Skip to main content
EPSS 0.4%top 65%

Red Hat Security Advisory: Release of containers for RHOSO 18.0.17 security update

0
High
Published: 03/18/2026 (03/18/2026, 15:36:04 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenStack Services on OpenShift is a hybrid cloud solution for deploying and managing virtualized and containerized applications in a scalable infrastructure with a Red Hat OpenShift Container Platform (RHOCP) control plane. Security Fix(es): * golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Affected software

Affected versions
>=18.0.0 <18.0.17Red HatRed Hat OpenStack Services on OpenShiftRed Hat OpenStack Services on OpenShift 18.0amd64registry.redhat.io/rhoso-operators/barbican-rhel9-operator@sha256:11a6cc1c3c4713b49b7af1e94e9bc3fd6781589a6567d612276dbc5eec4e8f7c_amd64Red Hat OpenStack Services on OpenShift 18

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:41:11 UTC

Technical Analysis

CVE-2025-58183 is a denial of service vulnerability in the Go archive/tar package where tar.Reader does not limit the number of sparse region data blocks in GNU tar pax 1.0 sparse files. An attacker can craft a tar archive with a large number of sparse regions causing the Go program to allocate excessive memory, leading to out-of-memory conditions and denial of service. This affects applications using the vulnerable Go package to process such archives. Red Hat OpenStack Services on OpenShift versions >=18.0.0 and <18.0.17 are impacted. Red Hat has released updated containers in version 18.0.17 to fix this issue. The vulnerability has no impact beyond denial of service and requires processing a malicious tar archive to exploit.

Potential Impact

The vulnerability allows an attacker to cause denial of service by forcing a Go application to consume excessive memory when processing a specially crafted GNU tar pax 1.0 sparse archive. This results in out-of-memory conditions and application crashes. There is no confidentiality or integrity impact reported. No known exploits in the wild have been observed. The impact is limited to resource exhaustion leading to service disruption.

Mitigation Recommendations

Red Hat has released updated containers for Red Hat OpenStack Services on OpenShift version 18.0.17 that address this vulnerability. Users should apply this update to affected deployments. Before applying the update, ensure all previous errata are applied. No alternative mitigations are currently available or meet Red Hat's criteria for ease of use and applicability. Applying the official update is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:4936
Cve Count
2
Additional Cves
["CVE-2025-61729"]
State
PUBLISHED

Threat ID: 6a160970e29bf47b50637bdf

Added to database: 05/26/2026, 20:58:24 UTC

Last enriched: 08/14/2026, 22:41:11 UTC

Last updated: 09/14/2026, 01:36:22 UTC

Views: 93

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses