Red Hat Security Advisory: OpenShift Virtualization 4.8.2 Images security and bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-33195 — golang: net: lookup functions may return invalid host names CVE-2021-33197 — golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty CVE-2021-33198 — golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents CVE-2021-34558 — golang: crypto/tls: certificate of wrong type is causing TLS client to panic
🎯 Affected products2
- CNV 4.8 for RHEL 8
- container-native-virtualization/vm-import-operator-rhel8@sha256:ec39e0dc1c3d6c0912b1da5b9dc36682a5a702cd64978ec6d0b34651942944ca_amd64 as a component of CNV 4.8 for RHEL 8
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://docs.openshift.com/container-platform/4.8/virt/upgrading-virt.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2021:3598
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1953485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1957791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1972819
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1982143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1983596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989570
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989575
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1990065
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991460
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1993122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995050
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996110
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996660
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998818
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998983
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001038
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001069
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3598.json