RHSA-2021:0799MediumCVSS 8.6

Red Hat Security Advisory: OpenShift Virtualization 2.6.0 security and bug fix update

Published
March 10, 2021
Last Modified
August 23, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash CVE-2020-15586 — golang: data race in certain net/http servers including ReverseProxy can lead to DoS CVE-2020-16845 — golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs CVE-2020-26160 — jwt-go: access restriction bypass vulnerability CVE-2020-27813 — golang-github-gorilla-websocket: integer overflow leads to denial of service CVE-2020-28362 — golang: math/big: panic during recursive division of very large numbers CVE-2020-29652 — golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-20206 — containernetworking-cni: Arbitrary path injection via type field in CNI configuration

🎯 Affected products6

  • CNV 2.6 for RHEL 8
  • container-native-virtualization/kubevirt-cpu-model-nfd-plugin@sha256:efb152ddc837945aad0163f96c9668cbb8271c2b14716b9fef5b798c27efbe48_amd64 as a component of CNV 2.6 for RHEL 8
  • container-native-virtualization/kubevirt-cpu-node-labeller@sha256:2b78b4854b18e53e388d2d30bf68803e39f8fbc9a0b3713885081af25abfb3f1_amd64 as a component of CNV 2.6 for RHEL 8
  • container-native-virtualization/kubevirt-kvm-info-nfd-plugin@sha256:2dcf59515b784d6decf484c1d756d5ddf4b65a38e78800a76ef1dab51020e553_amd64 as a component of CNV 2.6 for RHEL 8
  • container-native-virtualization/vm-import-controller-rhel8@sha256:ad9c84b90577d32229b803f7b8d014f39f517d0961de46de972fce3801fdfdc8_amd64 as a component of CNV 2.6 for RHEL 8
  • container-native-virtualization/vm-import-controller@sha256:ad9c84b90577d32229b803f7b8d014f39f517d0961de46de972fce3801fdfdc8_amd64 as a component of CNV 2.6 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (81)