Skip to main content
EPSS 0.9%top 43%

Red Hat Bug Fix Advisory: LVMS 4.15.10 Bug Fix Update

0
Critical
Published: 01/23/2025 (01/23/2025, 22:31:37 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Logical Volume Manager Storage uses lvm2 through the TopoLVM CSI driver to dynamically provision thin and thick local storage on a cluster with limited resources. Users of LVMS are advised to upgrade to the latest version of LVMS in OpenShift Container Platform, which fixes bugs and security vulnerabilities.

Affected software

Affected versions
>=1.3.0 <1.3.7Red HatOpenShift API for Data Protection9Base-OADP-1.3amd64oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:ce4b69a7ec86aa550a50bd2fdc345111ee5215a148e03a04e14c99363ec47fd6_amd64OpenShift VirtualizationCNV 4.18 for RHEL 9container-native-virtualization/aaq-controller-rhel9@sha256:9c59c01c21b1f032fed5a6a169c93e96f223e8a807c0c323a9362b945771a681_amd64Red Hat Developer Hub (RHDH)Red Hat Developer Hub (RHDH) 1.4registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:d8268197ba0466643efb818fcad8f0fc29e32463f75b0f7f51d9ce75ec717572_amd64CNV 4.17 for RHEL 9container-native-virtualization/aaq-controller-rhel9@sha256:8e04085ab5661b05f372c605c6270981a26b598f0891fb22215bb79ded29711b_amd64logical volume manager storageLVMS 4.15 for RHEL 9arm64lvms4/lvms-must-gather-rhel9@sha256:00d5249d3eca563f230af85c31ae241f4c50d763d22a7caa0593d6139e8509a6_arm64LVMS 4.16 for RHEL 9s390xlvms4/lvms-must-gather-rhel9@sha256:a9fc47d734d4341a82abe24ac8008117f6fa3f46c5c267cb5071f346ee844e5b_s390xLVMS 4.17 for RHEL 9ppc64lelvms4/lvms-must-gather-rhel9@sha256:8f06e68afb3de17ef073d6b1194c1c102a3721328356fa061a5fa334107cb8c6_ppc64leRed Hat Insights for RuntimesRed Hat Insights for Runtimes 1.0registry.redhat.io/insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator@sha256:a7f94c4a1b5b513c76273678840f512358d4ac51281beacc36d1ea23b299f489_amd64LVMS 4.14 for RHEL 9lvms4/lvms-must-gather-rhel9@sha256:7ee6477d60f3fd1ad63e9745ff3ea251107f72b20b241d880364386c096de242_ppc64leCNV 4.14 for RHEL 9container-native-virtualization/bridge-marker-rhel9@sha256:d9decf147c7cc894f5a861b208185b2f42ed81d6f6ff9fa069f5d5f8c7fbb5df_amd64container-native-virtualization/aaq-controller-rhel9@sha256:cc3b097a083d3265372704174de2f226e7e4f7c5b6e752038b5347e0b46cff6f_amd64Red Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.15CryostatCryostat 3 on RHEL 8cryostat-tech-preview/cryostat-db-rhel8@sha256:cc87993362b453460b47d2b8337f411ab12f68ec11114c4b26714e387a4fa3ac_arm64Red Hat ACMRed Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9rhacm2/lighthouse-agent-rhel9@sha256:50d111733ab8210aadf6741847c2858a3adb6c96e6a3ee1414f4ff3bc51a1e43_arm64Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8rhacm2/lighthouse-agent-rhel8@sha256:4103830b222e9e1bab1e312c7d4bf4792e93879430ce79e7f98ea09979319867_arm64Red Hat OpenShift Container Platform 4.17openshift4/kube-compare-artifacts-rhel9@sha256:8af8dfa63a2a891244144b4c0dbd47970f15b3795393b8aa19bcd21f0b9f8eb0_s390xRHDHRHDH 1.4Red Hat OpenShift Container Platform 4.13Builds for Red Hat OpenShiftBuilds for Red Hat OpenShift 1.1.1registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:9bbd9d38a700243149d85de444fc791482b662983b8ac7138e7fc88bcbb0c313_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:19:49 UTC

Technical Analysis

CVE-2024-45338 is a vulnerability in the golang.org/x/net/html package that causes non-linear parsing of case-insensitive content, impacting Red Hat OpenShift API for Data Protection (OADP) and related Red Hat products such as Red Hat Developer Hub and Red Hat OpenShift AI. This issue is part of a set of security fixes released by Red Hat in their 1.3.7 update for OADP and version 2.16.0 for Red Hat OpenShift AI. The vulnerability is rated critical by Red Hat Product Security. The advisory references multiple related CVEs and provides updated container images and operator bundles to address the issue. The vulnerability affects versions >=1.3.0 and <1.3.7 of OADP and version 1.4.x of Red Hat Developer Hub. No active exploitation has been reported.

