{"id":34336,"date":"2022-12-02T19:04:02","date_gmt":"2022-12-02T16:04:02","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170083\/RHSA-2022-8750-01.txt"},"modified":"2022-12-03T08:12:31","modified_gmt":"2022-12-03T04:42:31","slug":"red-hat-security-advisory-2022-8750-01-openshift-virtualization","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-8750-01-openshift-virtualization\/","title":{"rendered":"Red Hat Security Advisory 2022-8750-01 OpenShift Virtualization"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Moderate: OpenShift Virtualization 4.11.1 security and bug fix update<br \/>\nAdvisory ID: RHSA-2022:8750-01<br \/>\nProduct: cnv<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8750<br \/>\nIssue date: 2022-12-01<br \/>\nCVE Names: CVE-2015-20107 CVE-2016-3709 CVE-2020-0256<br \/>\nCVE-2020-35525 CVE-2020-35527 CVE-2021-0308<br \/>\nCVE-2021-38561 CVE-2022-0391 CVE-2022-0934<br \/>\nCVE-2022-1292 CVE-2022-1304 CVE-2022-1586<br \/>\nCVE-2022-1785 CVE-2022-1897 CVE-2022-1927<br \/>\nCVE-2022-2068 CVE-2022-2097 CVE-2022-2509<br \/>\nCVE-2022-3515 CVE-2022-22624 CVE-2022-22628<br \/>\nCVE-2022-22629 CVE-2022-22662 CVE-2022-24675<br \/>\nCVE-2022-24795 CVE-2022-24921 CVE-2022-25308<br \/>\nCVE-2022-25309 CVE-2022-25310 CVE-2022-26700<br \/>\nCVE-2022-26709 CVE-2022-26710 CVE-2022-26716<br \/>\nCVE-2022-26717 CVE-2022-26719 CVE-2022-27404<br \/>\nCVE-2022-27405 CVE-2022-27406 CVE-2022-28327<br \/>\nCVE-2022-29154 CVE-2022-30293 CVE-2022-30629<br \/>\nCVE-2022-30698 CVE-2022-30699 CVE-2022-32206<br \/>\nCVE-2022-32208 CVE-2022-34903 CVE-2022-37434<br \/>\nCVE-2022-38177 CVE-2022-38178 CVE-2022-40674<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p dir=\"ltr\">Red Hat OpenShift Virtualization release 4.11.1 is now available with<br \/>\nupdates to packages and images that fix several bugs and add enhancements.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">OpenShift Virtualization is Red Hat&#8217;s virtualization solution designed for<br \/>\nRed Hat OpenShift Container Platform.<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* golang: out-of-bounds read in golang.org\/x\/text\/language leads to DoS<br \/>\n(CVE-2021-38561)<\/p>\n<p dir=\"ltr\">* golang: encoding\/pem: fix stack overflow in Decode (CVE-2022-24675)<\/p>\n<p dir=\"ltr\">* golang: regexp: stack exhaustion via a deeply nested expression<br \/>\n(CVE-2022-24921)<\/p>\n<p dir=\"ltr\">* golang: crypto\/elliptic: panic caused by oversized scalar<br \/>\n(CVE-2022-28327)<\/p>\n<p dir=\"ltr\">* golang: crypto\/tls: session tickets lack random ticket_age_add<br \/>\n(CVE-2022-30629)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p dir=\"ltr\">Bug Fix(es):<\/p>\n<p dir=\"ltr\">* Cloning a Block DV to VM with Filesystem with not big enough size comes<br \/>\nto endless loop &#8211; using pvc api (BZ#2033191)<\/p>\n<p dir=\"ltr\">* Restart of VM Pod causes SSH keys to be regenerated within VM<br \/>\n(BZ#2087177)<\/p>\n<p dir=\"ltr\">* Import gzipped raw file causes image to be downloaded and uncompressed to<br \/>\nTMPDIR (BZ#2089391)<\/p>\n<p dir=\"ltr\">* [4.11] VM Snapshot Restore hangs indefinitely when backed by a<br \/>\nsnapshotclass (BZ#2098225)<\/p>\n<p dir=\"ltr\">* Fedora version in DataImportCrons is not &#8216;latest&#8217; (BZ#2102694)<\/p>\n<p dir=\"ltr\">* [4.11] Cloned VM&#8217;s snapshot restore fails if the source VM disk is<br \/>\ndeleted (BZ#2109407)<\/p>\n<p dir=\"ltr\">* CNV introduces a compliance check fail in &#8220;ocp4-moderate&#8221; profile &#8211;<br \/>\nroutes-protected-by-tls (BZ#2110562)<\/p>\n<p dir=\"ltr\">* Nightly build: v4.11.0-578: index format was changed in 4.11 to<br \/>\nfile-based instead of sqlite-based (BZ#2112643)<\/p>\n<p dir=\"ltr\">* Unable to start windows VMs on PSI setups (BZ#2115371)<\/p>\n<p dir=\"ltr\">* [4.11.1]virt-launcher cannot be started on OCP 4.12 due to PodSecurity<br \/>\nrestricted:v1.24 (BZ#2128997)<\/p>\n<p dir=\"ltr\">* Mark Windows 11 as TechPreview (BZ#2129013)<\/p>\n<p dir=\"ltr\">* 4.11.1 rpms (BZ#2139453)<\/p>\n<p dir=\"ltr\">This advisory contains the following OpenShift Virtualization 4.11.1<br \/>\nimages.