RHSA-2022:6351: Important: OpenShift Virtualization 4.10.5 Images security and bug fix update
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.This advisory contains the following OpenShift Virtualization 4.10.5 images:RHEL-8-CNV-4.10===============cluster-network-addons-operator-container-v4.10.5-1kubemacpool-container-v4.10.5-1virt-cdi-importer-container-v4.10.5-1hyperconverged-cluster-operator-container-v4.10.5-1hostpath-provisioner-operator-container-v4.10.5-1virtio-win-container-v4.10.5-1virt-cdi-cloner-container-v4.10.5-1kubevirt-ssp-operator-container-v4.10.5-1cnv-containernetworking-plugins-container-v4.10.5-1hyperconverged-cluster-webhook-container-v4.10.5-1virt-cdi-apiserver-container-v4.10.5-1ovs-cni-plugin-container-v4.10.5-1virt-cdi-uploadserver-container-v4.10.5-1virt-cdi-uploadproxy-container-v4.10.5-1virt-cdi-controller-container-v4.10.5-1kubevirt-template-validator-container-v4.10.5-1virt-cdi-operator-container-v4.10.5-1hostpath-provisioner-container-v4.10.5-1hostpath-csi-driver-container-v4.10.5-1kubernetes-nmstate-handler-container-v4.10.5-1ovs-cni-marker-container-v4.10.5-1bridge-marker-container-v4.10.5-1node-maintenance-operator-container-v4.10.5-1cnv-must-gather-container-v4.10.5-2virt-controller-container-v4.10.5-3virt-api-container-v4.10.5-3virt-handler-container-v4.10.5-3virt-operator-container-v4.10.5-3virt-artifacts-server-container-v4.10.5-3virt-launcher-container-v4.10.5-3libguestfs-tools-container-v4.10.5-3hco-bundle-registry-container-v4.10.5-6Security Fix(es): kubeVirt: Arbitrary file read on the host from KubeVirt VMs (CVE-2022-1798) go-restful: Authorization Bypass Through User-Controlled Key (CVE-2022-1996) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6351?
The severity of RHSA-2022:6351 is considered to be moderate.
How do I fix RHSA-2022:6351?
To fix RHSA-2022:6351, you should update to the recommended OpenShift Virtualization 4.10.5 images.
Which products are affected by RHSA-2022:6351?
RHSA-2022:6351 affects OpenShift Virtualization on the Red Hat OpenShift Container Platform.
What are the main vulnerabilities addressed in RHSA-2022:6351?
RHSA-2022:6351 addresses various vulnerabilities in OpenShift Virtualization that could impact security and performance.
When was RHSA-2022:6351 released?
RHSA-2022:6351 was released as part of the advisory process in 2022.