Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat: RHSA-2021-3235-01 Important Update for Virtualization Host

red hat
Calendar Grey August 26, 2021
Dist Redhat Esm H88
Essential patch for Red Hat Virtualization tackling various vulnerabilities and rectifying bugs for improved efficiency.
An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/2974891

Summary

The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.
Security Fix(es):
* edk2: remote buffer overflow in IScsiHexToBin function in NetworkPkg/IScsiDxe ()
* kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543)
* kernel: race condition in net/can/bcm.c leads to local privilege escalation (CVE-2021-3609)
* sssd: shell command injection in sssctl (CVE-2021-3621)
* kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Rebase package(s) to version: 1.2.23
Highlights, important fixes, or notable enhancements:
* imgbase should not copy the selinux binary policy file (BZ# 1979624) (BZ#1989397)
* RHV-H has been rebased on Red Hat Enterprise Linux 8.4 Batch #2. (BZ#1975177)

References

https://access.redhat.com/security/cve/CVE-2021-3609 https://access.redhat.com/security/cve/CVE-2021-3621 https://access.redhat.com/security/cve/CVE-2021-22543 https://access.redhat.com/security/cve/CVE-2021-22555 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Virtualization 4 Hypervisor for RHEL 8:
Source: redhat-virtualization-host-4.4.7-20210804.0.el8_4.src.rpm
x86_64: redhat-virtualization-host-image-update-4.4.7-20210804.0.el8_4.x86_64.rpm
RHEL 8-based RHEV-H for RHEV 4 (build requirements):
Source: imgbased-1.2.23-1.el8ev.src.rpm redhat-release-virtualization-host-4.4.7-4.el8ev.src.rpm
noarch: imgbased-1.2.23-1.el8ev.noarch.rpm python3-imgbased-1.2.23-1.el8ev.noarch.rpm redhat-virtualization-host-image-update-placeholder-4.4.7-4.el8ev.noarch.rpm
x86_64: redhat-release-virtualization-host-4.4.7-4.el8ev.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2021:3235-01
Product: Red Hat Virtualization
Issue date: 2021-08-19

Topic

An update for imgbased, redhat-release-virtualization-host, andredhat-virtualization-host is now available for Red Hat Virtualization 4for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactofImportant. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64

Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64

Bugs Fixed

1956284 - edk2: remote buffer overflow in IScsiHexToBin function in NetworkPkg/IScsiDxe

1965461 - CVE-2021-22543 kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks

1971651 - CVE-2021-3609 kernel: race condition in net/can/bcm.c leads to local privilege escalation

1975142 - CVE-2021-3621 sssd: shell command injection in sssctl

1975177 - Rebase RHV-H 4.4.7 on RHEL 8.4.0.2

1980101 - CVE-2021-22555 kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c

1989397 - Upgrade imgbased to 1.2.23

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here