Explore top 10 tips to secure your open-source projects now. Read More
×Upstream kernel version 6.6.93 fixes bugs and vulnerabilities. The kmod-virtualbox, kmod-xtables-addons, wireless-regdb & firmware packages have been updated to work with this new kernel; some updated build time requirement are here to allow building this kernel version. For information about the vulnerabilities see the links. . MGASA-2025-0182 - Updated kernel, kmod-virtualbox, kmod-xtables-addons, dwarves, libtraceevent, libtracefs, kernel-firmware, kernel-firmware-nonfree, radeon-firmware & wireless-regdb packages fix security vulnerabilities Publication date: 09 Jun 2025 URL: https://advisories.mageia.org/MGASA-2025-0182.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-37797, CVE-2025-37799, CVE-2025-37800, CVE-2025-37801, CVE-2025-37803, CVE-2025-37804, CVE-2025-37805, CVE-2025-37808, CVE-2025-37810, CVE-2025-37811, CVE-2025-37812, CVE-2025-37813, CVE-2025-37815, CVE-2025-37817, CVE-2025-37818, CVE-2025-37819, CVE-2025-37820, CVE-2025-37823, CVE-2025-37824, CVE-2025-37828, CVE-2025-37829, CVE-2025-37830, CVE-2025-37831, CVE-2025-37836, CVE-2025-37878, CVE-2025-37879, CVE-2025-37881, CVE-2025-37883, CVE-2025-37884, CVE-2025-37885, CVE-2025-37886, CVE-2025-37887, CVE-2025-37890, CVE-2025-37891, CVE-2025-37897, CVE-2025-37901, CVE-2025-37903, CVE-2025-37905, CVE-2025-37909, CVE-2025-37911, CVE-2025-37912, CVE-2025-37913, CVE-2025-37914, CVE-2025-37915, CVE-2025-37916, CVE-2025-37917, CVE-2025-37918, CVE-2025-37921, CVE-2025-37922, CVE-2025-37923, CVE-2025-37924, CVE-2025-37927, CVE-2025-37928, CVE-2025-37929, CVE-2025-37930, CVE-2025-37932, CVE-2025-37933, CVE-2025-37935, CVE-2025-37936, CVE-2025-37938, CVE-2025-37947, CVE-2025-37948, CVE-2025-37949, CVE-2025-37951, CVE-2025-37952, CVE-2025-37953, CVE-2025-37954, CVE-2025-37956, CVE-2025-37959, CVE-2025-37961, CVE-2025-37962, CVE-2025-37963, CVE-2025-37964, CVE-2025-37969, CVE-2025-37970, CVE-2025-37972, CVE-2025-37973, CVE-2025-37983, CVE-2025-37985, CVE-2025-37988, CVE-2025-37989, CVE-2025-37990, CVE-2025-37991, CVE-2025-37992 Upstream kernel version 6.6.93 fixes bugs and vulnerabilities. The kmod-virtualbox, kmod-xtables-addons, wireless-regdb & firmware packages have been updated to work with this new kernel; some updated build time requirement are here to allow building this kernel version. For information about the vulnerabilities see the links. References: - https://bugs.mageia.org/show_bug.cgi?id=34302 - https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.89 - https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.90 - https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.91 - https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.92 - https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.93 - https://www.cve.org/CVERecord?id=CVE-2025-37797 - https://www.cve.org/CVERecord?id=CVE-2025-37799 - https://www.cve.org/CVERecord?id=CVE-2025-37800 - https://www.cve.org/CVERecord?id=CVE-2025-37801 - https://www.cve.org/CVERecord?id=CVE-2025-37803 - https://www.cve.org/CVERecord?id=CVE-2025-37804 - https://www.cve.org/CVERecord?id=CVE-2025-37805 - https://www.cve.org/CVERecord?id=CVE-2025-37808 - https://www.cve.org/CVERecord?id=CVE-2025-37810 - https://www.cve.org/CVERecord?id=CVE-2025-37811 - https://www.cve.org/CVERecord?id=CVE-2025-37812 - https://www.cve.org/CVERecord?id=CVE-2025-37813 - https://www.cve.org/CVERecord?id=CVE-2025-37815 - https://www.cve.org/CVERecord?id=CVE-2025-37817 - https://www.cve.org/CVERecord?id=CVE-2025-37818 - https://www.cve.org/CVERecord?id=CVE-2025-37819 - https://www.cve.org/CVERecord?id=CVE-2025-37820 - https://www.cve.org/CVERecord?id=CVE-2025-37823 -https://www.cve.org/CVERecord?id=CVE-2025-37824 - https://www.cve.org/CVERecord?id=CVE-2025-37828 - https://www.cve.org/CVERecord?id=CVE-2025-37829 - https://www.cve.org/CVERecord?id=CVE-2025-37830 - https://www.cve.org/CVERecord?id=CVE-2025-37831 - https://www.cve.org/CVERecord?id=CVE-2025-37836 - https://www.cve.org/CVERecord?id=CVE-2025-37878 - https://www.cve.org/CVERecord?id=CVE-2025-37879 - https://www.cve.org/CVERecord?id=CVE-2025-37881 - https://www.cve.org/CVERecord?id=CVE-2025-37883 - https://www.cve.org/CVERecord?id=CVE-2025-37884 - https://www.cve.org/CVERecord?id=CVE-2025-37885 - https://www.cve.org/CVERecord?id=CVE-2025-37886 - https://www.cve.org/CVERecord?id=CVE-2025-37887 - https://www.cve.org/CVERecord?id=CVE-2025-37890 - https://www.cve.org/CVERecord?id=CVE-2025-37891 - https://www.cve.org/CVERecord?id=CVE-2025-37897 - https://www.cve.org/CVERecord?id=CVE-2025-37901 - https://www.cve.org/CVERecord?id=CVE-2025-37903 - https://www.cve.org/CVERecord?id=CVE-2025-37905 - https://www.cve.org/CVERecord?id=CVE-2025-37909 - https://www.cve.org/CVERecord?id=CVE-2025-37911 - https://www.cve.org/CVERecord?id=CVE-2025-37912 - https://www.cve.org/CVERecord?id=CVE-2025-37913 - https://www.cve.org/CVERecord?id=CVE-2025-37914 - https://www.cve.org/CVERecord?id=CVE-2025-37915 - https://www.cve.org/CVERecord?id=CVE-2025-37916 - https://www.cve.org/CVERecord?id=CVE-2025-37917 - https://www.cve.org/CVERecord?id=CVE-2025-37918 - https://www.cve.org/CVERecord?id=CVE-2025-37921 - https://www.cve.org/CVERecord?id=CVE-2025-37922 - https://www.cve.org/CVERecord?id=CVE-2025-37923 - https://www.cve.org/CVERecord?id=CVE-2025-37924 - https://www.cve.org/CVERecord?id=CVE-2025-37927 - https://www.cve.org/CVERecord?id=CVE-2025-37928 - https://www.cve.org/CVERecord?id=CVE-2025-37929 - https://www.cve.org/CVERecord?id=CVE-2025-37930 - https://www.cve.org/CVERecord?id=CVE-2025-37932 - https://www.cve.org/CVERecord?id=CVE-2025-37933 - https://www.cve.org/CVERecord?id=CVE-2025-37935 -https://www.cve.org/CVERecord?id=CVE-2025-37936 - https://www.cve.org/CVERecord?id=CVE-2025-37938 - https://www.cve.org/CVERecord?id=CVE-2025-37947 - https://www.cve.org/CVERecord?id=CVE-2025-37948 - https://www.cve.org/CVERecord?id=CVE-2025-37949 - https://www.cve.org/CVERecord?id=CVE-2025-37951 - https://www.cve.org/CVERecord?id=CVE-2025-37952 - https://www.cve.org/CVERecord?id=CVE-2025-37953 - https://www.cve.org/CVERecord?id=CVE-2025-37954 - https://www.cve.org/CVERecord?id=CVE-2025-37956 - https://www.cve.org/CVERecord?id=CVE-2025-37959 - https://www.cve.org/CVERecord?id=CVE-2025-37961 - https://www.cve.org/CVERecord?id=CVE-2025-37962 - https://www.cve.org/CVERecord?id=CVE-2025-37963 - https://www.cve.org/CVERecord?id=CVE-2025-37964 - https://www.cve.org/CVERecord?id=CVE-2025-37969 - https://www.cve.org/CVERecord?id=CVE-2025-37970 - https://www.cve.org/CVERecord?id=CVE-2025-37972 - https://www.cve.org/CVERecord?id=CVE-2025-37973 - https://www.cve.org/CVERecord?id=CVE-2025-37983 - https://www.cve.org/CVERecord?id=CVE-2025-37985 - https://www.cve.org/CVERecord?id=CVE-2025-37988 - https://www.cve.org/CVERecord?id=CVE-2025-37989 - https://www.cve.org/CVERecord?id=CVE-2025-37990 - https://www.cve.org/CVERecord?id=CVE-2025-37991 - https://www.cve.org/CVERecord?id=CVE-2025-37992 SRPMS: - 9/core/kernel-6.6.93-1.mga9 - 9/core/kmod-virtualbox-7.1.8-3.mga9 - 9/core/kmod-xtables-addons-3.24-80.mga9 - 9/core/dwarves-1.30-1.mga9 - 9/core/libtraceevent-1.8.4-1.mga9 - 9/core/libtracefs-1.8.2-1.mga9 - 9/core/kernel-firmware-20250509-1.mga9 - 9/core/wireless-regdb-20250220-1.mga9 - 9/nonfree/kernel-firmware-nonfree-20250509-1.mga9.nonfree - 9/nonfree/radeon-firmware-20250509-1.mga9.nonfree . Mageia 9 security bulletin introduces essential kernel and firmware patches addressing severe flaws found across various packages.. Mageia kernel update, security advisory, firmware vulnerabilities, package updates. . Severity: Critical. LinuxSecurity.com Team
deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-20f63c4273 2025-03-01 01:22:54.667856+00:00 -------------------------------------------------------------------------------- Name : xen Product : Fedora 41 Version : 4.19.1 Release : 5.fc41 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713] -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 27 2025 Michael Young - 4.19.1-5 - deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-20f63c4273' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle . MGASA-2025-0002 - Updated virtualbox & kmod-virtualbox packages fix security vulnerabilities Publication date: 04 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0002.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-21259, CVE-2024-21263, CVE-2024-21273, CVE-2024-21248, CVE-2024-21253 Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VirtualBox VMs. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). References: - https://bugs.mageia.org/show_bug.cgi?id=33754 - https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixOVIR - - https://www.cve.org/CVERecord?id=CVE-2024-21259 - https://www.cve.org/CVERecord?id=CVE-2024-21263 - https://www.cve.org/CVERecord?id=CVE-2024-21273 - https://www.cve.org/CVERecord?id=CVE-2024-21248 - https://www.cve.org/CVERecord?id=CVE-2024-21253 SRPMS: - 9/core/virtualbox-7.0.22-1.mga9 - 9/core/kmod-virtualbox-7.0.22-62.mga9 . SECURITY-UPDATE-2025-0010 for VMware & kernel-module-vmware addresses serious vulnerabilities. Ensure safety with the newest fixes.. Oracle VM, Mageia security, VirtualBox update,kmod-virtualbox, virtualization threats. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Oracle VirtualBox, the worst of which could lead to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202409-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Oracle VirtualBox: Multiple Vulnerabilities Date: September 22, 2024 Bugs: #918524 ID: 202409-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Oracle VirtualBox, the worst of which could lead to privilege escalation. Background ========== VirtualBox is a powerful virtualization product from Oracle. Affected packages ================= Package Vulnerable Unaffected ------------------------ ------------ ------------ app-emulation/virtualbox < 7.0.12 > = 7.0.12 Description =========== Multiple vulnerabilities have been discovered in Oracle VirtualBox. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Oracle VirtualBox users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-emulation/virtualbox-7.0.12" References ========== [ 1 ] CVE-2023-22098 https://nvd.nist.gov/vuln/detail/CVE-2023-22098 [ 2 ] CVE-2023-22099 https://nvd.nist.gov/vuln/detail/CVE-2023-22099 [ 3 ] CVE-2023-22100 https://nvd.nist.gov/vuln/detail/CVE-2023-22100 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202409-11 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311 . # Security update for qemu Announcement ID: SUSE-SU-2023:4662-1 Rating: important References: * bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311 Cross-References: * CVE-2021-3638 * CVE-2023-3180 * CVE-2023-3354 CVSS scores: * CVE-2021-3638 ( SUSE ): 3.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L * CVE-2021-3638 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2023-3180 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2023-3180 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2023-3354 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-3354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for qemu fixes the following issues: * CVE-2021-3638: hw/display/ati_2d: Fix buffer overflow in ati_2d_blt (bsc#1188609) * CVE-2023-3180: virtio-crypto: verify src and dst buffer length for sym request (bsc#1213925) * CVE-2023-3354: io: remove io watch if TLS channel is closed during handshake (bsc#1212850) * [openSUSE] roms/ipxe: Backport 0aa2e4ec9635, in preparation of binutils 2.41 (bsc#1215311) * target/s390x: Fix the "ignored match" case in VSTRS (bsc#1213210) * linux-user/elfload: Enable vxe2 on s390x (bsc#1213210) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-4662=1 openSUSE-SLE-15.5-2023-4662=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4662=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4662=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2023-4662=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * qemu-extra-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-debuginfo-7.1.0-150500.49.9.2 * qemu-block-curl-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-dbus-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-spice-core-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-qxl-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-pa-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-pci-7.1.0-150500.49.9.2 * qemu-audio-spice-7.1.0-150500.49.9.2 * qemu-tools-debuginfo-7.1.0-150500.49.9.2 * qemu-block-curl-7.1.0-150500.49.9.2 * qemu-ppc-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-curses-7.1.0-150500.49.9.2 * qemu-audio-spice-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-dbus-debuginfo-7.1.0-150500.49.9.2 * qemu-block-ssh-debuginfo-7.1.0-150500.49.9.2 * qemu-accel-tcg-x86-debuginfo-7.1.0-150500.49.9.2 * qemu-block-nfs-debuginfo-7.1.0-150500.49.9.2 * qemu-7.1.0-150500.49.9.2 * qemu-arm-7.1.0-150500.49.9.2 * qemu-block-dmg-7.1.0-150500.49.9.2 * qemu-chardev-spice-debuginfo-7.1.0-150500.49.9.2 * qemu-vhost-user-gpu-7.1.0-150500.49.9.2 * qemu-debugsource-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-pci-debuginfo-7.1.0-150500.49.9.2 * qemu-arm-debuginfo-7.1.0-150500.49.9.2 * qemu-chardev-baum-7.1.0-150500.49.9.2 * qemu-block-dmg-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-usb-redirect-debuginfo-7.1.0-150500.49.9.2 *qemu-accel-qtest-debuginfo-7.1.0-150500.49.9.2 * qemu-chardev-spice-7.1.0-150500.49.9.2 * qemu-ui-curses-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-gtk-7.1.0-150500.49.9.2 * qemu-ui-spice-app-debuginfo-7.1.0-150500.49.9.2 * qemu-extra-7.1.0-150500.49.9.2 * qemu-linux-user-debugsource-7.1.0-150500.49.9.1 * qemu-headless-7.1.0-150500.49.9.2 * qemu-hw-s390x-virtio-gpu-ccw-7.1.0-150500.49.9.2 * qemu-hw-usb-host-debuginfo-7.1.0-150500.49.9.2 * qemu-s390x-debuginfo-7.1.0-150500.49.9.2 * qemu-linux-user-debuginfo-7.1.0-150500.49.9.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-7.1.0-150500.49.9.2 * qemu-ivshmem-tools-debuginfo-7.1.0-150500.49.9.2 * qemu-ksm-7.1.0-150500.49.9.2 * qemu-guest-agent-7.1.0-150500.49.9.2 * qemu-audio-alsa-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-usb-smartcard-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-oss-7.1.0-150500.49.9.2 * qemu-audio-dbus-7.1.0-150500.49.9.2 * qemu-block-ssh-7.1.0-150500.49.9.2 * qemu-linux-user-7.1.0-150500.49.9.1 * qemu-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-pa-7.1.0-150500.49.9.2 * qemu-audio-jack-7.1.0-150500.49.9.2 * qemu-chardev-baum-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-spice-core-7.1.0-150500.49.9.2 * qemu-vhost-user-gpu-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-usb-host-7.1.0-150500.49.9.2 * qemu-ui-opengl-debuginfo-7.1.0-150500.49.9.2 * qemu-block-iscsi-7.1.0-150500.49.9.2 * qemu-ui-spice-app-7.1.0-150500.49.9.2 * qemu-block-iscsi-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-usb-smartcard-7.1.0-150500.49.9.2 * qemu-ppc-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-vga-debuginfo-7.1.0-150500.49.9.2 * qemu-accel-tcg-x86-7.1.0-150500.49.9.2 * qemu-block-gluster-debuginfo-7.1.0-150500.49.9.2 * qemu-lang-7.1.0-150500.49.9.2 * qemu-ivshmem-tools-7.1.0-150500.49.9.2 * qemu-hw-usb-redirect-7.1.0-150500.49.9.2 * qemu-s390x-7.1.0-150500.49.9.2 * qemu-audio-oss-debuginfo-7.1.0-150500.49.9.2 *qemu-hw-display-qxl-7.1.0-150500.49.9.2 * qemu-audio-alsa-7.1.0-150500.49.9.2 * qemu-tools-7.1.0-150500.49.9.2 * qemu-ui-dbus-7.1.0-150500.49.9.2 * qemu-x86-debuginfo-7.1.0-150500.49.9.2 * qemu-x86-7.1.0-150500.49.9.2 * qemu-ui-gtk-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-opengl-7.1.0-150500.49.9.2 * qemu-block-nfs-7.1.0-150500.49.9.2 * qemu-audio-jack-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-vga-7.1.0-150500.49.9.2 * qemu-accel-qtest-7.1.0-150500.49.9.2 * qemu-guest-agent-debuginfo-7.1.0-150500.49.9.2 * qemu-block-gluster-7.1.0-150500.49.9.2 * openSUSE Leap 15.5 (s390x x86_64 i586) * qemu-kvm-7.1.0-150500.49.9.2 * openSUSE Leap 15.5 (noarch) * qemu-microvm-7.1.0-150500.49.9.2 * qemu-sgabios-8-150500.49.9.2 * qemu-ipxe-1.0.0+-150500.49.9.2 * qemu-vgabios-1.16.0_0_gd239552-150500.49.9.2 * qemu-skiboot-7.1.0-150500.49.9.2 * qemu-SLOF-7.1.0-150500.49.9.2 * qemu-seabios-1.16.0_0_gd239552-150500.49.9.2 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * qemu-block-rbd-debuginfo-7.1.0-150500.49.9.2 * qemu-block-rbd-7.1.0-150500.49.9.2 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * qemu-hw-display-virtio-gpu-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-debuginfo-7.1.0-150500.49.9.2 * qemu-7.1.0-150500.49.9.2 * qemu-hw-usb-redirect-7.1.0-150500.49.9.2 * qemu-block-curl-debuginfo-7.1.0-150500.49.9.2 * qemu-chardev-spice-debuginfo-7.1.0-150500.49.9.2 * qemu-guest-agent-7.1.0-150500.49.9.2 * qemu-hw-display-qxl-7.1.0-150500.49.9.2 * qemu-ui-spice-core-debuginfo-7.1.0-150500.49.9.2 * qemu-debugsource-7.1.0-150500.49.9.2 * qemu-tools-7.1.0-150500.49.9.2 * qemu-hw-display-qxl-debuginfo-7.1.0-150500.49.9.2 * qemu-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-spice-7.1.0-150500.49.9.2 * qemu-hw-usb-redirect-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-opengl-7.1.0-150500.49.9.2 * qemu-tools-debuginfo-7.1.0-150500.49.9.2 *qemu-block-curl-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-vga-7.1.0-150500.49.9.2 * qemu-ui-spice-core-7.1.0-150500.49.9.2 * qemu-chardev-spice-7.1.0-150500.49.9.2 * qemu-ui-opengl-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-vga-debuginfo-7.1.0-150500.49.9.2 * qemu-guest-agent-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-spice-debuginfo-7.1.0-150500.49.9.2 * SUSE Linux Enterprise Micro 5.5 (aarch64) * qemu-arm-debuginfo-7.1.0-150500.49.9.2 * qemu-arm-7.1.0-150500.49.9.2 * SUSE Linux Enterprise Micro 5.5 (noarch) * qemu-seabios-1.16.0_0_gd239552-150500.49.9.2 * qemu-vgabios-1.16.0_0_gd239552-150500.49.9.2 * qemu-sgabios-8-150500.49.9.2 * qemu-ipxe-1.0.0+-150500.49.9.2 * SUSE Linux Enterprise Micro 5.5 (s390x) * qemu-s390x-7.1.0-150500.49.9.2 * qemu-s390x-debuginfo-7.1.0-150500.49.9.2 * SUSE Linux Enterprise Micro 5.5 (x86_64) * qemu-accel-tcg-x86-debuginfo-7.1.0-150500.49.9.2 * qemu-x86-debuginfo-7.1.0-150500.49.9.2 * qemu-accel-tcg-x86-7.1.0-150500.49.9.2 * qemu-x86-7.1.0-150500.49.9.2 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * qemu-tools-7.1.0-150500.49.9.2 * qemu-debuginfo-7.1.0-150500.49.9.2 * qemu-debugsource-7.1.0-150500.49.9.2 * qemu-tools-debuginfo-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * qemu-ui-dbus-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-usb-host-debuginfo-7.1.0-150500.49.9.2 * qemu-block-ssh-debuginfo-7.1.0-150500.49.9.2 * qemu-lang-7.1.0-150500.49.9.2 * qemu-7.1.0-150500.49.9.2 * qemu-block-rbd-debuginfo-7.1.0-150500.49.9.2 * qemu-block-curl-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-dbus-debuginfo-7.1.0-150500.49.9.2 * qemu-ksm-7.1.0-150500.49.9.2 * qemu-guest-agent-7.1.0-150500.49.9.2 * qemu-block-rbd-7.1.0-150500.49.9.2 * qemu-debugsource-7.1.0-150500.49.9.2 * qemu-audio-dbus-7.1.0-150500.49.9.2 * qemu-block-ssh-7.1.0-150500.49.9.2 *qemu-chardev-baum-7.1.0-150500.49.9.2 * qemu-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-dbus-7.1.0-150500.49.9.2 * qemu-chardev-baum-debuginfo-7.1.0-150500.49.9.2 * qemu-block-curl-7.1.0-150500.49.9.2 * qemu-hw-usb-host-7.1.0-150500.49.9.2 * qemu-ui-curses-debuginfo-7.1.0-150500.49.9.2 * qemu-block-iscsi-7.1.0-150500.49.9.2 * qemu-block-iscsi-debuginfo-7.1.0-150500.49.9.2 * qemu-guest-agent-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-curses-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5 (aarch64) * qemu-arm-debuginfo-7.1.0-150500.49.9.2 * qemu-arm-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5 (aarch64 ppc64le x86_64) * qemu-chardev-spice-7.1.0-150500.49.9.2 * qemu-chardev-spice-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-gtk-7.1.0-150500.49.9.2 * qemu-ui-opengl-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-spice-7.1.0-150500.49.9.2 * qemu-ui-spice-app-7.1.0-150500.49.9.2 * qemu-ui-spice-app-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-qxl-7.1.0-150500.49.9.2 * qemu-ui-spice-core-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-gtk-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-vga-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-usb-redirect-debuginfo-7.1.0-150500.49.9.2 * qemu-ui-opengl-7.1.0-150500.49.9.2 * qemu-hw-usb-redirect-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-vga-7.1.0-150500.49.9.2 * qemu-ui-spice-core-7.1.0-150500.49.9.2 * qemu-hw-display-qxl-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-spice-debuginfo-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5 (noarch) * qemu-vgabios-1.16.0_0_gd239552-150500.49.9.2 * qemu-ipxe-1.0.0+-150500.49.9.2 * qemu-sgabios-8-150500.49.9.2 * qemu-skiboot-7.1.0-150500.49.9.2 * qemu-SLOF-7.1.0-150500.49.9.2 * qemu-seabios-1.16.0_0_gd239552-150500.49.9.2 * Server Applications Module 15-SP5 (ppc64le) * qemu-ppc-debuginfo-7.1.0-150500.49.9.2 * qemu-ppc-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5(s390x x86_64) * qemu-hw-display-virtio-gpu-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-pci-7.1.0-150500.49.9.2 * qemu-kvm-7.1.0-150500.49.9.2 * qemu-hw-display-virtio-gpu-pci-debuginfo-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5 (s390x) * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-7.1.0-150500.49.9.2 * qemu-s390x-7.1.0-150500.49.9.2 * qemu-s390x-debuginfo-7.1.0-150500.49.9.2 * qemu-hw-s390x-virtio-gpu-ccw-7.1.0-150500.49.9.2 * Server Applications Module 15-SP5 (x86_64) * qemu-x86-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-pa-7.1.0-150500.49.9.2 * qemu-x86-7.1.0-150500.49.9.2 * qemu-accel-tcg-x86-debuginfo-7.1.0-150500.49.9.2 * qemu-audio-alsa-7.1.0-150500.49.9.2 * qemu-audio-alsa-debuginfo-7.1.0-150500.49.9.2 * qemu-accel-tcg-x86-7.1.0-150500.49.9.2 * qemu-audio-pa-debuginfo-7.1.0-150500.49.9.2 ## References: * https://www.suse.com/security/cve/CVE-2021-3638.html * https://www.suse.com/security/cve/CVE-2023-3180.html * https://www.suse.com/security/cve/CVE-2023-3354.html * https://bugzilla.suse.com/show_bug.cgi?id=1188609 * https://bugzilla.suse.com/show_bug.cgi?id=1212850 * https://bugzilla.suse.com/show_bug.cgi?id=1213210 * https://bugzilla.suse.com/show_bug.cgi?id=1213925 * https://bugzilla.suse.com/show_bug.cgi?id=1215311 . The recent QEMU updates address critical security flaws within SUSE systems. Immediate actions are recommended to enhance protection.. SUSE Security Update,Qemu Patch,Important Security Fix,Buffer Overflow,Virtualization. . Severity: Important. LinuxSecurity.com Team
An update for open-vm-tools is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: open-vm-tools security update Advisory ID: RHSA-2023:5313-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5313 Issue date: 2023-09-20 CVE Names: CVE-2023-20900 ===================================================================== 1. Summary: An update for open-vm-tools is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, x86_64 3. Description: The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines. Security Fix(es): * open-vm-tools: SAML token signature bypass (CVE-2023-20900) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2236542 - CVE-2023-20900 open-vm-tools: SAML token signature bypass 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: open-vm-tools-12.1.5-1.el9_2.3.src.rpm aarch64: open-vm-tools-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-debuginfo-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-debugsource-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-desktop-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-desktop-debuginfo-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-sdmp-debuginfo-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-test-12.1.5-1.el9_2.3.aarch64.rpm open-vm-tools-test-debuginfo-12.1.5-1.el9_2.3.aarch64.rpm x86_64: open-vm-tools-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-debuginfo-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-debugsource-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-desktop-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-desktop-debuginfo-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-salt-minion-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-sdmp-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-sdmp-debuginfo-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-test-12.1.5-1.el9_2.3.x86_64.rpm open-vm-tools-test-debuginfo-12.1.5-1.el9_2.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-20900 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlC2OxAAoJENzjgjWX9erEJ9AP/R9g99Xb4AeQ1D01808IWEtn tP66Cmr4VzAyJkO45E7tPjXpWKgbw6NuJkV2MKDLGwJTChXFjsSMtUAPg1tgj/qr J+YL0rDiNkWrmpHhFVNrhXGuoI+ZSAxb3Z/gQUQklzY2SWeCmfSuWdb6boaoenij jjrD1XjqCnsrMcmhS4Wx439X6k5nL5Z5+wZcxqqcbn3v0C2fh7EsjErxDEhBXM76 9pvDRaM9ssLt0hPCkMXO5jm7A4MQZUHzePVmC139yfSqbDLnL8kvHFCjXHRSkaqe nS+EwBhiYd7xPn12xnpy+ykNtqzXKKPHztoo77VE2oPEeGOmlOXOQInR+sLOpkHw W5aDMaAIVk8L1JAobLGsqriuHskeFa+nBTbDRuF1lRCHhA8z0w0kFRebTEcB0eBF Aa5hhiPE58RknIMOiAdUMPRVA1I3KwdTYc7+KT8Y1hVWo+md0S4W82pnTWWU97gl nYFslT5xoVlo1R5DBA6E8wFdNUO6TBLmJNMVPmuNqY+u/x7uclbdo6mX8JCquuHc o6ZXZt+nrFscPemjR1qlimabjc49iJd/w3LcLMtAhHikctyje3DvP55kQKLYz4jc N3ry8ZWn6luyqYulFjK2+PZ21lqibOTmznZDJ3JLgd/cmVDJ2cJdHOU48FalKUj5 /tDusnr5P7KQWunqmQHz =qI/X -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Virtualization release 4.11.6 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Virtualization 4.11.6 security and bug fix update Advisory ID: RHSA-2023:5103-01 Product: OpenShift Virtualization Advisory URL: https://access.redhat.com/errata/RHSA-2023:5103 Issue date: 2023-09-12 CVE Names: CVE-2016-3709 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0286 CVE-2023-0361 CVE-2023-2828 CVE-2023-3089 CVE-2023-3899 CVE-2023-38408 ===================================================================== 1. Summary: Red Hat OpenShift Virtualization release 4.11.6 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section 2. Description: OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains OpenShift Virtualization 4.11.6 images. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Requested TSC frequency outside tolerance range & TSC scaling not supported (BZ#2151169) * User cannot get resource"virtualmachineinstances/portforward" in API group "subresources.kubevirt.io" (BZ#2160673) * 4.11.4 containers (BZ#2173835) * VMI with x86_Icelake fail when mpx feature is missing (BZ#2218193) 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2151169 - Requested TSC frequency outside tolerance range & TSC scaling not supported 2160673 - User cannot get resource "virtualmachineinstances/portforward" in API group "subresources.kubevirt.io" 2173835 - 4.11.4 containers 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 2218193 - VMI with x86_Icelake fail when mpx feature is missing 5. References: https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/cve/CVE-2023-38408 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlAINpAAoJENzjgjWX9erEdG4P/jO759CVAR4s+eVcATfiu6r+ VPBs/U/dKc0aau2J2m5m4MXxUDl5xwBU/2MlrjMkO2m/nwLo8nziwZKW2m4ZsY+f i9f3H66M71u4eoPzfqLQ9imjyWAwYwYuHNumWQyzeWjStWaR7p3/NBo9vHaE63To ZFBmOZxRx9wsAfzhjSQbteWH7BNwqlqqjjZlCWf13BETlj2SF+6ow1soxVdSLY0M Dn4nKvohgA5neX3KBd51+f66R1HFKZshgUSH7/YlDC3FTRScFOPnbyrssUpGZpKg Ldf0vr27YVQIpfZRVIjwPgXK3oQ8hs+XYQgxP8T7CLAZ9bHDvqrb2y/O19XfqRW4 15/hsjuLUwmIQNpYdxu9s3lbPdNSxpH7g47OTF27JmHVSEe8mBlBOxEL7W3AvC5l v/0ovn8mlAJYfLWFOFU38Jy5FyDvR3GsEUo+xgWGJlSHGRx33nc/AMG+1MWHnxyV yAWfTkw3/QmfqK459kIKMnJuxB9SnFgf4tLpEkuwpQrgyiAfc//3PWQ0vJP9bXsu lxeV2fd8WZ9yEXPwkVN67sr/QOQYy2pdz+yxVDYHnIEfttiRgMutzKoMMGFIJmAW 81bG9c3hkArSvNraqZZbMUhfTbF8OfjHeroBQp+XcqSipk+mmoZKgFr8yhPzE1Rp 60MIgjdOBksum7fyI6a/ =7uko -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Virtualization release 4.12.5 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: OpenShift Virtualization 4.12.5 security and bug fix update Advisory ID: RHSA-2023:4421-01 Product: OpenShift Virtualization Advisory URL: https://access.redhat.com/errata/RHSA-2023:4421 Issue date: 2023-08-01 CVE Names: CVE-2020-24736 CVE-2022-4304 CVE-2022-41723 CVE-2023-0215 CVE-2023-0286 CVE-2023-1667 CVE-2023-2283 CVE-2023-2828 CVE-2023-3089 CVE-2023-24329 CVE-2023-24540 CVE-2023-26604 ===================================================================== 1. Summary: Red Hat OpenShift Virtualization release 4.12.5 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains OpenShift Virtualization 4.12.5 images. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) * golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * [4.12]must-gather doesn't collect ruletebles (BZ#2208641) * nft rules are not collected if the VMs are running in the node where must-gather is running (BZ#2214454) * [cnv-4.12] kubevirt should allow setting cluster-wide virt-launcher runtimeclass (BZ#2217913) * USB-redirection regression (BZ#2221222) 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2027959 - [RFE] virt-launcher pod of Windows VM stuck in terminating state, no button in the UI to force power off 2182056 - Cloned VM should not use the same PVC of the source VM 2196027 - CVE-2023-24540 golang: html/template: improper handling of JavaScript whitespace 2208641 - [4.12] must-gather doesn't collect ruletebles 2209318 - [4.12.z] VM connected to a VLAN is also receiving packets from VLAN 1 2209848 - OpenShift Virtualization Overview page shows no metrics for "All Projects" 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 2214454 - nft rules are not collected if the VMs are running in the node where must-gather is running 2216447 - must-gather: Multiple empty files under vms/ if the VM was live migrated 2216449 - must-gather is using unavailable brctl command 2217913 - [cnv-4.12] kubevirt should allow setting cluster-wide virt-launcher runtimeclass 2220843 - [4.12]Missing StorageProfile defaults for IBM and AWS EFS CSI provisioners 2221222 - USB-redirection regression 2222011 - [4.12]DataImportCron Garbage Collection can mistakenly delete latest PVC 5.References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-24540 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkyWkDAAoJENzjgjWX9erEf10P+gOCKsRV1UgO1ZTIPY7LSiTP LQQ/HW3WnVup2ameg2z6O3+eUOJNWVCB9UWEvnlRiMMhLOhKhfqCjIYdBQkjaQM5 n6XYVEOYRj+LfGLh4JN81BLUat/9On6gDXx2LcNZvTwk4foJukYlv0wmtRPSsGJQ 9qCg63EjDhpTIFo3bMF1rjDgapcjL9tFNaO0HBp0PtcYiN47oBr6opIQ3kpS3cN4 cpZJGpeJBP3kPPYbpd5L/qJ2f6GJxHEztGQFChgzI9vK92RVJveHNYJaoqD3FqQr j9+49nB/pmVqtgDX2Tjruh9h0F9aBy4c81Wl8YQ7zq5otBqwT4UKNR4WREzkMA6H AG6DAFa/5i+akC6ENUgo/edxyEViwY7EcLhESxvBzOg4aHGIe7YawvnKdsItYoc1 8phvDLLkwkrwUjbYqZ4xCwMPPgeY1ASmUueFSNp/g6PPaeYGNlY9+iMxaiP4I49/ LfIM1hx5H2rodI3kbAsC8n+EcHQZRJ7AoWEXfhAELTU//gx2zoyaEly6660qaxLC o8hV6L7YRiIgRYwKZLgd8NlVTfU+hXS62tL/A9MfxHdbgTZEo/FbR8sWfSaDKmbf OdPQ8bMKDUZ4mMT0tsODTpeHTwlfXRDBkdr/Qz5XlcYp17YvxFMXJfUDghn1FY9j 1U9dFxlPP5VCadFQo/WJ =SNKD -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.