Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE Linux Enterprise: 2022:0526-1 Moderate: Kubevirt Security Advisory

suse
Calendar Grey February 21, 2022
Scroller Suse
SUSE has issued a patch to resolve a significant vulnerability concerning kubevirt and associated container components. Ensure you update immediately.
An update that fixes one vulnerability is now available

Summary

This update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container fixes the following issues: - Update to version 0.49.0 Release notes https://github.com/kubevirt/kubevirt/releases/tag/v0.49.0 - Drop kubevirt-psp-caasp.yaml - Install curl and lsscsi (needed for testing) - Symlink UEFI firmware with AMD SEV support - Install tar package to enable kubectl cp ... - Make a "fixed appliance" for libguestfs - Explicitly install libguestfs{,-devel} and supermin Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

Cross- CVE-2021-43565

CVSS scores:

CVE-2021-43565 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise High Performance Computing 15-SP3

SUSE Linux Enterprise Module for Containers 15-SP3

SUSE Linux Enterprise Server 15-SP3

SUSE Linux Enterprise Server for SAP Applications 15-SP3

SUSE Manager Proxy 4.2

SUSE Manager Server 4.2

https://www.suse.com/security/cve/CVE-2021-43565.html

Announcement ID: SUSE-SU-2022:0526-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.