First published: Thu Sep 22 2022(Updated: )
This advisory contains the following OpenShift Virtualization 4.9.6 images:<br>RHEL-8-CNV-4.9<br>==============<br>cnv-must-gather-container-v4.9.6-7<br>kubevirt-template-validator-container-v4.9.6-6<br>kubevirt-ssp-operator-container-v4.9.6-5<br>virt-cdi-uploadserver-container-v4.9.6-4<br>virt-cdi-cloner-container-v4.9.6-4<br>virt-cdi-importer-container-v4.9.6-4<br>virt-cdi-uploadproxy-container-v4.9.6-4<br>virt-cdi-apiserver-container-v4.9.6-4<br>virt-cdi-controller-container-v4.9.6-4<br>virt-cdi-operator-container-v4.9.6-4<br>hostpath-provisioner-container-v4.9.6-3<br>hyperconverged-cluster-webhook-container-v4.9.6-3<br>hyperconverged-cluster-operator-container-v4.9.6-3<br>node-maintenance-operator-container-v4.9.6-4<br>kubevirt-vmware-container-v4.9.6-3<br>kubevirt-v2v-conversion-container-v4.9.6-3<br>ovs-cni-plugin-container-v4.9.6-3<br>cnv-containernetworking-plugins-container-v4.9.6-3<br>bridge-marker-container-v4.9.6-4<br>ovs-cni-marker-container-v4.9.6-3<br>kubemacpool-container-v4.9.6-4<br>kubernetes-nmstate-handler-container-v4.9.6-5<br>cluster-network-addons-operator-container-v4.9.6-5<br>virt-controller-container-v4.9.6-9<br>virt-handler-container-v4.9.6-9<br>virt-api-container-v4.9.6-9<br>virt-operator-container-v4.9.6-9<br>virt-artifacts-server-container-v4.9.6-9<br>virt-launcher-container-v4.9.6-9<br>libguestfs-tools-container-v4.9.6-9<br>virtio-win-container-v4.9.6-3<br>hostpath-provisioner-operator-container-v4.9.6-3<br>vm-import-operator-container-v4.9.6-3<br>vm-import-controller-container-v4.9.6-3<br>vm-import-virtv2v-container-v4.9.6-3<br>hco-bundle-registry-container-v4.9.6-51<br>Security Fix(es):<br><li> kubeVirt: Arbitrary file read on the host from KubeVirt VMs (CVE-2022-1798)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Virtualization |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:6681 is classified as important.
To fix RHSA-2022:6681, users should update to the latest recommended OpenShift Virtualization container images.
RHSA-2022:6681 affects OpenShift Virtualization components, specifically the versions listed in the advisory.
RHSA-2022:6681 addresses vulnerabilities related to container images used in OpenShift Virtualization.
Yes, immediate action is recommended to mitigate risks associated with the vulnerabilities addressed in RHSA-2022:6681.