Red Hat Security Advisory: OpenShift Virtualization 4.9.0 Images security and bug fix update
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-31525 — golang: net/http: panic in ReadRequest and ReadResponse when reading a very large header CVE-2021-33195 — golang: net: lookup functions may return invalid host names CVE-2021-33197 — golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty CVE-2021-33198 — golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents CVE-2021-34558 — golang: crypto/tls: certificate of wrong type is causing TLS client to panic
🎯 Affected products39
- CNV 4.9 for RHEL 8
- container-native-virtualization/bridge-marker@sha256:3ca4ad49caa78f772298b84bca2bc0bbc9e440ab248de857b4f7b37139cfe69e_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/cluster-network-addons-operator@sha256:8726e5e35ee4b31c66104e7c8e406d7b5040342954e0338ed548b5b2b1db583b_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/cnv-containernetworking-plugins@sha256:ee27c1fee061e3c012e223821510d81bdbedc2f4dcce6b6a1df3ee4e7ee8d95b_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/cnv-must-gather-rhel8@sha256:ae296e5e29cb28b018708c511413c9b442e00adeeab117f55ef11aa697815cc5_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/hco-bundle-registry@sha256:2d7b4f8c04d4562029587c4b8e45d4b911ea4e3590c58bf2ecb2b7b238fd0778_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:9a47e7f71bfd82a6bae03581c93c0b24bc56e60edf1f67956b48376467a82d3a_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/hostpath-provisioner-rhel8@sha256:21140d9f28a488d18d789be2ed8c2cd8e475e30aa337bfebdcb3b6901557d1ac_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/hyperconverged-cluster-operator@sha256:62829517f9d288727e92023b07f734745d4cb033580b7047556d89297e7ff4e9_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:fb78148f30401dc81acd1ad71b8c158b6da1ab9a4cd5a3988cc6dfd84f89d0fd_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/kubemacpool@sha256:a2140a25b75110f2353f88bcdcc6cbddeea41efd2b653242b8a3426f82cf060f_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/kubernetes-nmstate-handler-rhel8@sha256:4ab8d14a75e26afb8b63ed7253b93beafcd344be7729ed285c913e915dc43c2f_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/kubevirt-ssp-operator@sha256:d3fd0c8f6c71af32e513d28f198bdfcbf60b717ff8c33683ce8441e46b18597e_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/kubevirt-template-validator@sha256:8d33c8d2d5fd949a860385fac4badc32f579bafd8fffa37554475340dbf5d2f5_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/kubevirt-v2v-conversion@sha256:7588b962baa2a7905775ecbf455f9a7c7ae77bcdeb8c59fd592019190f032fba_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/kubevirt-vmware@sha256:1f379e14ac3485ca5d7f1dbb2dbb626a642fe8b5ae699ba005d0b9a4ec7b3695_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/libguestfs-tools-rhel8@sha256:14d2899027eeb27b2d6f6f0f3c3a67fb1bc14e15ca5371f51c936103e679b148_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/libguestfs-tools@sha256:14d2899027eeb27b2d6f6f0f3c3a67fb1bc14e15ca5371f51c936103e679b148_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/node-maintenance-operator@sha256:67708c4cf950afbfc43720d3ce09a15365e43a102c6174fb97401921d80b00ae_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/ovs-cni-marker@sha256:c98838f838720bca7054c7b5e3622718d44c27799f5266eaf792865091f885a3_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/ovs-cni-plugin@sha256:c3398a7e793e928e085b2f1ac718f875d38b0be36a6eb9a4f8365b116f6d3606_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-api@sha256:b2a9fd906d366609674d7731f256c7bb40dfce62cbaf1a1c4271b3c65b11d750_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-artifacts-server-rhel8@sha256:94394307fa2ebcb25f53a6b4866a98d182850b3f14173e4f6c795e9028939345_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-artifacts-server@sha256:94394307fa2ebcb25f53a6b4866a98d182850b3f14173e4f6c795e9028939345_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-cdi-apiserver@sha256:3aea2b6db027a2419f26bdb1b74b1d3ca09e6675180a46cefac45dd96516c6c5_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-cdi-cloner@sha256:aedd7f690a2fd5ad2f2988c673f337fa96f235ebf40e20c55a77b29c73651df7_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-cdi-controller@sha256:a7510b66fe8331591ba7d612eea04995f5ef42c10a0380f957b5e4b8be17fe8e_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-cdi-importer@sha256:648caeddba7e2ce0cc1688c2d8dee297931d1fe980701227ca6852750f7b74dc_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-cdi-operator@sha256:1549e1e6f3f145cced51e7b7b0800103c2bf218300d4029ea3b11380e1249b1c_amd64 as a component of CNV 4.9 for RHEL 8
- container-native-virtualization/virt-cdi-uploadproxy@sha256:f94eabaa002e1c2ae6ec927744da1bfa77a87403bbbedf6bb079746e6b4d1ebc_amd64 as a component of CNV 4.9 for RHEL 8
- +9 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (62)
- selfhttps://access.redhat.com/errata/RHSA-2021:4104
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1858777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891921
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1896469
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1903687
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1921650
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1933043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1942726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1943164
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1953481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1953483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1953484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1955129
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1957852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1958341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1963963
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1965050
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1973852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1976604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1976730
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1979631
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1979659
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981345
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1983596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1985083
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1985649
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1985670
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1985719
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989263
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989269
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989570
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989575
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1992608
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1993121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1994389
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995295
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996407
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997014
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998054
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999571
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001047
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2003473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2006418
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2008900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010742
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011179
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2017394
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2018521
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4104.json