Red Hat Security Advisory: Red Hat Virtualization Host security update [ovirt-4.4.6]
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-24489 — hw: vt-d related privilege escalation CVE-2021-3501 — kernel: userspace applications can misuse the KVM API to cause a write of 16 bytes at an offset up to 32 GB from vcpu->run CVE-2021-3560 — polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync() CVE-2021-27219 — glib: integer overflow in g_bytes_new function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits
🎯 Affected products7
- RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- Red Hat Virtualization 4 Hypervisor for RHEL 8
- redhat-release-virtualization-host-0:4.4.6-2.el8ev.src as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- redhat-release-virtualization-host-0:4.4.6-2.el8ev.x86_64 as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- redhat-virtualization-host-0:4.4.6-20210615.0.el8_4.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- redhat-virtualization-host-image-update-0:4.4.6-20210615.0.el8_4.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- redhat-virtualization-host-image-update-placeholder-0:4.4.6-2.el8ev.noarch as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2974891 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2021:2522
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1903997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1929858
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1950136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1961710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1962650
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2522.json