RHSA-2020:3194: Important: Container-native Virtualization security, bug fix, and enhancement update
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.Security Fix(es): kubevirt: VMIs can be used to access host files (CVE-2020-14316) containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters (CVE-2020-10749) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:This update also fixes several bugs and adds various enhancements.This advisory contains the following OpenShift Virtualization 2.4.0 images:RHEL-7-CNV-2.4==============kubevirt-ssp-operator-container-v2.4.0-71RHEL-8-CNV-2.4==============virt-cdi-controller-container-v2.4.0-29virt-cdi-uploadproxy-container-v2.4.0-29hostpath-provisioner-container-v2.4.0-25virt-cdi-operator-container-v2.4.0-29kubevirt-metrics-collector-container-v2.4.0-18cnv-containernetworking-plugins-container-v2.4.0-36kubevirt-kvm-info-nfd-plugin-container-v2.4.0-18hostpath-provisioner-operator-container-v2.4.0-31virt-cdi-uploadserver-container-v2.4.0-29virt-cdi-apiserver-container-v2.4.0-29virt-controller-container-v2.4.0-58virt-cdi-cloner-container-v2.4.0-29kubevirt-template-validator-container-v2.4.0-21vm-import-operator-container-v2.4.0-21kubernetes-nmstate-handler-container-v2.4.0-37node-maintenance-operator-container-v2.4.0-27virt-operator-container-v2.4.0-58kubevirt-v2v-conversion-container-v2.4.0-23cnv-must-gather-container-v2.4.0-73virtio-win-container-v2.4.0-15kubevirt-cpu-node-labeller-container-v2.4.0-19ovs-cni-plugin-container-v2.4.0-37kubevirt-vmware-container-v2.4.0-21hyperconverged-cluster-operator-container-v2.4.0-70virt-handler-container-v2.4.0-58virt-cdi-importer-container-v2.4.0-29virt-launcher-container-v2.4.0-58kubevirt-cpu-model-nfd-plugin-container-v2.4.0-17virt-api-container-v2.4.0-58ovs-cni-marker-container-v2.4.0-38kubemacpool-container-v2.4.0-39cluster-network-addons-operator-container-v2.4.0-38bridge-marker-container-v2.4.0-39vm-import-controller-container-v2.4.0-21hco-bundle-registry-container-v2.3.0-497
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3194?
The severity of RHSA-2020:3194 is classified as critical due to vulnerabilities that could allow unauthorized access to host files and enable potential network exposure.
How do I fix RHSA-2020:3194?
To fix RHSA-2020:3194, you should apply the latest security updates as provided by Red Hat for OpenShift Virtualization.
What vulnerabilities are addressed in RHSA-2020:3194?
RHSA-2020:3194 addresses vulnerabilities including CVE-2020-14316 that allows VMIs to access host files.
Which products are affected by RHSA-2020:3194?
RHSA-2020:3194 affects the Red Hat OpenShift Container Platform, specifically its virtualization components.
Is there a workaround for RHSA-2020:3194?
There are no specific workarounds mentioned for RHSA-2020:3194, so immediate patching is recommended.