RHSA-2020:3194HighCVSS 9.9

Red Hat Security Advisory: Container-native Virtualization security, bug fix, and enhancement update

Published
July 28, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2020-10749 — containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters CVE-2020-14316 — kubevirt: VMIs can be used to access host files

🎯 Affected products5

  • CNV 2.4 for RHEL 8
  • container-native-virtualization/kubevirt-cpu-model-nfd-plugin@sha256:72b956caace219d8ac56bb612ed9191e47c034573ec1b5c441bac5f95b4765c3_amd64 as a component of CNV 2.4 for RHEL 8
  • container-native-virtualization/kubevirt-cpu-node-labeller@sha256:b21c67b53c6b118ce91eec2bcfcad36c047de847eaace9fcadc6883644ef49b9_amd64 as a component of CNV 2.4 for RHEL 8
  • container-native-virtualization/kubevirt-kvm-info-nfd-plugin@sha256:a360db67b318af15e891e5f75bd53182882c0447cd0dc2dbef60656c8ea1185b_amd64 as a component of CNV 2.4 for RHEL 8
  • container-native-virtualization/vm-import-controller-rhel8@sha256:31e39f9f984733277f08360eb326f1a3808d236a222e70ead484454681d2e3ee_amd64 as a component of CNV 2.4 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Prevent untrusted, non-privileged containers from running with CAP_NET_RAW. Workaround: This flaw can be partially or completely mitigated by leveraging existing mechanisms to restrict the VMI process such as running as non-root and using SELinux and sVirt whenever possible.

🔗 References (98)