RHSA-2022:5678: Important: Red Hat Virtualization security, bug fix, and enhancement update [ovirt-4.5.1]
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.The following packages have been upgraded to a later upstream version: redhat-release-virtualization-host (4.5.1), redhat-virtualization-host (4.5.1), redhat-virtualization-host-productimg (4.5.1). (BZ#2062192, BZ#2070869, BZ#2094682)Security Fix(es): kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666) grub2: Integer underflow in grubnetrecvip4packets (CVE-2022-28733) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): RHV-H 4.4 SP1 Has been rebased on RHEL 8.6 Batch #1 (BZ#2070869)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5678?
The severity of RHSA-2022:5678 is considered important.
How do I fix RHSA-2022:5678?
To fix RHSA-2022:5678, update the affected redhat-virtualization-host packages to the specified versions provided in the advisory.
Which packages are affected by RHSA-2022:5678?
Affected packages include redhat-release-virtualization-host, redhat-virtualization-host-productimg, redhat-release-virtualization-host-content, and redhat-virtualization-host-image-update-placeholder.
What is the recommended version to upgrade for RHSA-2022:5678?
The recommended version to upgrade to for RHSA-2022:5678 is 4.5.1-1.el8e or the specified versions for other affected packages.
Is there a known exploit for RHSA-2022:5678?
As of now, there are no publicly available exploits documented for RHSA-2022:5678.