RHSA-2018:1275: Important: redhat-virtualization-host security update
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>Security Fix(es):<br><li> glusterfs: Privilege escalation via glustersharedstorage when snapshot scheduling is enabled (CVE-2018-1088)</li> <li> It was found that fix for CVE-2018-1088 introduced new vulnerability in the way 'auth.allow' is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes. (CVE-2018-1112)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>This issue was discovered by John Strunk (Red Hat).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:1275?
The severity of RHSA-2018:1275 is classified as important.
How do I fix RHSA-2018:1275?
To fix RHSA-2018:1275, update the affected packages to version 4.1-11.0.el7 or 4.1-20180426.0.el7_5.
Which packages are affected by RHSA-2018:1275?
The affected packages include redhat-release-virtualization-host and redhat-virtualization-host.
What type of systems are impacted by RHSA-2018:1275?
RHSA-2018:1275 impacts systems running Red Hat Virtualization Host with specific version limitations.
Is there a workaround for RHSA-2018:1275?
There are no official workarounds for the vulnerabilities addressed in RHSA-2018:1275, the update should be applied.