RHSA-2021:2522HighCVSS 9.8

Red Hat Security Advisory: Red Hat Virtualization Host security update [ovirt-4.4.6]

Published
June 22, 2021
Last Modified
August 5, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2020-24489 — hw: vt-d related privilege escalation CVE-2021-3501 — kernel: userspace applications can misuse the KVM API to cause a write of 16 bytes at an offset up to 32 GB from vcpu->run CVE-2021-3560 — polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync() CVE-2021-27219 — glib: integer overflow in g_bytes_new function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits

🎯 Affected products7

  • RHEL 8-based RHEV-H for RHEV 4 (build requirements)
  • Red Hat Virtualization 4 Hypervisor for RHEL 8
  • redhat-release-virtualization-host-0:4.4.6-2.el8ev.src as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
  • redhat-release-virtualization-host-0:4.4.6-2.el8ev.x86_64 as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
  • redhat-virtualization-host-0:4.4.6-20210615.0.el8_4.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
  • redhat-virtualization-host-image-update-0:4.4.6-20210615.0.el8_4.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
  • redhat-virtualization-host-image-update-placeholder-0:4.4.6-2.el8ev.noarch as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2974891 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

🔗 References (8)