RHSA-2020:5611: Important: Red Hat Virtualization security, bug fix, and enhancement update
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. <br>The ovirt-node-ng packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>The following packages have been upgraded to a later upstream version: cockpit-ovirt (0.14.15), redhat-release-virtualization-host (4.4.3), redhat-virtualization-host (4.4.3), v2v-conversion-host (1.16.2). (BZ#1898023, BZ#1902301, BZ#1907539)<br>Security Fix(es):<br><li> lldpd: buffer overflow in the lldpdecode function in daemon/protocols/lldp.c (CVE-2015-8011)</li> <li> nodejs-lodash: prototype pollution in zipObjectDeep function (CVE-2020-8203)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Previously, upgrade from Red Had Virtualization (RHV) 4.4.1 to RHV 4.4.2 failed due to dangling symlinks from the iSCSI Storage Domain that weren't cleaned up. In this release, the upgrade succeeds. (BZ#1895356)</li> <li> Previously, when migrating a Windows virtual machine from a VMware environment to Red Hat Virtualization 4.4.3, the migration failed due to a file permission error. In this release, the migration succeeds. (BZ#1901423)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5611?
The severity of RHSA-2020:5611 is categorized as important.
How do I fix RHSA-2020:5611?
To fix RHSA-2020:5611, update the affected packages to their latest versions as specified in the advisory.
Which packages are affected by RHSA-2020:5611?
Affected packages include redhat-release-virtualization-host, cockpit-ovirt, and v2v-conversion-host among others.
Is RHSA-2020:5611 related to security vulnerabilities?
Yes, RHSA-2020:5611 addresses security vulnerabilities in the Red Hat Virtualization Host packages.
What is the recommended action for system administrators regarding RHSA-2020:5611?
System administrators should prioritize updating affected packages to maintain security and system integrity.