Lucene search

K
redhatRedHatRHSA-2021:2920
HistoryJul 27, 2021 - 12:20 p.m.

(RHSA-2021:2920) Moderate: OpenShift Virtualization 4.8.0 Images

2021-07-2712:20:29
access.redhat.com
46

0.067 Low

EPSS

Percentile

93.9%

OpenShift Virtualization is Red Hat’s virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains the following OpenShift Virtualization 4.8.0 images:

RHEL-8-CNV-4.8

kubevirt-template-validator-container-v4.8.0-9
kubevirt-ssp-operator-container-v4.8.0-41
virt-cdi-uploadserver-container-v4.8.0-25
cnv-must-gather-container-v4.8.0-50
virt-cdi-uploadproxy-container-v4.8.0-25
virt-cdi-cloner-container-v4.8.0-25
virt-cdi-apiserver-container-v4.8.0-25
kubevirt-v2v-conversion-container-v4.8.0-10
hostpath-provisioner-operator-container-v4.8.0-17
hyperconverged-cluster-webhook-container-v4.8.0-62
hyperconverged-cluster-operator-container-v4.8.0-62
virt-cdi-operator-container-v4.8.0-25
virt-cdi-importer-container-v4.8.0-25
virt-cdi-controller-container-v4.8.0-25
cnv-containernetworking-plugins-container-v4.8.0-14
kubemacpool-container-v4.8.0-22
ovs-cni-plugin-container-v4.8.0-17
ovs-cni-marker-container-v4.8.0-17
bridge-marker-container-v4.8.0-17
cluster-network-addons-operator-container-v4.8.0-28
kubernetes-nmstate-handler-container-v4.8.0-21
virtio-win-container-v4.8.0-9
kubevirt-vmware-container-v4.8.0-11
hostpath-provisioner-container-v4.8.0-14
node-maintenance-operator-container-v4.8.0-19
virt-launcher-container-v4.8.0-67
vm-import-virtv2v-container-v4.8.0-18
vm-import-controller-container-v4.8.0-18
vm-import-operator-container-v4.8.0-18
virt-handler-container-v4.8.0-67
virt-api-container-v4.8.0-67
virt-controller-container-v4.8.0-67
virt-operator-container-v4.8.0-67
hco-bundle-registry-container-v4.8.0-451

Security Fix(es):

  • golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference (CVE-2020-29652)

  • gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation (CVE-2021-3121)

  • golang-github-gorilla-websocket: integer overflow leads to denial of service (CVE-2020-27813)

  • golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114)

  • ulikunitz/xz: Infinite loop in readUvarint allows for denial of service (CVE-2021-29482)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.