First published: Wed Mar 16 2022(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>This advisory contains the following OpenShift Virtualization 4.10.0 images:<br>RHEL-8-CNV-4.10<br>==============<br>kubevirt-velero-plugin-container-v4.10.0-8<br>virtio-win-container-v4.10.0-10<br>kubevirt-template-validator-container-v4.10.0-16<br>hostpath-csi-driver-container-v4.10.0-32<br>hostpath-provisioner-container-v4.10.0-32<br>hostpath-provisioner-operator-container-v4.10.0-62<br>cnv-must-gather-container-v4.10.0-110<br>virt-cdi-controller-container-v4.10.0-90<br>virt-cdi-apiserver-container-v4.10.0-90<br>virt-cdi-uploadserver-container-v4.10.0-90<br>virt-cdi-uploadproxy-container-v4.10.0-90<br>virt-cdi-operator-container-v4.10.0-90<br>virt-cdi-cloner-container-v4.10.0-90<br>virt-cdi-importer-container-v4.10.0-90<br>kubevirt-ssp-operator-container-v4.10.0-50<br>virt-api-container-v4.10.0-217<br>hyperconverged-cluster-webhook-container-v4.10.0-133<br>libguestfs-tools-container-v4.10.0-217<br>virt-handler-container-v4.10.0-217<br>virt-launcher-container-v4.10.0-217<br>virt-artifacts-server-container-v4.10.0-217<br>virt-controller-container-v4.10.0-217<br>node-maintenance-operator-container-v4.10.0-48<br>hyperconverged-cluster-operator-container-v4.10.0-133<br>virt-operator-container-v4.10.0-217<br>cnv-containernetworking-plugins-container-v4.10.0-49<br>kubemacpool-container-v4.10.0-49<br>bridge-marker-container-v4.10.0-49<br>ovs-cni-marker-container-v4.10.0-49<br>ovs-cni-plugin-container-v4.10.0-49<br>kubernetes-nmstate-handler-container-v4.10.0-49<br>cluster-network-addons-operator-container-v4.10.0-49<br>hco-bundle-registry-container-v4.10.0-696<br>Security Fix(es):<br><li> golang: net/<a href="http:" target="_blank">http:</a> limit growth of header canonicalization cache (CVE-2021-44716)</li> <li> golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet (CVE-2021-29923)</li> <li> golang: net: lookup functions may return invalid host names (CVE-2021-33195)</li> <li> golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)</li> <li> golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)</li> <li> golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)</li> <li> golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221)</li> <li> golang: syscall: don't close fd 0 on ForkExec error (CVE-2021-44717)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.