-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Virtualization security, bug fix, and enhancement update Advisory ID: RHSA-2021:0028-01 Product: Red Hat Virtualization Advisory URL: https://access.redhat.com/errata/RHSA-2021:0028 Issue date: 2021-01-06 CVE Names: CVE-2015-8011 ==================================================================== 1. Summary: An update for openvswitch2.11, ovn2.11, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: RHEL 7-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64 RHV-M 4.3 - x86_64 Red Hat Virtualization 4 Hypervisor for RHEL 7 - noarch Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts - ppc64le, x86_64 3. Description: The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. The following packages have been upgraded to a later upstream version: openvswitch2.11 (2.11.3), ovn2.11 (2.11.1), redhat-release-virtualization-host (4.3.12), redhat-virtualization-host (4.3.12). (BZ#1898513, BZ#1907537, BZ#1907538) Security Fix(es): * lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c (CVE-2015-8011) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 5. Bugs fixed (https://bugzilla.redhat.com/): 1896536 - CVE-2015-8011 lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c 1898513 - Rebase RHV-H 4.3 EUS on RHEL-7.9.z #2 6. Package List: Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts: Source: openvswitch2.11-2.11.3-77.el7fdp.src.rpm ovn2.11-2.11.1-56.el7fdp.src.rpm ppc64le: openvswitch2.11-2.11.3-77.el7fdp.ppc64le.rpm openvswitch2.11-debuginfo-2.11.3-77.el7fdp.ppc64le.rpm openvswitch2.11-devel-2.11.3-77.el7fdp.ppc64le.rpm ovn2.11-2.11.1-56.el7fdp.ppc64le.rpm ovn2.11-debuginfo-2.11.1-56.el7fdp.ppc64le.rpm ovn2.11-host-2.11.1-56.el7fdp.ppc64le.rpm ovn2.11-vtep-2.11.1-56.el7fdp.ppc64le.rpm python-openvswitch2.11-2.11.3-77.el7fdp.ppc64le.rpm x86_64: openvswitch2.11-2.11.3-77.el7fdp.x86_64.rpm openvswitch2.11-debuginfo-2.11.3-77.el7fdp.x86_64.rpm openvswitch2.11-devel-2.11.3-77.el7fdp.x86_64.rpm ovn2.11-2.11.1-56.el7fdp.x86_64.rpm ovn2.11-debuginfo-2.11.1-56.el7fdp.x86_64.rpm ovn2.11-host-2.11.1-56.el7fdp.x86_64.rpm ovn2.11-vtep-2.11.1-56.el7fdp.x86_64.rpm python-openvswitch2.11-2.11.3-77.el7fdp.x86_64.rpm Red Hat Virtualization 4 Hypervisor for RHEL 7: Source: redhat-virtualization-host-4.3.12-20201216.0.el7_9.src.rpm noarch: redhat-virtualization-host-image-update-4.3.12-20201216.0.el7_9.noarch.rpm RHEL 7-based RHEV-H for RHEV 4 (build requirements): Source: redhat-release-virtualization-host-4.3.12-4.el7ev.src.rpm redhat-virtualization-host-4.3.12-20201216.0.el7_9.src.rpm noarch: redhat-virtualization-host-image-update-4.3.12-20201216.0.el7_9.noarch.rpm redhat-virtualization-host-image-update-placeholder-4.3.12-4.el7ev.noarch.rpm x86_64: redhat-release-virtualization-host-4.3.12-4.el7ev.x86_64.rpm RHV-M 4.3: Source: openvswitch2.11-2.11.3-77.el7fdp.src.rpm ovn2.11-2.11.1-56.el7fdp.src.rpm x86_64: openvswitch2.11-2.11.3-77.el7fdp.x86_64.rpm openvswitch2.11-debuginfo-2.11.3-77.el7fdp.x86_64.rpm openvswitch2.11-devel-2.11.3-77.el7fdp.x86_64.rpm ovn2.11-2.11.1-56.el7fdp.x86_64.rpm ovn2.11-central-2.11.1-56.el7fdp.x86_64.rpm ovn2.11-debuginfo-2.11.1-56.el7fdp.x86_64.rpm ovn2.11-vtep-2.11.1-56.el7fdp.x86_64.rpm python-openvswitch2.11-2.11.3-77.el7fdp.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-8011 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX/WeHtzjgjWX9erEAQhq4Q//fdcK49h4XI0Wjh6rSt4t1PtJEeirqeFh ptx1eYMvliONrHebCXjDgXYdMttVgotw26lu9kNzfHsTO/jtA6xkBEEKl5fAWjVL UZYSvy7OL/ht38OQ2hWmML5dUCqavFgA7Jf5SS7jtmnT7O9F7BhjanR7eWIP+eq7 jnx8p9PmywrVeKduh1ozBaBxicnOYzlD/ArTX3d+K5hmXVvDWH7wtL0c8HBpg6QB 5JbRY/86su+QnFN+BagqI27GiOcaGfqEDNSU5pMnxWslECA4PYXHf0OABbcRMebk mxHMP6ZhzZFq2f+paXAMy5dh5fCilJps979qCu5EFSbK2aVkYSEKvHqSyvk7pI+0 SLeU1/YxF5rnDmGGWIatKOMk5+0gMbe8bFZiJLbFkKeY3nzSyUCpoyswt1zWbxob gwmP9DDoH8z7LnDoHB8c7Q8iFQ+zsWMWr7LWt/q7nFNB1QtSKpnhC7EnaoAF4x7U ujHn74JgAAR+AVoMI6ScUDgOJn3Bn5TfhLpR0IzkYLN8bU1o+RgH4yClHgTG4axc kHqW+dMJxVqeXAfuy+1dpSr+NDx+wCAAvAGJxY7dfSTNEZY87h/0F4T6GsGbwpcA Kt7WQZoeyQa3RhihngnKQ3ppJCLXLnCC6247EylJg2KV11MZCs/LC61NwmC7T9UF lO2cuXmA6AI=o+f9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/2974891
The redhat-virtualization-host packages provide the Red Hat Virtualization
Host. These packages include redhat-release-virtualization-host,
ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are
installed using a special build of Red Hat Enterprise Linux with only the
packages required to host virtual machines. RHVH features a Cockpit user
interface for monitoring the host's resources and performing administrative
tasks.