Potential Impact

The vulnerability allows improper parsing of HTML content which could lead to unexpected behavior or security issues in the affected components. Given the critical severity rating by Red Hat, the impact could be significant in environments using affected versions of OADP, Red Hat Developer Hub, and Red Hat OpenShift AI. However, no known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released official fixes for this vulnerability. Users should apply the OpenShift API for Data Protection (OADP) 1.3.7 update and upgrade Red Hat OpenShift AI to version 2.16.0. The advisories provide updated container images and operator bundles. Before applying these updates, ensure all previously released errata relevant to your system have been applied. Follow the detailed upgrade instructions provided by Red Hat in their advisories and documentation. No additional mitigation is required beyond applying these official updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:9646
Cve Count
3
Additional Cves
["CVE-2025-22868","CVE-2025-30204"]

Threat ID: 6a160970e29bf47b50638534

Added to database: 05/26/2026, 20:58:24 UTC

Last enriched: 08/14/2026, 23:19:49 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 92

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:9646https://access.redhat.com/security/updates/classification/#important233312223483662354195OADP-5905Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0905https://docs.redhat.com/en/documentation/red_hat_openshift_ai/https://access.redhat.com/security/cve/CVE-2024-45338https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0048CNV-39213CNV-49568CNV-50452CNV-50914CNV-52434CNV-53960Canonical URLhttps://access.redhat.com/errata/RHBA-2025:0409https://developers.redhat.com/rhdh/overviewhttps://docs.redhat.com/en/documentation/red_hat_developer_hubhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdhhttps://access.redhat.com/security/cve/CVE-2024-52798https://access.redhat.com/security/cve/CVE-2024-55565https://access.redhat.com/security/cve/CVE-2024-56201https://access.redhat.com/security/cve/CVE-2024-56326https://access.redhat.com/security/cve/CVE-2024-56334Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0121OCPBUGS-45204OCPBUGS-46075OCPBUGS-46080OCPBUGS-46430OCPBUGS-46525OCPBUGS-46576OCPBUGS-47520OCPBUGS-47534OCPBUGS-47646OCPBUGS-47680OCPBUGS-48105Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0224Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0384Canonical URLhttps://access.redhat.com/errata/RHBA-2025:0680Canonical URLhttps://access.redhat.com/errata/RHBA-2025:0681Canonical URLhttps://access.redhat.com/errata/RHBA-2025:0697Canonical URLhttps://access.redhat.com/errata/RHSA-2025:18382242803CNV-31844CNV-34076CNV-34339CNV-35199CNV-40584CNV-41165CNV-41232CNV-41403CNV-41410CNV-41812CNV-41922CNV-42051CNV-42158CNV-42175CNV-42401CNV-43128CNV-43589https://access.redhat.com/errata/RHBA-2025:1169Canonical URLhttps://access.redhat.com/errata/RHEA-2025:2194CNV-55277CNV-55567CNV-55705CNV-56369Canonical URLhttps://access.redhat.com/errata/RHEA-2025:2193CNV-41769CNV-52437CNV-52441Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0678Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0715https://docs.openshift.com/builds/1.1/about/overview-openshift-builds.htmlhttps://access.redhat.com/security/cve/CVE-2025-21613Canonical URLhttps://access.redhat.com/errata/RHSA-2025:2415Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0754Canonical URLhttps://access.redhat.com/errata/RHSA-2025:07752330689DFBUGS-1342Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0783DFBUGS-1343Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0821Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0827Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0831OCPBUGS-42507Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0840OCPBUGS-33145OCPBUGS-46603OCPBUGS-48063OCPBUGS-48323OCPBUGS-48477OCPBUGS-48480OCPBUGS-48495OCPBUGS-48546OCPBUGS-48554OCPBUGS-48752Canonical URLhttps://access.redhat.com/errata/RHSA-2025:111923358882335901Canonical URLhttps://access.redhat.com/errata/RHSA-2025:1013Canonical URLhttps://access.redhat.com/errata/RHSA-2025:27002333856Canonical URLhttps://access.redhat.com/errata/RHSA-2025:0907https://access.redhat.com/security/updates/classification/#criticalhttps://docs.openshift.com/acs/4.6/release_notes/46-release-notes.htmlROX-27748Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses