Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

RedHat Virtualization 4.4 Update: RHSA-2021-2866-01 Low Security Advisory

red hat
Calendar Grey July 22, 2021
Dist Redhat Esm H88
Oracle puts forth minor security updates for VM VirtualBox and Guest Additions, featuring performance improvements and repairs.
Updated dependency packages for ovirt-engine and ovirt-host that fix several bugs and add various enhancements are now available

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/2974891

Summary

The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.
The ovirt-ansible-hosted-engine-setup package provides an Ansible role for deploying Red Hat Virtualization Hosted-Engine.
Security Fix(es):
* ansible: multiple modules expose secured values (CVE-2021-3447)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Previously, using an Ansible playbook to fetch virtual machine disk information was slow and incomplete, while the REST API fetched the information faster and more completely. In this release, the Ansible playbook fetches the information completely and quickly. (BZ#1947902)
* The ovirt-engine in RHV 4.4.7 requires an Ansible 2.9.z version later than Ansible 2.9.20. In addition, in RHV 4.4.7 the version limitation for a specific Ansible version has been removed, the correct Ansible version is now shipped in the RHV subscription channels. (BZ#1966145)

References

https://access.redhat.com/security/cve/CVE-2021-3447 https://access.redhat.com/security/updates/classification/#low

Package List

Red Hat Virtualization 4 Tools for Red Hat Enterprise Linux 8:
Source: ovirt-ansible-collection-1.5.3-1.el8ev.src.rpm python-ovirt-engine-sdk4-4.4.13-1.el8ev.src.rpm
noarch: ovirt-ansible-collection-1.5.3-1.el8ev.noarch.rpm
ppc64le: python-ovirt-engine-sdk4-debugsource-4.4.13-1.el8ev.ppc64le.rpm python3-ovirt-engine-sdk4-4.4.13-1.el8ev.ppc64le.rpm python3-ovirt-engine-sdk4-debuginfo-4.4.13-1.el8ev.ppc64le.rpm
x86_64: python-ovirt-engine-sdk4-debugsource-4.4.13-1.el8ev.x86_64.rpm python3-ovirt-engine-sdk4-4.4.13-1.el8ev.x86_64.rpm python3-ovirt-engine-sdk4-debuginfo-4.4.13-1.el8ev.x86_64.rpm
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts:
Source: ansible-2.9.21-1.el8ae.src.rpm ovirt-ansible-collection-1.5.3-1.el8ev.src.rpm ovirt-imageio-2.2.0-1.el8ev.src.rpm ovirt-openvswitch-2.11-1.el8ev.src.rpm python-ovirt-engine-sdk4-4.4.13-1.el8ev.src.rpm
noarch: ansible-2.9.21-1.el8ae.noarch.rpm ovirt-ansible-collection-1.5.3-1.el8ev.noarch.rpm ovirt-openvswitch-2.11-1.el8ev.noarch.rpm ovirt-openvswitch-devel-2.11-1.el8ev.noarch.rpm ovirt-openvswitch-ovn-2.11-1.el8ev.noarch.rpm ovirt-openvswitch-ovn-central-2.11-1.el8ev.noarch.rpm ovirt-openvswitch-ovn-common-2.11-1.el8ev.noarch.rpm ovirt-openvswitch-ovn-host-2.11-1.el8ev.noarch.rpm

Read the Full Advisory


Severity
low
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2021:2866-01
Product: Red Hat Virtualization
Issue date: 2021-07-22

Topic

Updated dependency packages for ovirt-engine and ovirt-host that fixseveral bugs and add various enhancements are now available.Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4 - noarch, x86_64

Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts - noarch, ppc64le, x86_64

Red Hat Virtualization 4 Tools for Red Hat Enterprise Linux 8 - noarch, ppc64le, x86_64

Bugs Fixed

1939349 - CVE-2021-3447 ansible: multiple modules expose secured values

1947902 - ansible modules for gathering VM information are incomplete and very slow

1953029 - HE deployment fails on "Add lines to answerfile"

1966145 - Remove version lock on specific ansible version and require ansible 2.9.z >= 2.9.21 in ovirt-engine

1969855 - [RFE] Update ovirt_vm module to allow setting multiple hosts for PlacementPolicy when affinity is "pinned"

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here