<\/p>\n<p dir=\"ltr\">RHEL-8-CNV-4.11<\/p>\n<p dir=\"ltr\">virt-cdi-operator-container-v4.11.1-5<br \/>\nvirt-cdi-uploadserver-container-v4.11.1-5<br \/>\nvirt-cdi-apiserver-container-v4.11.1-5<br \/>\nvirt-cdi-importer-container-v4.11.1-5<br \/>\nvirt-cdi-controller-container-v4.11.1-5<br \/>\nvirt-cdi-cloner-container-v4.11.1-5<br \/>\nvirt-cdi-uploadproxy-container-v4.11.1-5<br \/>\ncheckup-framework-container-v4.11.1-3<br \/>\nkubevirt-tekton-tasks-wait-for-vmi-status-container-v4.11.1-7<br \/>\nkubevirt-tekton-tasks-create-datavolume-container-v4.11.1-7<br \/>\nkubevirt-template-validator-container-v4.11.1-4<br \/>\nvirt-handler-container-v4.11.1-5<br \/>\nhostpath-provisioner-operator-container-v4.11.1-4<br \/>\nvirt-api-container-v4.11.1-5<br \/>\nvm-network-latency-checkup-container-v4.11.1-3<br \/>\ncluster-network-addons-operator-container-v4.11.1-5<br \/>\nvirtio-win-container-v4.11.1-4<br \/>\nvirt-launcher-container-v4.11.1-5<br \/>\novs-cni-marker-container-v4.11.1-5<br \/>\nhyperconverged-cluster-webhook-container-v4.11.1-7<br \/>\nvirt-controller-container-v4.11.1-5<br \/>\nvirt-artifacts-server-container-v4.11.1-5<br \/>\nkubevirt-tekton-tasks-modify-vm-template-container-v4.11.1-7<br \/>\nkubevirt-tekton-tasks-disk-virt-customize-container-v4.11.1-7<br \/>\nlibguestfs-tools-container-v4.11.1-5<br \/>\nhostpath-provisioner-container-v4.11.1-4<br \/>\nkubevirt-tekton-tasks-disk-virt-sysprep-container-v4.11.1-7<br \/>\nkubevirt-tekton-tasks-copy-template-container-v4.11.1-7<br \/>\ncnv-containernetworking-plugins-container-v4.11.1-5<br \/>\nbridge-marker-container-v4.11.1-5<br \/>\nvirt-operator-container-v4.11.1-5<br \/>\nhostpath-csi-driver-container-v4.11.1-4<br \/>\nkubevirt-tekton-tasks-create-vm-from-template-container-v4.11.1-7<br \/>\nkubemacpool-container-v4.11.1-5<br \/>\nhyperconverged-cluster-operator-container-v4.11.1-7<br \/>\nkubevirt-ssp-operator-container-v4.11.1-4<br \/>\novs-cni-plugin-container-v4.11.1-5<br \/>\nkubevirt-tekton-tasks-cleanup-vm-container-v4.11.1-7<br \/>\nkubevirt-tekton-tasks-operator-container-v4.11.1-2<br \/>\ncnv-must-gather-container-v4.11.1-8<br \/>\nkubevirt-console-plugin-container-v4.11.1-9<br \/>\nhco-bundle-registry-container-v4.11.1-49<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">Before applying this update, make sure all previously released errata<br \/>\nrelevant to your system have been applied.<\/p>\n<p dir=\"ltr\">For details on how to apply this update, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">2033191 &#8211; Cloning a Block DV to VM with Filesystem with not big enough size comes to endless loop &#8211; using pvc api<br \/>\n2064857 &#8211; CVE-2022-24921 golang: regexp: stack exhaustion via a deeply nested expression<br \/>\n2070772 &#8211; When specifying pciAddress for several SR-IOV NIC they are not correctly propagated to libvirt XML<br \/>\n2077688 &#8211; CVE-2022-24675 golang: encoding\/pem: fix stack overflow in Decode<br \/>\n2077689 &#8211; CVE-2022-28327 golang: crypto\/elliptic: panic caused by oversized scalar<br \/>\n2087177 &#8211; Restart of VM Pod causes SSH keys to be regenerated within VM<br \/>\n2089391 &#8211; Import gzipped raw file causes image to be downloaded and uncompressed to TMPDIR<br \/>\n2091856 &#8211; ?Edit BootSource? action should have more explicit information when disabled<br \/>\n2092793 &#8211; CVE-2022-30629 golang: crypto\/tls: session tickets lack random ticket_age_add<br \/>\n2098225 &#8211; [4.11] VM Snapshot Restore hangs indefinitely when backed by a snapshotclass<br \/>\n2100495 &#8211; CVE-2021-38561 golang: out-of-bounds read in golang.org\/x\/text\/language leads to DoS<br \/>\n2102694 &#8211; Fedora version in DataImportCrons is not &#8216;latest&#8217;<br \/>\n2109407 &#8211; [4.11] Cloned VM&#8217;s snapshot restore fails if the source VM disk is deleted<br \/>\n2110562 &#8211; CNV introduces a compliance check fail in &#8220;ocp4-moderate&#8221; profile &#8211; routes-protected-by-tls<br \/>\n2112643 &#8211; Nightly build: v4.11.0-578: index format was changed in 4.11 to file-based instead of sqlite-based<br \/>\n2115371 &#8211; Unable to start windows VMs on PSI setups<br \/>\n2119613 &#8211; GiB changes to B in Template&#8217;s Edit boot source reference modal<br \/>\n2128554 &#8211; The storageclass of VM disk is different from quick created and customize created after changed the default storageclass<br \/>\n2128872 &#8211; [4.11]Can&#8217;t restore cloned VM<br \/>\n2128997 &#8211; [4.11.1]virt-launcher cannot be started on OCP 4.12 due to PodSecurity restricted:v1.24<br \/>\n2129013 &#8211; Mark Windows 11 as TechPreview<br \/>\n2129235 &#8211; [RFE] Add &#8220;Copy SSH command&#8221; to VM action list<br \/>\n2134668 &#8211; Cannot edit ssh even vm is stopped<br \/>\n2139453 &#8211; 4.11.1 