First published: Wed Sep 14 2022(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>This advisory contains OpenShift Virtualization 4.11.0 RPMs.<br>Security Fix(es):<br><li> golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kubevirt | <4.11.0-643.el8 | 4.11.0-643.el8 |
redhat/kubevirt-virtctl | <4.11.0-643.el8 | 4.11.0-643.el8 |
redhat/kubevirt-virtctl-redistributable | <4.11.0-643.el8 | 4.11.0-643.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:6527 is classified as moderate due to the potential impact of the vulnerability on OpenShift Virtualization.
To fix RHSA-2022:6527, update to OpenShift Virtualization version 4.11.0-643.el8 or later.
RHSA-2022:6527 addresses CVE-2022-27191, which involves a crash in a golang.org/x/crypto/ssh server.
The affected packages in RHSA-2022:6527 include kubevirt, kubevirt-virtctl, and kubevirt-virtctl-redistributable.
No, RHSA-2022:6527 is specifically applicable to OpenShift Virtualization versions up to and including 4.11.0-643.el8.