Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section.
AI Analysis
Technical Summary
CVE-2025-57847 is a container privilege escalation flaw in Red Hat Ansible Automation Platform 2.5 images. The vulnerability arises because the /etc/passwd file is created with group-writable permissions during the build process. If an attacker can execute commands inside the container and is a member of the root group, they can modify /etc/passwd to add a new user with any UID, including UID 0, effectively gaining root privileges inside the container. Red Hat states that OpenShift's default Security Context Constraints and SELinux policies mitigate this risk effectively. The vulnerability is rated moderate severity for OpenShift but may have different impacts in other container environments. The issue is addressed by updated container images released by Red Hat.
Potential Impact
The vulnerability allows an attacker with command execution inside an affected container and root group membership to escalate privileges to root within that container by modifying /etc/passwd. This could lead to full root access inside the container environment. However, in OpenShift environments, default security mechanisms such as Security Context Constraints and SELinux provide effective mitigation, reducing the practical impact. The vulnerability does not affect the host system or other containers directly. The flaw is due to incorrect file permissions set during image build.
Mitigation Recommendations
Red Hat has released updated container images for Ansible Automation Platform 2.5 that fix the incorrect permissions on /etc/passwd. Users should apply these updates after ensuring all prior relevant errata are applied. For OpenShift users, the default security posture effectively mitigates this vulnerability, so no additional action may be required beyond applying updates. For other container runtimes, users should evaluate their environment's security controls and apply the updated images promptly. Refer to Red Hat's official advisory and upgrade documentation for detailed instructions.
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update
Description
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-57847 is a container privilege escalation flaw in Red Hat Ansible Automation Platform 2.5 images. The vulnerability arises because the /etc/passwd file is created with group-writable permissions during the build process. If an attacker can execute commands inside the container and is a member of the root group, they can modify /etc/passwd to add a new user with any UID, including UID 0, effectively gaining root privileges inside the container. Red Hat states that OpenShift's default Security Context Constraints and SELinux policies mitigate this risk effectively. The vulnerability is rated moderate severity for OpenShift but may have different impacts in other container environments. The issue is addressed by updated container images released by Red Hat.
Potential Impact
The vulnerability allows an attacker with command execution inside an affected container and root group membership to escalate privileges to root within that container by modifying /etc/passwd. This could lead to full root access inside the container environment. However, in OpenShift environments, default security mechanisms such as Security Context Constraints and SELinux provide effective mitigation, reducing the practical impact. The vulnerability does not affect the host system or other containers directly. The flaw is due to incorrect file permissions set during image build.
Mitigation Recommendations
Red Hat has released updated container images for Ansible Automation Platform 2.5 that fix the incorrect permissions on /etc/passwd. Users should apply these updates after ensuring all prior relevant errata are applied. For OpenShift users, the default security posture effectively mitigates this vulnerability, so no additional action may be required beyond applying updates. For other container runtimes, users should evaluate their environment's security controls and apply the updated images promptly. Refer to Red Hat's official advisory and upgrade documentation for detailed instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:42144
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-8643","CVE-2026-44431","CVE-2026-44432","CVE-2026-48526"]
- Cvss Version
- null
Threat ID: 6a5fd0a31010f89cc219a998
Added to database: 07/21/2026, 20:03:47 UTC
Last enriched: 08/15/2026, 18:06:44 UTC
Last updated: 09/01/2026, 22:52:07 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.