-
Bug
-
Resolution: Unresolved
-
Undefined
-
None
-
4.16.z
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
Moderate
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
The scanner reports that cve [1] is affecting the oc cli binary with the dependency package "xz" at version 0.5.11. [2] Requesting The version '0.5.15' of the "xz" should contain the fix for the cve. The cve report came from the ACS scanner. Other versions affected - [3][4][5] [1] https://access.redhat.com/security/cve/cve-2025-58058 [2] https://github.com/openshift/oc/blob/release-4.16/go.mod#L179 [3] https://github.com/openshift/oc/blob/release-4.17/go.mod#L183 [4] https://github.com/openshift/oc/blob/release-4.18/go.mod#L182 [5] https://github.com/openshift/oc/blob/release-4.19/go.mod#L179
Version-Release number of selected component (if applicable):
OpenShift Container Platform 4.16.z