An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Virtualization Host 4.4.z SP 1 security update batch#5 (oVirt-4.5.3-5) Advisory ID: RHSA-2023:1677-01 Product: Red Hat Virtualization Advisory URL: https://access.redhat.com/errata/RHSA-2023:1677 Issue date: 2023-04-10 CVE Names: CVE-2022-23521 CVE-2022-41903 CVE-2023-0266 CVE-2023-0386 CVE-2023-0767 ==================================================================== 1. Summary: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64 Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64 3. Description: The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages includeredhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. Security Fix(es): * git: gitattributes parsing integer overflow (CVE-2022-23521) * git: Heap overflow in `git archive`, `git log --format` leading to RCE (CVE-2022-41903) * ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266) * kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386) * nss: Arbitrary memory write via PKCS 12 (CVE-2023-0767) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 5. Bugs fixed (https://bugzilla.redhat.com/): 2159505 - CVE-2023-0386 kernel: FUSE filesystem low-privileged user privileges escalation 2162055 - CVE-2022-23521 git: gitattributes parsing integer overflow 2162056 - CVE-2022-41903 git: Heap overflow in `git archive`, `git log --format` leading to RCE 2163379 - CVE-2023-0266 ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF 2170377 - CVE-2023-0767 nss: Arbitrary memory write via PKCS 12 6. Package List: Red Hat Virtualization 4 Hypervisor for RHEL 8: Source: redhat-virtualization-host-4.5.3-202304051438_8.6.src.rpm x86_64: redhat-virtualization-host-image-update-4.5.3-202304051438_8.6.x86_64.rpm RHEL 8-based RHEV-H for RHEV 4 (buildrequirements): Source: redhat-release-virtualization-host-4.5.3-6.el8ev.src.rpm noarch: redhat-virtualization-host-image-update-placeholder-4.5.3-6.el8ev.noarch.rpm x86_64: redhat-release-virtualization-host-4.5.3-6.el8ev.x86_64.rpm redhat-release-virtualization-host-content-4.5.3-6.el8ev.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-23521 https://access.redhat.com/security/cve/CVE-2022-41903 https://access.redhat.com/security/cve/CVE-2023-0266 https://access.redhat.com/security/cve/CVE-2023-0386 https://access.redhat.com/security/cve/CVE-2023-0767 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZDpwqdzjgjWX9erEAQi19g/+M/xOl/dJ5guZOutoPIEJFcwmAljGRAZc uL90OsNpwdCgISaSGuTnJmK5WgkW5iYCFKe3ZkOoO24eVAHrdixXs/MigacVXimE 9N/LuZ8KNcij0mO07kb2156EpVvJSV6fqx59NW9IS8vFKoTmEU88MfYD4yW9q2H6 AOIyTzyVBXO9N2mbe6zI15SQTpdr+ccZqzQeV27zylYOqM0lWTfVTRnyThbzZnWv k3+qcFtnLC3IsJaMdcCVUurVQyYHOxsh6b42jGzjgTp9kMhiHnBuyU8+YJNlIf14 GEa8fm80JcLAx/Fe+PWjxR86IDdHWIkwMFnf3FdYTvHPqIdIuLDHaX23pYVHkDH/ lAHpqJbUUvUorgyS51DLHXUkLtn7taH2pt1LBEZwFeB2I5dTLJmcYzpg/Qs5XuqG Pz6ax39hiE5VxuLjgja3zB1J6LXQDAdmNKxLrNUgM9Rqs8NxMyLpI55olkt7cI7p ghBpjBE1/Dl+yAdJ6As5qQ7edarPpqolP83RiV6V9GyhMn77MDwUZC80PHnlzmDW L6X2xGU6LWLf35kegEjcNF2JMylSUahksCue/q3yHMRnX76xG2rAzHoGOpTQBRu3 Fz11oqk0G20AKmpogYtW27qhg9Av/C+QeEP5pfxz2YkpPhHXVheOIFTToZewtAtK tFh4T3UCqE4=gnQ9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.. SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:0637-1 Rating: important References: #749735 #758060 Cross-References: CVE-2012-2110 Affected Products: SUSE Linux Enterprise Server 10 SP4 SUSE Linux Enterprise Desktop 10 SP4 SLE SDK 10 SP4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update of openssl fixes an integer conversation issue which could cause a heap-based memory corruption (CVE-2012-2110 ). Additionally, a check for negative buffer length values was added ( CVE-2012-2131 ) and a memory leak when creating public keys fixed. Package List: - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64): openssl-0.9.8a-18.68.1 openssl-devel-0.9.8a-18.68.1 openssl-doc-0.9.8a-18.68.1 - SUSE Linux Enterprise Server 10 SP4 (s390x x86_64): openssl-32bit-0.9.8a-18.68.1 openssl-devel-32bit-0.9.8a-18.68.1 - SUSE Linux Enterprise Server 10 SP4 (ia64): openssl-x86-0.9.8a-18.68.1 - SUSE Linux Enterprise Server 10 SP4 (ppc): openssl-64bit-0.9.8a-18.68.1 openssl-devel-64bit-0.9.8a-18.68.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64): openssl-0.9.8a-18.68.1 openssl-devel-0.9.8a-18.68.1 - SUSE Linux Enterprise Desktop 10 SP4 (x86_64): openssl-32bit-0.9.8a-18.68.1 openssl-devel-32bit-0.9.8a-18.68.1 - SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64): openssl-doc-0.9.8a-18.68.1 References: https://www.suse.com/security/cve/CVE-2012-2110.html . SUSE Software Patch addresses critical openssl flaws, enhancing defenses against data breaches and integrity issues. Update immediately.. SUSE Security Update, openssl patch, memory mitigation, enterprise fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.