Cross-References: * CVE-2023-44487 CVSS scores: . # Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t Announcement ID: SUSE-SU-2023:4624-1 Rating: important References: Cross-References: * CVE-2023-44487 CVSS scores: * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for kubevirt, virt-api-container, virt-controller-container, virt- exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator- container, virt-pr-helper-container fixes the following issues: Update to version 1.1.0 * Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.1.0 Update to version 1.0.1 * Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.0.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-4624=1 openSUSE-SLE-15.5-2023-4624=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4624=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2023-4624=1 ## Package List: * openSUSE Leap 15.5 (x86_64) *kubevirt-container-disk-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-controller-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-operator-debuginfo-1.1.0-150500.8.6.1 * kubevirt-container-disk-1.1.0-150500.8.6.1 * kubevirt-virt-exportserver-1.1.0-150500.8.6.1 * obs-service-kubevirt_containers_meta-1.1.0-150500.8.6.1 * kubevirt-virt-handler-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-exportproxy-1.1.0-150500.8.6.1 * kubevirt-virt-exportserver-debuginfo-1.1.0-150500.8.6.1 * kubevirt-tests-1.1.0-150500.8.6.1 * kubevirt-tests-debuginfo-1.1.0-150500.8.6.1 * kubevirt-pr-helper-conf-1.1.0-150500.8.6.1 * kubevirt-virt-exportproxy-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-api-1.1.0-150500.8.6.1 * kubevirt-virt-handler-1.1.0-150500.8.6.1 * kubevirt-manifests-1.1.0-150500.8.6.1 * kubevirt-virt-launcher-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-1.1.0-150500.8.6.1 * kubevirt-virt-launcher-1.1.0-150500.8.6.1 * kubevirt-virt-controller-1.1.0-150500.8.6.1 * kubevirt-virt-api-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-operator-1.1.0-150500.8.6.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * kubevirt-virtctl-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-1.1.0-150500.8.6.1 * kubevirt-manifests-1.1.0-150500.8.6.1 * Containers Module 15-SP5 (x86_64) * kubevirt-virtctl-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-1.1.0-150500.8.6.1 * kubevirt-manifests-1.1.0-150500.8.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html . Urgent patch release for kubevirt and container modules; immediate application recommended for all vulnerable systems. Kubevirt Update, SUSE Security Fix, Container Vulnerability. . Severity: Critical. LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for kubevirt stack ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4147-1 Rating: important References: Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.3 SUSE Linux Enterprise Module for Containers 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 openSUSE Leap Micro 5.3 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update provides rebuilds of the kubevirt containers with up to date base images, fixing various security issues. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap Micro 5.3: zypper in -t patch openSUSE-Leap-Micro-5.3-2022-4147=1 - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-4147=1 - SUSE Linux Enterprise Module for Containers 15-SP4: zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2022-4147=1 - SUSE Linux Enterprise Micro 5.3: zypper in -t patch SUSE-SLE-Micro-5.3-2022-4147=1 Package List: - openSUSE Leap Micro 5.3 (x86_64): kubevirt-manifests-0.54.0-150400.3.7.1 kubevirt-virtctl-0.54.0-150400.3.7.1 kubevirt-virtctl-debuginfo-0.54.0-150400.3.7.1 - openSUSE Leap 15.4 (x86_64): kubevirt-container-disk-0.54.0-150400.3.7.1 kubevirt-container-disk-debuginfo-0.54.0-150400.3.7.1 kubevirt-manifests-0.54.0-150400.3.7.1 kubevirt-tests-0.54.0-150400.3.7.1 kubevirt-tests-debuginfo-0.54.0-150400.3.7.1 kubevirt-virt-api-0.54.0-150400.3.7.1 kubevirt-virt-api-debuginfo-0.54.0-150400.3.7.1 kubevirt-virt-controller-0.54.0-150400.3.7.1 kubevirt-virt-controller-debuginfo-0.54.0-150400.3.7.1 kubevirt-virt-handler-0.54.0-150400.3.7.1 kubevirt-virt-handler-debuginfo-0.54.0-150400.3.7.1 kubevirt-virt-launcher-0.54.0-150400.3.7.1 kubevirt-virt-launcher-debuginfo-0.54.0-150400.3.7.1 kubevirt-virt-operator-0.54.0-150400.3.7.1 kubevirt-virt-operator-debuginfo-0.54.0-150400.3.7.1 kubevirt-virtctl-0.54.0-150400.3.7.1 kubevirt-virtctl-debuginfo-0.54.0-150400.3.7.1 obs-service-kubevirt_containers_meta-0.54.0-150400.3.7.1 - SUSE Linux Enterprise Module for Containers 15-SP4 (x86_64): kubevirt-manifests-0.54.0-150400.3.7.1 kubevirt-virtctl-0.54.0-150400.3.7.1 kubevirt-virtctl-debuginfo-0.54.0-150400.3.7.1 - SUSE Linux Enterprise Micro 5.3 (x86_64): kubevirt-manifests-0.54.0-150400.3.7.1 kubevirt-virtctl-0.54.0-150400.3.7.1 kubevirt-virtctl-debuginfo-0.54.0-150400.3.7.1 References: . SUSE Security Release for kubevirt framework tackles significant issues and vulnerabilities affecting various distributions.. SUSE Linux Security,kubevirt update,container security fix,important security update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.