RHSA-2020:4201: Low: OpenShift Virtualization 2.4.2 Images
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.Security Fix(es): golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586) golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Container-native Virtualization 2.4.2 Images (BZ#1877407) This advisory contains the following OpenShift Virtualization 2.4.2 images:RHEL-7-CNV-2.4==============kubevirt-ssp-operator-container-v2.4.2-2RHEL-8-CNV-2.4==============virt-cdi-controller-container-v2.4.2-1virt-cdi-apiserver-container-v2.4.2-1hostpath-provisioner-operator-container-v2.4.2-1virt-cdi-uploadproxy-container-v2.4.2-1virt-cdi-cloner-container-v2.4.2-1virt-cdi-importer-container-v2.4.2-1kubevirt-template-validator-container-v2.4.2-1hostpath-provisioner-container-v2.4.2-1virt-cdi-uploadserver-container-v2.4.2-1virt-cdi-operator-container-v2.4.2-1virt-controller-container-v2.4.2-1kubevirt-cpu-model-nfd-plugin-container-v2.4.2-1virt-api-container-v2.4.2-1ovs-cni-marker-container-v2.4.2-1kubevirt-cpu-node-labeller-container-v2.4.2-1bridge-marker-container-v2.4.2-1kubevirt-metrics-collector-container-v2.4.2-1kubemacpool-container-v2.4.2-1cluster-network-addons-operator-container-v2.4.2-1ovs-cni-plugin-container-v2.4.2-1kubernetes-nmstate-handler-container-v2.4.2-1cnv-containernetworking-plugins-container-v2.4.2-1virtio-win-container-v2.4.2-1virt-handler-container-v2.4.2-1virt-launcher-container-v2.4.2-1cnv-must-gather-container-v2.4.2-1virt-operator-container-v2.4.2-1vm-import-controller-container-v2.4.2-1hyperconverged-cluster-operator-container-v2.4.2-1vm-import-operator-container-v2.4.2-1kubevirt-vmware-container-v2.4.2-1kubevirt-v2v-conversion-container-v2.4.2-1kubevirt-kvm-info-nfd-plugin-container-v2.4.2-1node-maintenance-operator-container-v2.4.2-1hco-bundle-registry-container-v2.4.2-15
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4201?
The severity of RHSA-2020:4201 is considered moderate due to the potential for denial of service.
How do I fix RHSA-2020:4201?
To fix RHSA-2020:4201, you should update to the latest version of OpenShift Virtualization that includes the relevant security patches.
What vulnerabilities are addressed in RHSA-2020:4201?
RHSA-2020:4201 addresses vulnerabilities related to data races in certain net/http servers and potential denial of service issues.
Who is affected by RHSA-2020:4201?
RHSA-2020:4201 affects users of OpenShift Virtualization running vulnerable versions of the golang libraries.
Is there a workaround for RHSA-2020:4201?
There are no recommended workarounds for RHSA-2020:4201; the best course of action is to apply the updates.