First published: Thu Oct 10 2019(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, redhat-virtualization-host, and ovirt-node-ng. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>The following packages have been upgraded to a later upstream version: imgbased (1.1.10), ovirt-node-ng (4.3.6), redhat-release-virtualization-host (4.3.6), redhat-virtualization-host (4.3.6). (BZ#1734624, BZ#1737771, BZ#1752750)<br>Security Fix(es):<br><li> kernel: hw: Spectre SWAPGS gadget vulnerability (CVE-2019-1125)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> RHVH 4.3.6: Incorrect welcome info appear in RHVH boot process (BZ#1736798)</li> <li> The company logo displays wrong. (BZ#1738457)</li> Enhancement(s):<br><li> [downstream clone - 4.3.6] [RFE] Warn if SELinux is disabled when upgrading RHV-H (BZ#1744027)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/imgbased | <1.1.10-0.1.el7e | 1.1.10-0.1.el7e |
redhat/ovirt-node-ng | <4.3.6-0.20190820.0.el7e | 4.3.6-0.20190820.0.el7e |
redhat/redhat-release-virtualization-host | <4.3.6-2.el7e | 4.3.6-2.el7e |
redhat/redhat-virtualization-host | <4.3.6-20190924.0.el7_7 | 4.3.6-20190924.0.el7_7 |
redhat/ovirt-node-ng-nodectl | <4.3.6-0.20190820.0.el7e | 4.3.6-0.20190820.0.el7e |
redhat/python-imgbased | <1.1.10-0.1.el7e | 1.1.10-0.1.el7e |
redhat/python2-ovirt-node-ng-nodectl | <4.3.6-0.20190820.0.el7e | 4.3.6-0.20190820.0.el7e |
redhat/redhat-virtualization-host-image-update | <4.3.6-20190924.0.el7_7 | 4.3.6-20190924.0.el7_7 |
redhat/redhat-virtualization-host-image-update-placeholder | <4.3.6-2.el7e | 4.3.6-2.el7e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The RHSA-2019:3011 vulnerability is classified with critical severity due to its potential impact on the security of Red Hat Virtualization Hosts.
To fix RHSA-2019:3011, users should update their packages to the specified remedied versions as outlined in the advisory.
The affected packages include redhat-virtualization-host, ovirt-node-ng, and various related packages of Red Hat.
Failing to address RHSA-2019:3011 could lead to security vulnerabilities that may expose systems to unauthorized access or exploitation.
The recommended versions to mitigate RHSA-2019:3011 include specific updates for each affected package, such as redhat-virtualization-host version 4.3.6-20190924.0.el7_7.