First published: Tue Jan 24 2023(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains the following OpenShift Virtualization 4.12.0 images:<br>Security Fix(es):<br><li> golang: net/<a href="http:" target="_blank">http:</a> limit growth of header canonicalization cache (CVE-2021-44716)</li> <li> kubeVirt: Arbitrary file read on the host from KubeVirt VMs (CVE-2022-1798)</li> <li> golang: out-of-bounds read in golang.org/x/text/language leads to DoS (CVE-2021-38561)</li> <li> golang: syscall: don't close fd 0 on ForkExec error (CVE-2021-44717)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> improper sanitization of Transfer-Encoding header (CVE-2022-1705)</li> <li> golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)</li> <li> golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString (CVE-2022-23772)</li> <li> golang: cmd/go: misinterpretation of branch names can lead to incorrect access control (CVE-2022-23773)</li> <li> golang: crypto/elliptic: IsOnCurve returns true for invalid field elements (CVE-2022-23806)</li> <li> golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)</li> <li> golang: syscall: faccessat checks wrong group (CVE-2022-29526)</li> <li> golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)</li> <li> golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)</li> <li> golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)</li> <li> golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)</li> <li> golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)</li> <li> golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)</li> <li> golang: crypto/tls: session tickets lack random ticket_age_add (CVE-2022-30629)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>RHEL-8-CNV-4.12<br>==============<br>bridge-marker-container-v4.12.0-24<br>cluster-network-addons-operator-container-v4.12.0-24<br>cnv-containernetworking-plugins-container-v4.12.0-24<br>cnv-must-gather-container-v4.12.0-58<br>hco-bundle-registry-container-v4.12.0-769<br>hostpath-csi-driver-container-v4.12.0-30<br>hostpath-provisioner-container-v4.12.0-30<br>hostpath-provisioner-operator-container-v4.12.0-31<br>hyperconverged-cluster-operator-container-v4.12.0-96<br>hyperconverged-cluster-webhook-container-v4.12.0-96<br>kubemacpool-container-v4.12.0-24<br>kubevirt-console-plugin-container-v4.12.0-182<br>kubevirt-ssp-operator-container-v4.12.0-64<br>kubevirt-tekton-tasks-cleanup-vm-container-v4.12.0-55<br>kubevirt-tekton-tasks-copy-template-container-v4.12.0-55<br>kubevirt-tekton-tasks-create-datavolume-container-v4.12.0-55<br>kubevirt-tekton-tasks-create-vm-from-template-container-v4.12.0-55<br>kubevirt-tekton-tasks-disk-virt-customize-container-v4.12.0-55<br>kubevirt-tekton-tasks-disk-virt-sysprep-container-v4.12.0-55<br>kubevirt-tekton-tasks-modify-vm-template-container-v4.12.0-55<br>kubevirt-tekton-tasks-operator-container-v4.12.0-40<br>kubevirt-tekton-tasks-wait-for-vmi-status-container-v4.12.0-55<br>kubevirt-template-validator-container-v4.12.0-32<br>libguestfs-tools-container-v4.12.0-255<br>ovs-cni-marker-container-v4.12.0-24<br>ovs-cni-plugin-container-v4.12.0-24<br>virt-api-container-v4.12.0-255<br>virt-artifacts-server-container-v4.12.0-255<br>virt-cdi-apiserver-container-v4.12.0-72<br>virt-cdi-cloner-container-v4.12.0-72<br>virt-cdi-controller-container-v4.12.0-72<br>virt-cdi-importer-container-v4.12.0-72<br>virt-cdi-operator-container-v4.12.0-72<br>virt-cdi-uploadproxy-container-v4.12.0-71<br>virt-cdi-uploadserver-container-v4.12.0-72<br>virt-controller-container-v4.12.0-255<br>virt-exportproxy-container-v4.12.0-255<br>virt-exportserver-container-v4.12.0-255<br>virt-handler-container-v4.12.0-255<br>virt-launcher-container-v4.12.0-255<br>virt-operator-container-v4.12.0-255<br>virtio-win-container-v4.12.0-10<br>vm-network-latency-checkup-container-v4.12.0-89
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.