rpms<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2015-20107<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2016-3709<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-0256<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-35525<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-35527<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-0308<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-38561<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0391<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0934<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1292<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1304<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1586<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1785<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1897<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1927<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2068<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2097<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2509<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-3515<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22624<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22628<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22629<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22662<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24675<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24795<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24921<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25308<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25309<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25310<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26700<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26709<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26710<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26716<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26717<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26719<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27404<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27405<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27406<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-28327<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-29154<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30293<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30629<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30698<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30699<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-32206<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-32208<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-34903<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-37434<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-38177<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-38178<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-40674<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBY4lNCdzjgjWX9erEAQhXxhAAjaag4e7jIpQLpc0kJhc\/hn59M4UIxn8v<br \/>\na1L+lD58IrBfY3KAtSAK0t3ei92Lyf8LCJqm027yGlIskeCV91vkO9ZpJhPfRasU<br \/>\nu1a8Uhd\/5F6caB0xUPX26vyCyksalw17CNmLWh5wd2izhkOGctkgVD7LhsVzXbFh<br \/>\ntIomeVp\/hVwW9ILX03ijss27E6m2ZUczgWmuNpviqW8WRFMUw3ZM+1MxnSDHxURe<br \/>\nH28dsj2l7nrshdBGrZeuj2HBoA0\/x3Vsc2jiXfP8nt7LcQ\/pb1DN4MYo6lAAEVkC<br \/>\nO2LlzTAzw\/3MAGofaRinyHZD2aoqicPqooUIQglBbF6cvYAUrMtxRCwKcZOckE3d<br \/>\nF2exKjihBY3JeLlsjpWXBe0yAhdwse7j0oovNL2uQH1imUr7Y1pXVlJqeDzHkzME<br \/>\nMIRKzuuTGJe1D9Av4S8R+W5eT7iXBAH7x9Lia1NFxeflemVQbyr8ayEMLcmiDuyj<br \/>\nxMKYFFpW9GmplZlCnDaG5lxKu8ZbOkRzanaLeLn+G5j1+1w9Y9wGtlXJIHV6gmfC<br \/>\nWk33MBCpqCGg1Wz+SlXJCtksnYmvKdzn79b2HInvPJtndDQ\/VidcN2MuJfkYe688<br \/>\n2m3FYMI0ehPummvv3iGXLz5ku6gD6y0qNhNWC6HM+hLNnPvvukXXcFgCyonJuv0I<br \/>\nAqwDoKa8myM=pIHc<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Virtualization 4.11.1 security and bug fix update Advisory ID: RHSA-2022:8750-01 Product: cnv Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8750 Issue date: 2022-12-01 CVE Names: CVE-2015-20107 CVE-2016-3709 CVE-2020-0256 CVE-2020-35525 CVE-2020-35527 CVE-2021-0308 CVE-2021-38561 CVE-2022-0391 CVE-2022-0934 CVE-2022-1292 CVE-2022-1304 CVE-2022-1586 CVE-2022-1785 CVE-2022-1897 CVE-2022-1927 CVE-2022-2068 CVE-2022-2097 CVE-2022-2509 CVE-2022-3515 CVE-2022-22624 CVE-2022-22628 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34336","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34336"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34336\/revisions"}],"predecessor-version":[{"id":34367,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34336\/revisions\/34367"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}