First published: Tue Nov 02 2021(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. <br>This advisory contains OpenShift Virtualization 4.9.0 RPMs.<br>Security Fix(es):<br><li> golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586)</li> <li> golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845)</li> <li> golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> panic in ReadRequest and ReadResponse when reading a very large header (CVE-2021-31525)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kubevirt | <4.9.0-287.el8 | 4.9.0-287.el8 |
redhat/kubevirt-virtctl | <4.9.0-287.el8 | 4.9.0-287.el8 |
redhat/kubevirt-virtctl-redistributable | <4.9.0-287.el8 | 4.9.0-287.el8 |
redhat/kubevirt | <4.9.0-287.el7 | 4.9.0-287.el7 |
redhat/kubevirt-virtctl | <4.9.0-287.el7 | 4.9.0-287.el7 |
redhat/kubevirt-virtctl-redistributable | <4.9.0-287.el7 | 4.9.0-287.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.