Lucene search

K
redhatRedHatRHSA-2022:6351
HistorySep 06, 2022 - 1:25 p.m.

(RHSA-2022:6351) Important: OpenShift Virtualization 4.10.5 Images security and bug fix update

2022-09-0613:25:31
access.redhat.com
19
openshift virtualization
security fixes
cve-2022-1798
cve-2022-1996
red hat
container platform

0.002 Low

EPSS

Percentile

62.2%

OpenShift Virtualization is Red Hat’s virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains the following OpenShift Virtualization 4.10.5 images:

RHEL-8-CNV-4.10

cluster-network-addons-operator-container-v4.10.5-1
kubemacpool-container-v4.10.5-1
virt-cdi-importer-container-v4.10.5-1
hyperconverged-cluster-operator-container-v4.10.5-1
hostpath-provisioner-operator-container-v4.10.5-1
virtio-win-container-v4.10.5-1
virt-cdi-cloner-container-v4.10.5-1
kubevirt-ssp-operator-container-v4.10.5-1
cnv-containernetworking-plugins-container-v4.10.5-1
hyperconverged-cluster-webhook-container-v4.10.5-1
virt-cdi-apiserver-container-v4.10.5-1
ovs-cni-plugin-container-v4.10.5-1
virt-cdi-uploadserver-container-v4.10.5-1
virt-cdi-uploadproxy-container-v4.10.5-1
virt-cdi-controller-container-v4.10.5-1
kubevirt-template-validator-container-v4.10.5-1
virt-cdi-operator-container-v4.10.5-1
hostpath-provisioner-container-v4.10.5-1
hostpath-csi-driver-container-v4.10.5-1
kubernetes-nmstate-handler-container-v4.10.5-1
ovs-cni-marker-container-v4.10.5-1
bridge-marker-container-v4.10.5-1
node-maintenance-operator-container-v4.10.5-1
cnv-must-gather-container-v4.10.5-2
virt-controller-container-v4.10.5-3
virt-api-container-v4.10.5-3
virt-handler-container-v4.10.5-3
virt-operator-container-v4.10.5-3
virt-artifacts-server-container-v4.10.5-3
virt-launcher-container-v4.10.5-3
libguestfs-tools-container-v4.10.5-3
hco-bundle-registry-container-v4.10.5-6

Security Fix(es):

  • kubeVirt: Arbitrary file read on the host from KubeVirt VMs (CVE-2022-1798)

  • go-restful: Authorization Bypass Through User-Controlled Key (CVE-2022-1996)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.