RHSA-2021:0988MediumCVSS 9.8

Red Hat Security Advisory: rhvm-appliance security, bug fix, and enhancement update

Published
March 25, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2015-8011 — lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c CVE-2020-14349 — postgresql: Uncontrolled search path element in logical replication CVE-2020-14350 — postgresql: Uncontrolled search path element in CREATE EXTENSION

🎯 Affected products6

  • Red Hat Virtualization 4 Hypervisor for RHEL 8
  • Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.4-20210310.0.el8ev.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
  • rhvm-appliance-2:4.4-20210310.0.el8ev.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.4-20210310.0.el8ev.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
  • rhvm-appliance-2:4.4-20210310.0.el8ev.x86_64 as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: When the lldpd source is compiled with source fortification enabled, the flaw becomes unexploitable and will just cause a crash.

🔗 References (7)