RHSA-2022:0540: Important: Red Hat Virtualization Host security update [ovirt-4.4.10-1]
The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Security Fix(es):<br><li> polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector (CVE-2021-4034)</li> <li> kernel: xfs: raw block device data leak in XFSIOCALLOCSP IOCTL (CVE-2021-4155)</li> <li> aide: heap-based buffer overflow on outputs larger than B64BUF (CVE-2021-45417)</li> <li> kernel: fscontext: heap overflow in legacy parameter handling (CVE-2022-0185)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Rebased wget package and its dependencies for the same version shipped with recent RHEL. (BZ#2030082)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0540?
The severity of RHSA-2022:0540 is classified as important.
How do I fix RHSA-2022:0540?
To fix RHSA-2022:0540, ensure that you update the affected packages to the remedied versions 4.4.10-1.el8e for redhat-release-virtualization-host and 1.19.5-10.el8 for wget.
What packages are affected by RHSA-2022:0540?
The affected packages include redhat-release-virtualization-host, redhat-release-virtualization-host-content, wget, and libmetalink.
Is RHSA-2022:0540 specific to any version of Red Hat?
Yes, RHSA-2022:0540 is specific to Red Hat Enterprise Linux 8.
How can I check if my system is vulnerable to RHSA-2022:0540?
You can check if your system is vulnerable by verifying the installed versions of the affected packages against the versions listed in the RHSA-2022:0540 advisory.