First published: Wed May 02 2018(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>Security Fix(es):<br><li> glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled (CVE-2018-1088)</li> <li> It was found that fix for CVE-2018-1088 introduced new vulnerability in the way 'auth.allow' is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes. (CVE-2018-1112)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>This issue was discovered by John Strunk (Red Hat).
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/redhat-release-virtualization-host | <4.1-11.0.el7 | 4.1-11.0.el7 |
redhat/redhat-release-virtualization-host | <4.1-11.0.el7 | 4.1-11.0.el7 |
redhat/redhat-virtualization-host-image-update-placeholder | <4.1-11.0.el7 | 4.1-11.0.el7 |
redhat/redhat-virtualization-host | <4.1-20180426.0.el7_5 | 4.1-20180426.0.el7_5 |
redhat/redhat-virtualization-host-image-update | <4.1-20180426.0.el7_5 | 4.1-20180426.0.el7_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:1275 is classified as important.
To fix RHSA-2018:1275, update the affected packages to version 4.1-11.0.el7 or 4.1-20180426.0.el7_5.
The affected packages include redhat-release-virtualization-host and redhat-virtualization-host.
RHSA-2018:1275 impacts systems running Red Hat Virtualization Host with specific version limitations.
There are no official workarounds for the vulnerabilities addressed in RHSA-2018:1275, the update should be applied.