First published: Mon Nov 05 2018(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>Security Fix(es):<br><li> spice: Missing check in demarshal.py:write_validate_array_item() allows for buffer overflow and denial of service (CVE-2018-10873)</li> <li> glusterfs: Multiple flaws (CVE-2018-10904, CVE-2018-10907, CVE-2018-10923, CVE-2018-10926, CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, CVE-2018-10911, CVE-2018-10914, CVE-2018-14652, CVE-2018-14653, CVE-2018-14654, CVE-2018-14659, CVE-2018-14660, CVE-2018-14661, CVE-2018-10913)</li> <li> samba: Insufficient input validation in libsmbclient (CVE-2018-10858)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Michael Hanselmann (hansmi.ch) for reporting CVE-2018-10904, CVE-2018-10907, CVE-2018-10923, CVE-2018-10926, CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, CVE-2018-10911, CVE-2018-10914, CVE-2018-14652, CVE-2018-14653, CVE-2018-14654, CVE-2018-14659, CVE-2018-14660, CVE-2018-14661, and CVE-2018-10913. The CVE-2018-10873 issue was discovered by Frediano Ziglio (Red Hat).<br>Bug Fix(es):<br><li> When upgrading Red Hat Virtualization Host (RHVH), imgbased fails to run garbage collection on previous layers, so new logical volumes are removed, and the boot entry points to a logical volume that was removed.</li> If the RHVH upgrade finishes successfully, the hypervisor boots successfully, even if garbage collection fails. (BZ#1632058)<br><li> During the upgrade process, when lvremove runs garbage collection, it prompts for user confirmation, causing the upgrade process to fail. Now the process uses "lvremove --force" when trying to remove logical volumes and does not fail even if garbage collection fails, and as a result, the upgrade process finishes successfully. (BZ#1632585)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/imgbased | <1.0.29-1.el7e | 1.0.29-1.el7e |
redhat/redhat-release-virtualization-host | <4.2-7.3.el7 | 4.2-7.3.el7 |
redhat/python-imgbased | <1.0.29-1.el7e | 1.0.29-1.el7e |
redhat/redhat-release-virtualization-host | <4.2-7.3.el7 | 4.2-7.3.el7 |
redhat/redhat-virtualization-host-image-update-placeholder | <4.2-7.3.el7 | 4.2-7.3.el7 |
redhat/redhat-virtualization-host | <4.2-20181026.0.el7_6 | 4.2-20181026.0.el7_6 |
redhat/redhat-virtualization-host-image-update | <4.2-20181026.0.el7_6 | 4.2-20181026.0.el7_6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.