First published: Tue Feb 15 2022(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Security Fix(es):<br><li> polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector (CVE-2021-4034)</li> <li> kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL (CVE-2021-4155)</li> <li> aide: heap-based buffer overflow on outputs larger than B64_BUF (CVE-2021-45417)</li> <li> kernel: fs_context: heap overflow in legacy parameter handling (CVE-2022-0185)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Rebased wget package and its dependencies for the same version shipped with recent RHEL. (BZ#2030082)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/redhat-release-virtualization-host | <4.4.10-1.el8e | 4.4.10-1.el8e |
redhat/redhat-release-virtualization-host-content | <4.4.10-1.el8e | 4.4.10-1.el8e |
redhat/redhat-virtualization-host-image-update-placeholder | <4.4.10-1.el8e | 4.4.10-1.el8e |
redhat/libmetalink | <0.1.3-7.el8 | 0.1.3-7.el8 |
redhat/wget | <1.19.5-10.el8 | 1.19.5-10.el8 |
redhat/libmetalink | <0.1.3-7.el8 | 0.1.3-7.el8 |
redhat/libmetalink-debuginfo | <0.1.3-7.el8 | 0.1.3-7.el8 |
redhat/libmetalink-debugsource | <0.1.3-7.el8 | 0.1.3-7.el8 |
redhat/libmetalink-devel | <0.1.3-7.el8 | 0.1.3-7.el8 |
redhat/wget | <1.19.5-10.el8 | 1.19.5-10.el8 |
redhat/wget-debuginfo | <1.19.5-10.el8 | 1.19.5-10.el8 |
redhat/wget-debugsource | <1.19.5-10.el8 | 1.19.5-10.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0540 is classified as important.
To fix RHSA-2022:0540, ensure that you update the affected packages to the remedied versions 4.4.10-1.el8e for redhat-release-virtualization-host and 1.19.5-10.el8 for wget.
The affected packages include redhat-release-virtualization-host, redhat-release-virtualization-host-content, wget, and libmetalink.
Yes, RHSA-2022:0540 is specific to Red Hat Enterprise Linux 8.
You can check if your system is vulnerable by verifying the installed versions of the affected packages against the versions listed in the RHSA-2022:0540 advisory.