RedHat: RHSA-2022-5678:01 Important: Red Hat Virtualization securit...
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Virtualization security, bug fix, and enhancement update [ovirt-4.5.1]
Advisory ID:       RHSA-2022:5678-01
Product:           Red Hat Virtualization
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:5678
Issue date:        2022-07-21
CVE Names:         CVE-2022-27666 CVE-2022-28733 
=====================================================================

1. Summary:

An update for imgbased, redhat-release-virtualization-host, and
redhat-virtualization-host is now available for Red Hat Virtualization 4
for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64
Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64

3. Description:

The redhat-virtualization-host packages provide the Red Hat Virtualization
Host. These packages include redhat-release-virtualization-host,
ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are
installed using a special build of Red Hat Enterprise Linux with only the
packages required to host virtual machines. RHVH features a Cockpit user
interface for monitoring the host's resources and performing administrative
tasks.

The following packages have been upgraded to a later upstream version:
redhat-release-virtualization-host (4.5.1), redhat-virtualization-host
(4.5.1), redhat-virtualization-host-productimg (4.5.1). (BZ#2062192,
BZ#2070869, BZ#2094682)

Security Fix(es):

* kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666)

* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

* RHV-H 4.4 SP1 Has been rebased on RHEL 8.6 Batch #1 (BZ#2070869)

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/2974891

5. Bugs fixed (https://bugzilla.redhat.com/):

2061633 - CVE-2022-27666 kernel: buffer overflow in IPsec ESP transformation code
2070869 - Rebase RHV-H 4.4 SP1 on RHEL 8.6.0.1
2083339 - CVE-2022-28733 grub2: Integer underflow in grub_net_recv_ip4_packets
2097627 - Upgrade redhat-release-virtualization-host to 4.5.1
2103984 - when upgrade RHVH from 4.5.0 to 4.5.1 via engine, "no updates found" is shown when checking for updates

6. Package List:

Red Hat Virtualization 4 Hypervisor for RHEL 8:

Source:
redhat-virtualization-host-4.5.1-202207170705_8.6.src.rpm

x86_64:
redhat-virtualization-host-image-update-4.5.1-202207170705_8.6.x86_64.rpm

RHEL 8-based RHEV-H for RHEV 4 (build requirements):

Source:
redhat-release-virtualization-host-4.5.1-1.el8ev.src.rpm
redhat-virtualization-host-productimg-4.5.1-1.el8.src.rpm

noarch:
redhat-virtualization-host-image-update-placeholder-4.5.1-1.el8ev.noarch.rpm

x86_64:
redhat-release-virtualization-host-4.5.1-1.el8ev.x86_64.rpm
redhat-release-virtualization-host-content-4.5.1-1.el8ev.x86_64.rpm
redhat-virtualization-host-productimg-4.5.1-1.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-27666
https://access.redhat.com/security/cve/CVE-2022-28733
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYuFjttzjgjWX9erEAQhnYA//d9RJJgaQQpTdAzrO2gTgotqLl+imRGQv
+V+A0LYoV+RF14f14OwgN7wtv6MUNCfIqpwNUFi2lEf7rgzIQAOd5tm4qXcBW7+i
Fewg2STLpMg1xMGQTsn7BrrdXaTgDOtAGnRbPOczJ2pvBIN2N0Fqoh9aj3acLFm6
tmGKRGHRvxfGk0kGuFsOB1UcMDJsKSHviha3LQfluaPiTiduDReSr79xl+KCjdd5
FHK/Z+/CD2ZhQ/HX2dhbMUEYDs3RMlmZFrESg6PmFcLC/rMxsr7mY+y5Pxmot76Q
eslzo0t0pQOdjgK59OflYmkJjymP+7Hzdjti+HSp6xeXH2ztG2z/HAvnHyk7T7vt
j29FVaGo8055+swRDZQ6aL+pg4djLobM8DY0yZHwGgmTgq4d4mWiJ1Q3f+13ACyL
Ax2B2hyidtAftUBINvSlvpAVRzpgzO9umUAowRXAUN+YHNaAlur1Cdhue4QT87JH
jKDIZZXKscOrSsae1ZQonpOvVViGJwBcSbRkp1JlGqgRVF2BhaBtZvZnuw4M42sI
YFvOMM3yvXWGRd8kbCKxpVEZgZMMvedA//G+WS/fh3OtiEtXTySehl+ul6J+o3aK
K2aU156XBjvQzOKPid1d+at3e44pFW975bhRBq8DUx3sEDi7E3VgGulMZNvZSDh3
cX/S4McQiSc=
=fNBx
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-5678:01 Important: Red Hat Virtualization security,

An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

Summary

The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.
The following packages have been upgraded to a later upstream version: redhat-release-virtualization-host (4.5.1), redhat-virtualization-host (4.5.1), redhat-virtualization-host-productimg (4.5.1). (BZ#2062192, BZ#2070869, BZ#2094682)
Security Fix(es):
* kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666)
* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* RHV-H 4.4 SP1 Has been rebased on RHEL 8.6 Batch #1 (BZ#2070869)

Solution

For details on how to apply this update, which includes the changesdescribed in this advisory, refer to:https://access.redhat.com/articles/2974891

References

https://access.redhat.com/security/cve/CVE-2022-27666 https://access.redhat.com/security/cve/CVE-2022-28733 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Virtualization 4 Hypervisor for RHEL 8:
Source: redhat-virtualization-host-4.5.1-202207170705_8.6.src.rpm
x86_64: redhat-virtualization-host-image-update-4.5.1-202207170705_8.6.x86_64.rpm
RHEL 8-based RHEV-H for RHEV 4 (build requirements):
Source: redhat-release-virtualization-host-4.5.1-1.el8ev.src.rpm redhat-virtualization-host-productimg-4.5.1-1.el8.src.rpm
noarch: redhat-virtualization-host-image-update-placeholder-4.5.1-1.el8ev.noarch.rpm
x86_64: redhat-release-virtualization-host-4.5.1-1.el8ev.x86_64.rpm redhat-release-virtualization-host-content-4.5.1-1.el8ev.x86_64.rpm redhat-virtualization-host-productimg-4.5.1-1.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/

Severity
Advisory ID: RHSA-2022:5678-01
Product: Red Hat Virtualization
Advisory URL: https://access.redhat.com/errata/RHSA-2022:5678
Issued Date: : 2022-07-21
CVE Names: CVE-2022-27666 CVE-2022-28733

Topic

An update for imgbased, redhat-release-virtualization-host, andredhat-virtualization-host is now available for Red Hat Virtualization 4for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64

Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64

Bugs Fixed

2061633 - CVE-2022-27666 kernel: buffer overflow in IPsec ESP transformation code

2070869 - Rebase RHV-H 4.4 SP1 on RHEL 8.6.0.1

2083339 - CVE-2022-28733 grub2: Integer underflow in grub_net_recv_ip4_packets

2097627 - Upgrade redhat-release-virtualization-host to 4.5.1

2103984 - when upgrade RHVH from 4.5.0 to 4.5.1 via engine, "no updates found" is shown when checking for updates

We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.