RHSA-2022:6392: Important: RHV RHEL Host (ovirt-host) [ovirt-4.5.2] security update
The ovirt-host package consolidates host package requirements into a single meta package.Security Fix(es): moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): The hosted-engine-ha binaries have been moved from /usr/share to /usr/libexec. As a result, the hosted-engine --clean-metadata command fails. With this release, you must use the new path for the command to succeed: /usr/libexec/ovirt-hosted-engine-ha/ovirt-ha-agent (BZ#2105781) A new warning has been added to the vdsm-tool to protect users from using the unsupported userfriendlynames multipath configuration. The following is an example of the output: $ vdsm-tool is-configured --module multipathWARNING: Invalid configuration: 'userfriendlynames' is enabled in multipath configuration: section1 { key1 value1 userfriendlynames yes key2 value2 } section2 { userfriendlynames yes }This configuration is not supported and may lead to storage domain corruption. (BZ#1793207)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6392?
The severity of RHSA-2022:6392 is categorized based on its potential impact and usual environmental factors.
How do I fix RHSA-2022:6392?
To fix RHSA-2022:6392, upgrade the affected packages to the specified versions outlined in the advisory.
What are the affected packages for RHSA-2022:6392?
The affected packages for RHSA-2022:6392 include ovirt-host, cockpit-ovirt, and vdsm among others.
What vulnerability does RHSA-2022:6392 address?
RHSA-2022:6392 addresses a vulnerability related to an inefficient parsing algorithm in the moment package, leading to a potential denial of service.
Is RHSA-2022:6392 applicable to my system?
RHSA-2022:6392 is applicable to systems using specific versions of Red Hat Enterprise Linux and related oVirt packages.