Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-62655

Update the dependency "docker/docker" to fix CVE-2025-54410 and CVE-2024-41110

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.16.z
    • oc
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      The scanner reports that cve [1] and [2] is affecting the oc cli binary with the dependency package "docker/docker" with version "v24.0.9+incompatible". [3]
      
      Per the links [4][5] the docker should be updated to version "25.0.12" or higher for [2] and "27.1.1" or higher for [1]. 
      
      The cve report came from the ACS scanner.
      
      [1] https://access.redhat.com/security/cve/cve-2024-41110
      [2] https://access.redhat.com/security/cve/cve-2025-54410 
      [3] https://github.com/openshift/oc/blob/release-4.16/go.mod#L19
      [4] https://nvd.nist.gov/vuln/detail/CVE-2024-41110
      [5] https://nvd.nist.gov/vuln/detail/CVE-2025-54410
      
      

      Version-Release number of selected component (if applicable):

      OpenShift Container Platform 4.16    

              aos-workloads-staff Workloads Team Bot Account
              rhn-support-vwalek Vladislav Walek
              None
              None
              Ying Zhou Ying Zhou
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: