nothing

Affected software

Affected versions
=2.56.4-8.el8_2.2Red HatRed Hat OpenShift distributed tracingRed Hat OpenShift distributed tracing 3.6.0amd64registry.redhat.io/rhosdt/jaeger-agent-rhel8@sha256:389b9cbd0f05d3d773edc2c06aa73818307cbb25048bddf4f192a992670b6fb4_amd64Red Hat OpenShift distributed tracing 3.6.1Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)Red Hat Enterprise Linux CRB (v. 9)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 21:58:31 UTC

Technical Analysis

The GLib2 library, which provides core application building blocks for C libraries and applications including GNOME components, has multiple security flaws. These include signal subscription vulnerabilities (CVE-2024-34397), a buffer overflow vulnerability in the set_connect_msg() function (CVE-2024-52533), and a buffer underflow vulnerability in the g_string_insert_unichar function (CVE-2025-4373). These vulnerabilities affect Red Hat Enterprise Linux 8.2 AUS and related packages. Red Hat has released security updates to address these issues, with advisories RHSA-2025:14991 and RHSA-2025:11662 providing details and update instructions. The vulnerabilities have been assessed as moderate in severity, and no active exploitation has been reported.

Potential Impact

The identified vulnerabilities could potentially allow attackers to cause memory corruption issues such as buffer overflow and underflow, and exploit signal subscription weaknesses in GLib2. This could lead to application instability or other security impacts depending on the context of use. However, Red Hat rates the overall impact as moderate, and there are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released updated glib2 packages for Red Hat Enterprise Linux 8.2 AUS that address these vulnerabilities. Users should apply these official security updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor advisory. Systems running affected versions should be updated to the fixed package versions to remediate these issues.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:14991
Cve Count
3
Additional Cves
["CVE-2024-52533","CVE-2025-4373"]

Threat ID: 6a1f4e87e29bf47b500818c4

Added to database: 06/02/2026, 21:43:35 UTC

Last enriched: 08/17/2026, 21:58:31 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 65

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses