RHSA-2019:3011: Moderate: Red Hat Virtualization security, bug fix, and enhancement update
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, redhat-virtualization-host, and ovirt-node-ng. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.The following packages have been upgraded to a later upstream version: imgbased (1.1.10), ovirt-node-ng (4.3.6), redhat-release-virtualization-host (4.3.6), redhat-virtualization-host (4.3.6). (BZ#1734624, BZ#1737771, BZ#1752750)Security Fix(es): kernel: hw: Spectre SWAPGS gadget vulnerability (CVE-2019-1125) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): RHVH 4.3.6: Incorrect welcome info appear in RHVH boot process (BZ#1736798) The company logo displays wrong. (BZ#1738457) Enhancement(s): [downstream clone - 4.3.6] [RFE] Warn if SELinux is disabled when upgrading RHV-H (BZ#1744027)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/imgbasedto a version that resolves this vulnerability.Fixed in 1.1.10-0.1.el7e - Upgrade
Upgrade
redhat/ovirt-node-ngto a version that resolves this vulnerability.Fixed in 4.3.6-0.20190820.0.el7e - Upgrade
Upgrade
redhat/redhat-release-virtualization-hostto a version that resolves this vulnerability.Fixed in 4.3.6-2.el7e - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 4.3.6-20190924.0.el7_7 - Upgrade
Upgrade
redhat/ovirt-node-ng-nodectlto a version that resolves this vulnerability.Fixed in 4.3.6-0.20190820.0.el7e - Upgrade
Upgrade
redhat/python-imgbasedto a version that resolves this vulnerability.Fixed in 1.1.10-0.1.el7e - Upgrade
Upgrade
redhat/python2-ovirt-node-ng-nodectlto a version that resolves this vulnerability.Fixed in 4.3.6-0.20190820.0.el7e - Upgrade
Upgrade
redhat/redhat-virtualization-host-image-updateto a version that resolves this vulnerability.Fixed in 4.3.6-20190924.0.el7_7 - Upgrade
Upgrade
redhat/redhat-virtualization-host-image-update-placeholderto a version that resolves this vulnerability.Fixed in 4.3.6-2.el7e
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3011?
The RHSA-2019:3011 vulnerability is classified with critical severity due to its potential impact on the security of Red Hat Virtualization Hosts.
How do I fix RHSA-2019:3011?
To fix RHSA-2019:3011, users should update their packages to the specified remedied versions as outlined in the advisory.
Which packages are affected by RHSA-2019:3011?
The affected packages include redhat-virtualization-host, ovirt-node-ng, and various related packages of Red Hat.
Is there any risk if I do not address RHSA-2019:3011?
Failing to address RHSA-2019:3011 could lead to security vulnerabilities that may expose systems to unauthorized access or exploitation.
What are the recommended versions to mitigate RHSA-2019:3011?
The recommended versions to mitigate RHSA-2019:3011 include specific updates for each affected package, such as redhat-virtualization-host version 4.3.6-20190924.0.el7_7.