The ovirt-node-ng packages provide the Red Hat Virtualization Host. These
packages include redhat-release-virtualization-host, ovirt-node, and
rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a
special build of Red Hat Enterprise Linux with only the packages required
to host virtual machines. RHVH features a Cockpit user interface for
monitoring the host's resources and performing administrative tasks.
The following packages have been upgraded to a later upstream version:
openvswitch2.11 (2.11.3), ovn2.11 (2.11.1),
redhat-release-virtualization-host (4.3.12), redhat-virtualization-host
(4.3.12). (BZ#1898513, BZ#1907537, BZ#1907538)
Security Fix(es):
* lldpd: buffer overflow in the lldp_decode function in
daemon/protocols/lldp.c (CVE-2015-8011)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2015-8011 https://access.redhat.com/security/updates/classification/#important
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts:
Source:
openvswitch2.11-2.11.3-77.el7fdp.src.rpm
ovn2.11-2.11.1-56.el7fdp.src.rpm
ppc64le:
openvswitch2.11-2.11.3-77.el7fdp.ppc64le.rpm
openvswitch2.11-debuginfo-2.11.3-77.el7fdp.ppc64le.rpm
openvswitch2.11-devel-2.11.3-77.el7fdp.ppc64le.rpm
ovn2.11-2.11.1-56.el7fdp.ppc64le.rpm
ovn2.11-debuginfo-2.11.1-56.el7fdp.ppc64le.rpm
ovn2.11-host-2.11.1-56.el7fdp.ppc64le.rpm
ovn2.11-vtep-2.11.1-56.el7fdp.ppc64le.rpm
python-openvswitch2.11-2.11.3-77.el7fdp.ppc64le.rpm
x86_64:
openvswitch2.11-2.11.3-77.el7fdp.x86_64.rpm
openvswitch2.11-debuginfo-2.11.3-77.el7fdp.x86_64.rpm
openvswitch2.11-devel-2.11.3-77.el7fdp.x86_64.rpm
ovn2.11-2.11.1-56.el7fdp.x86_64.rpm
ovn2.11-debuginfo-2.11.1-56.el7fdp.x86_64.rpm
ovn2.11-host-2.11.1-56.el7fdp.x86_64.rpm
ovn2.11-vtep-2.11.1-56.el7fdp.x86_64.rpm
python-openvswitch2.11-2.11.3-77.el7fdp.x86_64.rpm
Red Hat Virtualization 4 Hypervisor for RHEL 7:
Source:
redhat-virtualization-host-4.3.12-20201216.0.el7_9.src.rpm
noarch:
redhat-virtualization-host-image-update-4.3.12-20201216.0.el7_9.noarch.rpm
RHEL 7-based RHEV-H for RHEV 4 (build requirements):
Source:
redhat-release-virtualization-host-4.3.12-4.el7ev.src.rpm
redhat-virtualization-host-4.3.12-20201216.0.el7_9.src.rpm
noarch:
Read the Full Advisory
An update for openvswitch2.11, ovn2.11, redhat-release-virtualization-host,and redhat-virtualization-host is now available for Red Hat Virtualization4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
RHEL 7-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64
RHV-M 4.3 - x86_64
Red Hat Virtualization 4 Hypervisor for RHEL 7 - noarch
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts - ppc64le, x86_64
1896536 - CVE-2015-8011 lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c
1898513 - Rebase RHV-H 4.3 EUS on RHEL-7.9.z #2
Get the latest Linux and open source security news straight to your inbox.