-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Virtualization 4.10.1 RPMs security and bug fix update
Advisory ID:       RHSA-2022:4667-01
Product:           cnv
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:4667
Issue date:        2022-05-18
CVE Names:         CVE-2022-21698 
====================================================================
1. Summary:

Red Hat OpenShift Virtualization release 4.10.1 is now available with
updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

CNV 4.10 for RHEL 7 - x86_64
CNV 4.10 for RHEL 8 - x86_64

3. Description:

OpenShift Virtualization is Red Hat's virtualization solution designed for
Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.10.1 RPMs.

Security Fix(es):

* prometheus/client_golang: Denial of service using
InstrumentHandlerCounter (CVE-2022-21698)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

* 4.10.1 rpms (BZ#2065755)

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter
2065755 - 4.10.1 rpms

6. Package List:

CNV 4.10 for RHEL 7:

Source:
kubevirt-4.10.1-489.el7.src.rpm

x86_64:
kubevirt-virtctl-4.10.1-489.el7.x86_64.rpm
kubevirt-virtctl-redistributable-4.10.1-489.el7.x86_64.rpm

CNV 4.10 for RHEL 8:

Source:
kubevirt-4.10.1-489.el8.src.rpm

x86_64:
kubevirt-virtctl-4.10.1-489.el8.x86_64.rpm
kubevirt-virtctl-redistributable-4.10.1-489.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-21698
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYoWMktzjgjWX9erEAQgyFA/8DIMP4f+xqWaMEn4gBHrml6OvQvX3VvWH
ZhhBozmF+4rMSj7OPQmZWDCPwxBRwL2X4Kl9Tj12RMR8/yjlQjfb8QnvVEsQDiQx
wrzjH/fIFrguVntn7xzUWp1bF6ILCTjrpNp7s8mK/MP6UOEIVFXT3CYTOR3R0Vjk
rK5yM1w0CNxzk2kXx7nQm7UHms+CEVBTJDsYY4lFZwkoXC2gYepWQeLrF2QwBcNL
dNyzZE404VF0DQoC3UtKD6tNqOTx/iVGfqnRYTEPSdxVuSDPJnjsorcHYruGwpY7
NkaYUZWVnyUVyL9moFAETC3editDwM2qvCOU6sJjgs1g9v8FygkTWCPBYyUQXRgr
hBdnoNilb1GPhGDWT1fkZ5020iVnjgVDlEqI4NCTVwzvnpjVMocZykCSFi3EkPKD
Gssf+tdZEtIIsDPTfPdQNJmflh4SB462ZRwQQ7kRgYw1qLtqQqP+zNkZrOrZrmdu
II7bhD9Zk8RGYGFWIq2ffp5Xqh93C2tu9AZ3gI/jiIj4flB5zEu5tILYpxjRT4pL
4hESeuJ8G2ctP8Z1Rv7VaY1VDcaf84uujvPquOb15JE15vfxJ3E0YNgXQNhBx1Li
xyD3g1LUIhOGbBRQ4a2WziR3IiD8SCrIs8s+WFgzDhacVQKXBPSkv0J9qLoH9Jxn
bARoPlu+u4E=lItE
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-4667:01 Moderate: OpenShift Virtualization 4.10.1 RPMs

Red Hat OpenShift Virtualization release 4.10.1 is now available with updates to packages and images that fix several bugs and add enhancements

Summary

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.
This advisory contains OpenShift Virtualization 4.10.1 RPMs.
Security Fix(es):
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* 4.10.1 rpms (BZ#2065755)



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-21698 https://access.redhat.com/security/updates/classification/#moderate

Package List

CNV 4.10 for RHEL 7:
Source: kubevirt-4.10.1-489.el7.src.rpm
x86_64: kubevirt-virtctl-4.10.1-489.el7.x86_64.rpm kubevirt-virtctl-redistributable-4.10.1-489.el7.x86_64.rpm
CNV 4.10 for RHEL 8:
Source: kubevirt-4.10.1-489.el8.src.rpm
x86_64: kubevirt-virtctl-4.10.1-489.el8.x86_64.rpm kubevirt-virtctl-redistributable-4.10.1-489.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2022:4667-01
Product: cnv
Advisory URL: https://access.redhat.com/errata/RHSA-2022:4667
Issued Date: : 2022-05-18
CVE Names: CVE-2022-21698

Topic

Red Hat OpenShift Virtualization release 4.10.1 is now available withupdates to packages and images that fix several bugs and add enhancements.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

CNV 4.10 for RHEL 7 - x86_64

CNV 4.10 for RHEL 8 - x86_64


Bugs Fixed

2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter

2065755 - 4.10.1 rpms


Related News