First published: Mon Apr 10 2023(Updated: )
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. <br>The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>Security Fix(es):<br><li> git: gitattributes parsing integer overflow (CVE-2022-23521)</li> <li> git: Heap overflow in `git archive`, `git log --format` leading to RCE (CVE-2022-41903)</li> <li> ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)</li> <li> kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386)</li> <li> nss: Arbitrary memory write via PKCS 12 (CVE-2023-0767)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/redhat-release-virtualization-host | <4.5.3-6.el8e | 4.5.3-6.el8e |
redhat/redhat-release-virtualization-host-content | <4.5.3-6.el8e | 4.5.3-6.el8e |
redhat/redhat-virtualization-host-image-update-placeholder | <4.5.3-6.el8e | 4.5.3-6.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.