-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Critical: Red Hat Virtualization Host security and bug fix update [ovirt-4.4.9] Async #1
Advisory ID:       RHSA-2021:5006-01
Product:           Red Hat Virtualization
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:5006
Issue date:        2021-12-08
CVE Names:         CVE-2021-43527 
====================================================================
1. Summary:

An update for redhat-release-virtualization-host and
redhat-virtualization-host is now available for Red Hat Virtualization 4
for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64
Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64

3. Description:

The redhat-virtualization-host packages provide the Red Hat Virtualization
Host. These packages include redhat-release-virtualization-host,
ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are
installed using a special build of Red Hat Enterprise Linux with only the
packages required to host virtual machines. RHVH features a Cockpit user
interface for monitoring the host's resources and performing administrative
tasks.

Security Fix(es):

* nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and
RSA-PSS) (CVE-2021-43527)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/2974891

5. Bugs fixed (https://bugzilla.redhat.com/):

2024370 - CVE-2021-43527 nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
2029406 - Could not find available upgrade package, when upgrade RHVH to the latest rhvh-4.4.9.3-0.20211202.0+1

6. Package List:

Red Hat Virtualization 4 Hypervisor for RHEL 8:

Source:
redhat-virtualization-host-4.4.9-202112061811_8.5.src.rpm

x86_64:
redhat-virtualization-host-image-update-4.4.9-202112061811_8.5.x86_64.rpm

RHEL 8-based RHEV-H for RHEV 4 (build requirements):

Source:
redhat-release-virtualization-host-4.4.9-3.el8ev.src.rpm

noarch:
redhat-virtualization-host-image-update-placeholder-4.4.9-3.el8ev.noarch.rpm

x86_64:
redhat-release-virtualization-host-4.4.9-3.el8ev.x86_64.rpm
redhat-release-virtualization-host-content-4.4.9-3.el8ev.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2021-43527
https://access.redhat.com/security/updates/classification/#critical
https://access.redhat.com/security/vulnerabilities/RHSB-2021-008

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYbC279zjgjWX9erEAQgd0g/+Oip0y8d3cR1KhdCOD3/gat0yaMometjv
uu6KDBUeq1OU6nfn7rj+cMHTS+qCSt4K0nR+MAi1WsfEQg+avTWKYRoJie4WZXrA
58gxS0iI3vRYhMiwtGj+C3F1QXogEGWayI9B+mgSmNERQfi4HIm40ul8+Xxm97vJ
Z4gplJ0Ewr6xrxJsMbDZbg2PKwgZRbS6lbxytYE2+LjCk3NFY8xtgijHqmS5O+Cq
jsUFGagwb4p9gmR3M3XALQNZmsg2izSc03b3R7g0ZAjgxVkHgKbvwA0K1R9pR5Xn
M1TQXAiN2e06AOQC7LhjKTu22ZoOiN8ca5kJLsKT9yIaAscgVKnBkuPejKo88u4u
VW0ORalSTyB1QcXMhRnzkhE10eWeHcGA3NNUIKRPD5x423/97iJRPfI6ZbMG70hI
aoWnjDow3i0FpHKEG8IqVQQRWKNKv1VEK7DFvtlivdpGpYH2sGZV85Es/bbg0ijn
fyl9Ri90anEUemvAxiW9Qcym98FLLeYF/xuGViE3rCtSopuySEmX85EprNHJgGad
AH1FQVHscoPoxdQTwp7KrP/cOEJD6h6WOqDOUI80c4+FplUNCb/owgzjdFJBxPhq
Hc/iQccwl+/u1rXvnDzaat9FBXFNuntGxCNuhqgs3tjERZpO17vpI4v5nJSTyDFW
hQ5CDGyhKo0=86mZ
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-5006:04 Critical: Red Hat Virtualization Host security

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

Summary

The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.
Security Fix(es):
* nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) (CVE-2021-43527)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/2974891

References

https://access.redhat.com/security/cve/CVE-2021-43527 https://access.redhat.com/security/updates/classification/#critical https://access.redhat.com/security/vulnerabilities/RHSB-2021-008

Package List

Red Hat Virtualization 4 Hypervisor for RHEL 8:
Source: redhat-virtualization-host-4.4.9-202112061811_8.5.src.rpm
x86_64: redhat-virtualization-host-image-update-4.4.9-202112061811_8.5.x86_64.rpm
RHEL 8-based RHEV-H for RHEV 4 (build requirements):
Source: redhat-release-virtualization-host-4.4.9-3.el8ev.src.rpm
noarch: redhat-virtualization-host-image-update-placeholder-4.4.9-3.el8ev.noarch.rpm
x86_64: redhat-release-virtualization-host-4.4.9-3.el8ev.x86_64.rpm redhat-release-virtualization-host-content-4.4.9-3.el8ev.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2021:5006-01
Product: Red Hat Virtualization
Advisory URL: https://access.redhat.com/errata/RHSA-2021:5006
Issued Date: : 2021-12-08
CVE Names: CVE-2021-43527

Topic

An update for redhat-release-virtualization-host andredhat-virtualization-host is now available for Red Hat Virtualization 4for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Critical. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64

Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64


Bugs Fixed

2024370 - CVE-2021-43527 nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)

2029406 - Could not find available upgrade package, when upgrade RHVH to the latest rhvh-4.4.9.3-0.20211202.0+1


Related News