First published: Thu May 18 2023(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>This advisory contains OpenShift Virtualization 4.13.0 RPMs.<br>Security Fix(es):<br><li> golang: net/<a href="http:" target="_blank">http:</a> handle server errors after sending GOAWAY (CVE-2022-27664)</li> <li> golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags (CVE-2022-32149)</li> <li> golang: net/url: JoinPath does not strip relative path components in all circumstances (CVE-2022-32190)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)</li> <li> golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> 4.13.0 rpms (BZ#2124993)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kubevirt | <4.13.0-1469.el9 | 4.13.0-1469.el9 |
redhat/kubevirt-virtctl | <4.13.0-1469.el9 | 4.13.0-1469.el9 |
redhat/kubevirt-virtctl-redistributable | <4.13.0-1469.el9 | 4.13.0-1469.el9 |
redhat/kubevirt | <4.13.0-1469.el8 | 4.13.0-1469.el8 |
redhat/kubevirt-virtctl | <4.13.0-1469.el8 | 4.13.0-1469.el8 |
redhat/kubevirt-virtctl-redistributable | <4.13.0-1469.el8 | 4.13.0-1469.el8 |
redhat/kubevirt | <4.13.0-1469.el7 | 4.13.0-1469.el7 |
redhat/kubevirt-virtctl | <4.13.0-1469.el7 | 4.13.0-1469.el7 |
redhat/kubevirt-virtctl-redistributable | <4.13.0-1469.el7 | 4.13.0-1469.el7 |
redhat/kubevirt-virtctl | <4.13.0-1469.el9.aa | 4.13.0-1469.el9.aa |
redhat/kubevirt-virtctl-redistributable | <4.13.0-1469.el9.aa | 4.13.0-1469.el9.aa |
redhat/kubevirt-virtctl | <4.13.0-1469.el8.aa | 4.13.0-1469.el8.aa |
redhat/kubevirt-virtctl-redistributable | <4.13.0-1469.el8.aa | 4.13.0-1469.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.