First published: Tue Nov 22 2022(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. <br>The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>The following packages have been upgraded to a later upstream version: redhat-release-virtualization-host (4.5.2), redhat-virtualization-host (4.5.2), redhat-virtualization-host-productimg (4.5.2). (BZ#2070049, BZ#2093195)<br>Security Fix(es):<br><li> libksba: integer overflow may lead to remote code execution (CVE-2022-3515)</li> <li> bind: memory leak in ECDSA DNSSEC verification code (CVE-2022-38177)</li> <li> bind: memory leaks in EdDSA DNSSEC verification code (CVE-2022-38178)</li> <li> expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674)</li> <li> device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket (CVE-2022-41974)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/redhat-release-virtualization-host | <4.5.3-1.el8e | 4.5.3-1.el8e |
redhat/redhat-virtualization-host-productimg | <4.5.3-1.el8 | 4.5.3-1.el8 |
redhat/redhat-release-virtualization-host-content | <4.5.3-1.el8e | 4.5.3-1.el8e |
redhat/redhat-virtualization-host-image-update-placeholder | <4.5.3-1.el8e | 4.5.3-1.el8e |
redhat/redhat-virtualization-host-productimg | <4.5.3-1.el8 | 4.5.3-1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.