First published: Mon Mar 14 2022(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>Security Fix(es):<br><li> kernel: improper initialization of the "flags" member of the new pipe_buffer (CVE-2022-0847)</li> <li> kernel: Use After Free in unix_gc() which could result in a local privilege escalation (CVE-2021-0920)</li> <li> kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154)</li> <li> kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330)</li> <li> kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435)</li> <li> kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942)</li> <li> cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands (CVE-2022-24407)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/redhat-release-virtualization-host | <4.4.10-2.el8e | 4.4.10-2.el8e |
redhat/redhat-release-virtualization-host-content | <4.4.10-2.el8e | 4.4.10-2.el8e |
redhat/redhat-virtualization-host-image-update-placeholder | <4.4.10-2.el8e | 4.4.10-2.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.