First published: Tue Oct 06 2020(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>Security Fix(es):<br><li> golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586)</li> <li> golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Container-native Virtualization 2.4.2 Images (BZ#1877407)</li> This advisory contains the following OpenShift Virtualization 2.4.2 images:<br>RHEL-7-CNV-2.4<br>==============<br>kubevirt-ssp-operator-container-v2.4.2-2<br>RHEL-8-CNV-2.4<br>==============<br>virt-cdi-controller-container-v2.4.2-1<br>virt-cdi-apiserver-container-v2.4.2-1<br>hostpath-provisioner-operator-container-v2.4.2-1<br>virt-cdi-uploadproxy-container-v2.4.2-1<br>virt-cdi-cloner-container-v2.4.2-1<br>virt-cdi-importer-container-v2.4.2-1<br>kubevirt-template-validator-container-v2.4.2-1<br>hostpath-provisioner-container-v2.4.2-1<br>virt-cdi-uploadserver-container-v2.4.2-1<br>virt-cdi-operator-container-v2.4.2-1<br>virt-controller-container-v2.4.2-1<br>kubevirt-cpu-model-nfd-plugin-container-v2.4.2-1<br>virt-api-container-v2.4.2-1<br>ovs-cni-marker-container-v2.4.2-1<br>kubevirt-cpu-node-labeller-container-v2.4.2-1<br>bridge-marker-container-v2.4.2-1<br>kubevirt-metrics-collector-container-v2.4.2-1<br>kubemacpool-container-v2.4.2-1<br>cluster-network-addons-operator-container-v2.4.2-1<br>ovs-cni-plugin-container-v2.4.2-1<br>kubernetes-nmstate-handler-container-v2.4.2-1<br>cnv-containernetworking-plugins-container-v2.4.2-1<br>virtio-win-container-v2.4.2-1<br>virt-handler-container-v2.4.2-1<br>virt-launcher-container-v2.4.2-1<br>cnv-must-gather-container-v2.4.2-1<br>virt-operator-container-v2.4.2-1<br>vm-import-controller-container-v2.4.2-1<br>hyperconverged-cluster-operator-container-v2.4.2-1<br>vm-import-operator-container-v2.4.2-1<br>kubevirt-vmware-container-v2.4.2-1<br>kubevirt-v2v-conversion-container-v2.4.2-1<br>kubevirt-kvm-info-nfd-plugin-container-v2.4.2-1<br>node-maintenance-operator-container-v2.4.2-1<br>hco-bundle-registry-container-v2.4.2-15
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.