RHSA-2021:3235: Important: Red Hat Virtualization Host security and bug fix update [ovirt-4.4.7]
The redhat-virtualization-host packages provide the Red Hat Virtualization Host.These packages include redhat-release-virtualization-host, ovirt-node, andrhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using aspecial build of Red Hat Enterprise Linux with only the packages required tohost virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.Security Fix(es): edk2: remote buffer overflow in IScsiHexToBin function in NetworkPkg/IScsiDxe () kernel: Improper handling of VMIO|VMPFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543) kernel: race condition in net/can/bcm.c leads to local privilege escalation (CVE-2021-3609) sssd: shell command injection in sssctl (CVE-2021-3621) kernel: out-of-bounds write in xtcompattargetfromuser() in net/netfilter/xtables.c (CVE-2021-22555) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Rebase package(s) to version: 1.2.23 Highlights, important fixes, or notable enhancements: imgbase should not copy the selinux binary policy file (BZ# 1979624) (BZ#1989397) RHV-H has been rebased on Red Hat Enterprise Linux 8.4 Batch #2. (BZ#1975177)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3235?
The severity of RHSA-2021:3235 is classified as important.
How do I fix RHSA-2021:3235?
To fix RHSA-2021:3235, update the affected packages to the recommended versions.
What packages are affected by RHSA-2021:3235?
Affected packages include redhat-release-virtualization-host, imgbased, and redhat-virtualization-host among others.
Is there a workaround for RHSA-2021:3235?
There are no known workarounds for RHSA-2021:3235; updating the packages is required.
How can I determine if my system is vulnerable to RHSA-2021:3235?
You can determine if your system is vulnerable by checking the installed versions of the affected packages against the advisory.